Intermediary Command Validation for Inline Authorization Offload

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing server systems face high costs and resource consumption due to the need for a heavyweight authentication and authorization system to handle numerous client device requests, leading to overburdening and reduced capacity for providing services.

Innovation Solution

Implementing an intermediary device with an inline authentication and authorization engine that performs authentication and authorization tasks for client devices, reducing the burden on server systems by handling these tasks before they reach the server, and utilizing cloud computing resources on demand.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a heavyweight authentication and authorization system is deployed on-premises to handle numerous client device requests, then authentication and authorization capabilities are improved, but system complexity and resource consumption increase significantly

Engineering Contradiction:
Improveauthentication and authorization capabilitiesVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary device positioned between client devices and server systems that handles authentication and authorization requests. This intermediary captures commands from client devices, performs authentication and authorization locally, and forwards only authorized commands to server systems, thereby reducing the burden on both clients and servers while maintaining security capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication and authorization functionality from the server systems and places it in a separate intermediary device. This extraction allows server systems to focus on their primary functions while the intermediary handles security-related tasks, reducing overall system complexity and resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If a heavyweight authentication and authorization system is deployed on-premises to handle numerous client device requests, then authentication and authorization capabilities are improved, but cost increases due to hardware and maintenance requirements

Engineering Contradiction:
Improveauthentication and authorization capabilitiesVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The intermediary device is designed to work with multiple server systems and support various authentication protocols, making it a universal solution that can serve multiple purposes. This multi-functionality reduces the need for separate authentication systems for different server systems, thereby lowering overall deployment costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Extent of automation

If authentication and authorization tasks are handled by server systems, then centralized control is maintained, but server system capacity for providing services is reduced

Engineering Contradiction:
Improvecentralized controlVSAvoidserver system capacity
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The intermediary device acts as a mediator that handles authentication and authorization tasks locally, preventing these resource-intensive operations from consuming server system capacity. The intermediary maintains centralized security policies while allowing server systems to focus on service delivery, thereby preserving both control and productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250247429A1Command validation at an intermediary device
Publication Date: 2025.07.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250247429A1 patent drawing
  • US20250247429A1 patent drawing
  • US20250247429A1 patent drawing

AI summary

In some examples, an intermediary device receives, from a client device, a command associated with a secure protocol that secures a connection between the client device and a server system, where the intermediary device includes an inline authentication and authorization service between the client device and the server system. The authentication and authorization service at the intermediary device determines, based on command enforcement policy information, whether to authorize the command received from the client device.