Intermediary Authentication System for Multi-Tenant Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant systems, prospective tenants without their own AAA servers face challenges in accessing shared network resources while ensuring access protection, as MSPs struggle to support these tenants effectively.

Innovation Solution

A computer system that facilitates authentication and authorization by communicating with an electronic device associated with a tenant and an MSP's system, enabling the MSP to provide authentication and authorization services even to tenants without their own AAA servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tenants have their own AAA servers for authentication and authorization, then access protection is ensured, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improveaccess protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication system that acts as a mediator between tenants without AAA servers and the shared network. This intermediary handles authentication and authorization requests, allowing tenants to access the network without deploying their own AAA servers, thus maintaining access protection while reducing system complexity for individual tenants

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If tenants without AAA servers are supported, then adaptability and service coverage improve, but access protection reliability deteriorates

Engineering Contradiction:
Improveservice coverageVSAvoidaccess protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal authentication system that can serve both tenants with their own AAA servers and tenants without them. The intermediary authentication mechanism provides multi-functional capability, handling authentication for diverse tenant types through a unified approach, thereby expanding service coverage while maintaining consistent access protection standards

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional AAA server deployment is required, then access authorization is secure, but ease of operation and deployment difficulty worsen

Engineering Contradiction:
Improveauthorization securityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables tenants without AAA servers to self-register and access the shared network through the intermediary authentication system. The system automatically handles authentication request routing and credential verification, allowing tenants to deploy services immediately without complex AAA server installation and configuration, thus improving deployment ease while maintaining authorization security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12306978B2Tenant access protection via an intermediary computer system
Publication Date: 2025.05.20 RUCKUS IP HOLDINGS LLC
  • US12306978B2 patent drawing
  • US12306978B2 patent drawing
  • US12306978B2 patent drawing

AI summary

During operation, a computer system may receive, from an electronic device, an access request to access a shared network in a multi-tenant system, where the electronic device associated with a tenant in the multi-tenant system. Then, the computer system may identify a second computer system, which may be associated with an MSP of the shared network and that provides authentication and/or authorization to the shared network for users associated with the tenant. Moreover, the computer system may provide, to the second computer system, an authorization request for the electronic device. Next, the computer system may receive, from the second computer system, an authorization response, where the authorization response approves access by the electronic device to the shared network. Furthermore, the computer system may provide, to the electronic device, an access response, where the access response includes information specifying access privileges of the electronic device in the shared network.