Identity Service for Secure Inter-Server Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing inter-server communications within enterprises lack authentication, relying on assumptions that are not truly secure, and modifying legacy applications to achieve authentication is costly and not deemed beneficial.

Innovation Solution

Implementing an identity-based monitoring approach that intercepts and authenticates communications between servers using an identity service, which assigns unique identities to communications and enforces policies, ensuring secure and validated transactions without modifying legacy applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy applications are modified to implement authentication for inter-server communications, then security is improved, but cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidcost and complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity service as an intermediary component that mediates authentication between servers and legacy applications. The identity service intercepts communications, performs authentication, and returns results without requiring modifications to the legacy applications themselves. This resolves the contradiction by providing security (improved reliability) through the intermediary identity service while avoiding the cost and complexity of modifying legacy systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication is implemented for all inter-server communications, then security is improved, but processing time and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The identity service performs authentication in advance by establishing identity contexts and credentials before actual communication occurs. Once authenticated, the identity information is cached and reused for subsequent communications between the same servers, eliminating the need for repeated authentication handshakes. This resolves the contradiction by providing comprehensive security while minimizing processing time through pre-authentication and credential caching.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If identity-based monitoring is implemented without modifying legacy processes, then ease of operation is improved, but authentication coverage may be incomplete

Engineering Contradiction:
Improveease of operationVSAvoidauthentication coverage
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements authentication in a different dimension by operating at the network/kernel layer rather than requiring application-layer modifications. The identity service hooks into the operating system's network stack to intercept and authenticate communications transparently. This resolves the contradiction by providing comprehensive authentication coverage through OS-level integration while maintaining ease of operation since legacy applications require no modification.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9882965B2Techniques for network process identity enablement
Publication Date: 2018.01.30 MICRO FOCUS LLC
  • US9882965B2 patent drawing
  • US9882965B2 patent drawing
  • US9882965B2 patent drawing

AI summary

Techniques for network process identity enablement are provided. Inter-server communications within a network are intercepted so that unique identity-based information is gathered and recorded before a sending process is permitted to release a communication over the network to a receiving process. Moreover, the receiving process cannot process the communication being sent until identifying information is gathered again and independently validated against the prior recorded information.