SD-WAN Edge Authentication Across Network Zones
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure communication channel between different network zones, such as public clouds and private data centers, is complex and error-prone, especially when virtual desktop infrastructure (VDI) is deployed in one zone and the authentication service, like Microsoft Active Directory, is located in another, making it difficult for IT administrators to manage.
Innovation Solution
Deploying software-defined wide area network (SD-WAN) edge devices to create a secure overlay network, allowing authentication services to be accessed across zones by authenticating and configuring SD-WAN edges with administrator credentials, thereby establishing secure communication channels between network zones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a VPN tunnel is manually configured to provide secure communication between different network zones, then security is improved, but the complexity of configuration and administration increases significantly
Solution Approach 1:
The patent introduces an intermediary system that automatically discovers network zones, authenticates devices, and configures secure communication channels without manual intervention. This intermediary layer handles the complexity of VPN tunnel configuration while providing simple authentication for end users, resolving the contradiction between security and configuration complexity.
Solution Approach 2:
The system enables self-service authentication where devices automatically register with the authentication service and obtain secure access credentials without requiring manual VPN configuration by administrators. Devices autonomously establish secure connections through the overlay network, eliminating the need for complex manual setup while maintaining security.
2Reliability
If manual VPN tunnel configuration is used to connect different network zones, then secure access is achieved, but the time and effort required for administration increases
Solution Approach 1:
The patent implements preliminary action by pre-configuring the authentication service and overlay network infrastructure before devices need access. Network zones are预先 discovered and registered, authentication credentials are pre-established, and secure pathways are prepared in advance, eliminating the need for time-consuming manual configuration when devices need to connect.
Solution Approach 2:
Devices automatically perform self-registration and self-authentication with the authentication service, obtaining secure access credentials without administrator intervention. This self-service mechanism eliminates the time administrators would otherwise spend manually configuring VPN tunnels for each device or network zone.
3Reliability
If traditional network configuration methods are used for cross-zone authentication, then security can be maintained, but the ease of operation deteriorates
Solution Approach 1:
The authentication service acts as an intermediary that abstracts complex security configuration from end users. Instead of requiring users to manually configure VPN tunnels and security parameters, the intermediary handles all security-related operations automatically, maintaining security while dramatically improving ease of operation.
Solution Approach 2:
The system enables devices to automatically discover the authentication service, register themselves, and obtain secure access credentials through simple automated processes. This self-service approach maintains security through proper authentication while making the operation as simple as device deployment, eliminating complex manual configuration steps.
Data Source
AI summary
A method of establishing a secure communication channel from a first edge device that is in a first network zone across a secure overlay network to a second edge device that is in a second network zone, so that access to a computing device that is in the second network zone can be authenticated by an authentication service that is in the first network zone, includes the steps of establishing a first secure communication channel from the first edge device to the secure overlay network, receiving a request to join the secure overlay network along with administrator credential information and, responsive to the request, transmitting the administrator credential information to the authentication service for authentication through the first secure communication channel and the first edge device, and establishing a second secure communication channel from the second edge device to the secure overlay network if the authentication is received from the authentication service.


