Policy Server for LDAP Web Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack an efficient method to authenticate and control access to external web resources based on user identity, role, and group membership, especially when integrating with LDAP directory servers for custom policies across varying time ranges.
Innovation Solution
A policy-based web filter that integrates with LDAP directory servers or Kerberos/NTLM for authentication, using a uniform resource identifier to reference a policy server within a trusted network, allowing access control based on user identity and group membership, and enforcing custom policies by transmitting credentials to determine authorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional web filters are used to block access to web sites based on domain, URL pattern, or content category, then web security is improved, but the ability to provide personalized access control based on user identity and group membership is lost
Solution Approach 1:
The patent introduces a policy server as an intermediary component that mediates between the web filter and LDAP directory server. This policy server receives authentication information from the web filter, queries the LDAP directory server for user identity and group membership, retrieves applicable policies, and returns access decisions to the web filter. This intermediary enables personalized access control without compromising the security filtering functionality.
2Adaptability or versatility
If LDAP directory servers are integrated for authentication and group membership information, then personalized policy enforcement is improved, but system complexity and administrative burden increase
Solution Approach 1:
The policy server implements self-service functionality by automatically querying the LDAP directory server for user authentication information and group membership, automatically retrieving applicable policies based on user identity, and automatically making access decisions. This eliminates the need for manual policy configuration and reduces administrative burden, allowing the system to manage its own authentication and authorization processes.
Solution Approach 2:
The policy server serves multiple functions: it acts as an authentication gateway, queries the LDAP directory server for user information, retrieves policies based on user identity and group membership, and makes access decisions. This multi-functional component reduces overall system complexity by consolidating multiple responsibilities into a single server rather than requiring separate systems for each function.
3Measurement precision
If custom policies are enforced for particular users and groups across customizable time ranges, then access control precision is improved, but processing time and system resource usage increase
Solution Approach 1:
The system performs preliminary actions by pre-fetching and caching policy information from the LDAP directory server before actual web access requests occur. The policy server queries user identity, group membership, and applicable policies in advance, storing this information for quick retrieval during access decisions. This preliminary preparation reduces processing time during actual web browsing operations while maintaining precise access control based on user identity and group membership.
Data Source
AI summary
Enabling web filtering by authenticated group membership, role, or user identity is provided by embedding a uniform resource identifier into an electronic document requested by a client. A client browser will provide directory credentials to a trusted web filter apparatus enabling a policy controlled access to resources external to the trusted network. An apparatus comprises circuits for transmitting a uniform resource identifier to a client, receiving a request comprising authentication credentials, querying a policy database and determining a customized policy for access to an externally sourced electronic document or application. A computer-implemented technique to simplify web filter administrator tasks by removing a need to set each browsers settings or install additional software on each user terminal.


