Outbound Agent Cloud Authentication Firewall Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Cloud-based authentication methods compromise network security by either outsourcing authentication control to third-party Cloud vendors or opening inbound ports, making corporate networks vulnerable to hacking and security breaches.

Innovation Solution

Implementing a software agent within the corporate network that establishes an outbound secure connection with Cloud servers, allowing remote users to authenticate and access resources without opening the network to potential security threats by using a Request Collector to manage requests and responses through a secure protocol/channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication information is stored in Cloud servers, then remote users can authenticate without opening inbound ports, but the entity loses control over authentication security and risks exposure to hackers

Engineering Contradiction:
Improveremote authentication capabilityVSAvoidauthentication security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a software agent as an intermediary component installed on the client machine within the corporate network. This agent acts as a mediator between the remote user's authentication request and the Cloud-based authentication server. The agent establishes an outbound connection to the cloud, allowing authentication requests to be forwarded securely without opening inbound ports on the corporate firewall, thus maintaining both remote access capability and security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If inbound ports are opened on the firewall to allow authentication requests, then remote users can access authentication servers, but the network becomes vulnerable to hackers and unauthorized access

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional approach by reversing the connection direction. Instead of opening inbound ports on the corporate firewall to allow connections from remote users, the solution establishes outbound connections from within the corporate network to the Cloud servers. The software agent proactively initiates these outbound connections, allowing authentication requests to traverse the firewall in the safe direction of outgoing traffic rather than incoming traffic.

Inventive Principle:
Principle #13The other way round (Inversion)

3Adaptability or versatility

If the entire Active Directory is copied to the Cloud, then authentication can be performed remotely, but the entity loses control over its AD and authentication information

Engineering Contradiction:
Improveremote authentication functionalityVSAvoidauthentication control
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent extracts only the necessary authentication functionality from the full Active Directory system and implements it through a lightweight software agent on the client machine. Rather than copying the entire AD to the cloud, the agent contains minimal AD functionality locally to handle authentication requests, communicating only with the cloud for verification. This extraction maintains remote authentication capability while preserving control over the majority of AD information within the corporate network.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10791095B2Secure authentication and data transfer for cloud systems
Publication Date: 2020.09.29 XIID CORP
  • US10791095B2 patent drawing
  • US10791095B2 patent drawing
  • US10791095B2 patent drawing

AI summary

A user may access resources within a secure network through an agent stored on a first computing device within the secure network which then opens an outbound secure channel through a firewall of the secure network to a request collector stored on a second computing device outside the secure network. The agent waits until the request collector has rendered available on the outbound secure channel a request from the user for access to the resources in the secure network. The agent then reads the request rendered available on the outbound secure channel by the request collector and causes the request to be executed utilizing the resources within the secure network. The agent responds back to the request collector on the outbound secure channel which then responds to the user.