Web Authentication Protocol Exchange for Secure Cloud Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy web authentication protocols are not secure enough for public cloud environments, leading to vulnerabilities and hindering migration of business-critical applications to the public cloud.
Innovation Solution
A method and system that utilize a legacy authentication protocol certification, followed by validation and generation of tokens, to augment access requests with modern authentication tokens, ensuring secure access to public cloud platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If legacy authentication protocols are used, then applications can maintain backward compatibility and existing functionality, but security vulnerabilities increase and public cloud migration is blocked
Solution Approach 1:
The patent introduces a protocol exchange service as an intermediary component that sits between legacy applications and public cloud authentication systems. This service receives authentication requests using legacy protocols, translates them into modern cloud-compatible protocols, and returns responses to the original applications. This mediator approach allows legacy applications to communicate with secure cloud infrastructure without requiring modifications to the applications themselves, thus resolving the contradiction between maintaining backward compatibility and achieving secure cloud migration
Solution Approach 2:
The protocol exchange service dynamically changes authentication protocol parameters based on the target cloud platform requirements. It transforms authentication request formats, token structures, and protocol versions from legacy standards to modern cloud standards. This parameter transformation enables the same application to interact with both legacy and modern authentication systems, simultaneously achieving backward compatibility and security compliance
2Productivity
If a big bang migration approach is used, then migration speed increases, but system complexity and risk of interdependent failures increase
Solution Approach 1:
The patent segments the monolithic authentication system into modular components: legacy protocol handlers, protocol exchange services, and cloud authentication interfaces. Each component can be independently developed, tested, and deployed. This segmentation allows organizations to migrate specific authentication services to the cloud independently rather than requiring complete simultaneous migration, thus reducing system complexity and enabling incremental adoption while maintaining overall migration progress
3Stability of the object's composition
If legacy authentication protocols are used, then existing applications continue to function, but vulnerability to malicious threats increases
Solution Approach 1:
The protocol exchange service acts as a security intermediary that filters and translates authentication traffic. It receives potentially vulnerable legacy protocol requests, validates them against security policies, transforms them into secure modern protocols, and forwards them to cloud authentication systems. This intermediary layer blocks malicious threats from reaching legacy applications while maintaining their functionality, thus resolving the contradiction between application stability and threat vulnerability
Data Source
AI summary
A system and a method for authenticating user access to a service that is hosted on a public cloud platform are provided. The method includes: receiving an access request from a user that relates to a service that is hosted on a public cloud platform; preliminarily authenticating the access request by using a legacy authentication protocol that is not sufficiently secure for accessing the first service via the public cloud platform; generating and validating, based on a result of the preliminary authentication, a legacy protocol certification; retrieving roles that are associated with the user; obtaining, based on the user roles, a token that is usable for controlling access to the service via the public cloud platform; and augmenting the access request with the token and a signature to facilitate an authentication of the access request by the public cloud platform, while excluding the legacy protocol certification.


