Kerberos Group Ticket Virtualization for Network Load Balancers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In client-server cluster environments, existing Kerberos security protocols face challenges when combined with network load balancing, particularly in routing via hardware devices that only provide routing support, as they prohibit registration of multiple servers under a common Server Principle Name, limiting scalability and manageability.

Innovation Solution

A group ticket for the Kerberos protocol is introduced, encrypted with a dynamic group key and enveloped pairs, allowing decryption by each cluster node's long-term key, enabling secure access to resources without altering the classic Kerberos abstraction, and managed centrally by a Key Distribution Center, facilitating network load balancing without requiring changes to applications or routing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Kerberos security protocol is used with traditional server authentication, then security is provided, but multiple servers cannot be registered under a common Server Principle_name, limiting cluster scalability

Engineering Contradiction:
ImprovesecurityVSAvoidcluster scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the traditional single-server authentication model by introducing a group ticket mechanism where multiple servers are divided into a cluster group. Each server retains its individual identity while being part of a larger group that shares a common authentication credential, allowing servers to be segmented into manageable clusters that can scale independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple server identities under a common group ticket structure. Instead of requiring separate authentication for each server, the cluster group ticket combines the authentication credentials of multiple servers, allowing clients to access any server in the cluster using a single ticket while maintaining individual server security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If network load balancing is implemented with hardware routing devices, then traffic distribution is achieved, but Kerberos authentication cannot be properly routed, compromising security

Engineering Contradiction:
Improvetraffic distributionVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a Kerberos authentication server as an intermediary between the load balancer and the cluster servers. The authentication server acts as a mediator that issues group tickets valid for multiple servers, allowing the load balancer to distribute traffic without needing to understand or process individual server authentication credentials, thus maintaining security while enabling load balancing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The group ticket mechanism provides universal authentication that works across multiple servers and load balancers. A single group ticket can be used to access any server in the cluster regardless of which load balancer routes the request, making the authentication system universal and independent of the specific load balancing hardware or configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If individual server tickets are used for each cluster node, then security is maintained, but ticket management complexity increases with cluster size

Engineering Contradiction:
ImprovesecurityVSAvoidticket management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple individual server tickets into a single group ticket that represents the entire cluster. Instead of managing separate authentication credentials for each server, the group ticket consolidates these credentials into one manageable object that can be issued and validated by the Kerberos authentication server, reducing management complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The group ticket serves multiple functions simultaneously: it authenticates the client to the cluster, enables load balancing across multiple servers, and provides a single point of management for cluster-wide authentication. This multi-functional approach eliminates the need for separate ticket management for each server while maintaining individual server security boundaries.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If cluster size is increased for scalability, then resource capacity increases, but authentication overhead and management burden increase

Engineering Contradiction:
Improveresource capacityVSAvoidauthentication overhead
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments the authentication process by introducing a group-level authentication layer that is independent of the number of individual servers. The group ticket is issued once for the entire cluster regardless of size, and can be used to access any number of servers within the cluster without requiring additional authentication operations, thus making authentication overhead independent of cluster size.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The group ticket provides universal access rights across the entire cluster, allowing a single authentication operation to grant access to any server in the cluster. This universal approach eliminates the need for repeated authentication operations as cluster size increases, making the authentication system scalable without increasing overhead.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8132246B2Kerberos ticket virtualization for network load balancers
Publication Date: 2012.03.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8132246B2 patent drawing
  • US8132246B2 patent drawing
  • US8132246B2 patent drawing

AI summary

An exemplary group ticket for a Kerberos protocol includes a service ticket encrypted with a dynamic group key and a plurality of enveloped pairs where each pair includes a name associated with a member of a group and an encrypted the dynamic group key for decryption by a key possessed by the member of the group where decryption of an encrypted dynamic group key allows for decryption of the service ticket. Other exemplary methods, systems, etc., are also disclosed.