Devices, systems and methods for providing improved authentication from edge infrastructure
The method and system address authentication challenges in edge computing by using edge devices with active agents to manage user profiles in a secure cloud, ensuring scalable and efficient authentication with reduced vulnerabilities and endpoint management complexities.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-23
- Publication Date
- 2026-04-09
AI Technical Summary
Authentication in edge computing environments is challenging due to their distributed nature, dynamic device changes, and the need for low latency, which complicates credential management and security policy enforcement, often leading to security vulnerabilities and inefficiencies in traditional systems.
A method and system that utilize edge devices with active agents to intercept and authenticate entity requests, generate and encrypt authentication tokens, and manage user profiles in a secure cloud, enabling flexible and secure authentication without relying on endpoint devices.
Provides scalable, adaptable, and efficient authentication with enhanced security and reduced latency by managing user profiles in the cloud and deploying them to edge infrastructure, reducing vulnerabilities and endpoint management complexities.
Smart Images

Figure US2025047479_09042026_PF_FP_ABST
Abstract
Description
DEVICES, SYSTEMS AND METHODS FOR PROVIDING IMPROVED AUTHENTICATION FROM EDGE INFRASTRUCTURECROSS-REFERENCE TO PREVIOUS APPLICATON
[0001] This application claims priority from United States provisional patent application 63 / 703,319 filed on October 4th, 2024, which is incorporated herein by reference in its entirety,FIELD
[0002] The present disclosure generally relates to the field of data communications and networking. In particular, the present disclosure relates to devices, systems, and methods for providing improved authentication from edge infrastructure.INTRODUCTION
[0003] The increasing ubiquity of remote work, combined with a sustained escalation in the number and the sophistication of cybersecurity threats, has caused security practices to evolve to the point where information flows require real-time and continuous monitoring and management,
[0004] Such functionality is typically provided by an active agent, i.e,, a continuously running, autonomous piece of software that performs security functions in accordance with security policies. Such active agents may simply monitor and log information flow metadata, and / or take a more active role by encrypting, routing, attenuating, and / or filtering information flows. In order to actively monitor and manage information flows, active agents must be located on endpoint devices, inside a Virtual Private Network (VPN), or at the edge (entry point) of a network.
[0005] Authentication in edge computing presents unique challenges due to the distributed nature of the architecture. In edge computing, data processing occurs closer to the source of data, which often involves numerous devices and nodes spread across different locations. This distributed setup complicates the management of authentication credentials and the enforcement of security policies. Also, traditional authentication methods designed for centralized systems may not be feasible or secure in such a heterogeneous environment.
[0006] Moreover, the dynamic nature of edge computing environments, where devices frequently join or leave secured networks, adds another layer of complexity.Ensuring that authentication mechanisms are scalable and adaptable to these changes without compromising security is a significant challenge.
[0007] Furthermore, the need for low latency in edge computing means that authentication processes must be efficient and fast, which can be at odds with the more thorough, but slower, security measures typically employed in traditional systems.
[0008] As such, there is a clear need for improved devices, systems and methods for providing improved authentication from edge infrastructure.SUMMARY
[0009] The various embodiments described herein generally relate to devices, systems, and methods for providing improved authentication using edge infrastructure.
[0010] In one aspect of the present disclosure, there is provided a method of authenticating an entity to a third-party application running on an endpoint device. The third-party application is in communication with a third-party cloud. The method comprises issuing, from the third-party application running on the endpoint device, an entity authentication request comprising third-party identification information identifying the third-party. The method also comprises intercepting, at an edge device, the entity authentication request from the third-party application running on the endpoint device. The method also comprises authenticating the entity using identification information which the edge device has associated with the entity and sending an authentication confirmation to the third-party cloud.
[0011] In some examples, issuing an entity authentication request comprises generating an entity authentication request and sending it to a secure cloud associated with the edge device.
[0012] In some examples, intercepting the entity authentication request is performed by an active agent configured to encrypt, route, attenuate, and / or filter information flows through the edge device.
[0013] In some examples, the method further comprises, after authenticating the entity using identification information which the edge device has associated with the entity, sending information indicative of the authentication to a secure cloud. The method also comprises generating an authentication token and encrypting it with a common encryption method shared with the third-party cloud and sending the encryptedauthentication token to the third-party cioud via the third-party application running on the endpoint device.
[0014] in some examples, the method further comprises establishing a communication session between the third-party application and the third-party cioud and receiving a session token associated with the communication session at the third-party application from the third-party cloud and including the session token with the entity authentication request. The method may also comprise, after authenticating the entity using identification information which the edge device has associated with the entity, sending information indicative of the authentication to a secure cloud together with the session token. The method may also comprise generating an authentication token associated with the session token and encrypting it with an encryption method shared with the third-party cloud and sending the encrypted authentication token to the third- party cloud.
[0015] In some examples, sending an authentication confirmation to the third-party cloud includes generating an encrypted authentication token at the edge device with an encryption key shared with the secure cloud and sending the encrypted authentication token from the edge device to the third-party application running on the endpoint device. The method may also include sending the encrypted authentication token from the third- party application running on the endpoint device to the third-party cloud and sending the encrypted authentication token from the third-party cioud to the secure cioud. The method may also include decrypting the encrypted authentication token at the secure cloud and sending authentication confirmation information to the third-party cloud.
[0016] In some examples, the entity is a user of the endpoint device and the identification information which the edge device has associated with the entity is information relating to the endpoint device.
[0017] In some examples, the entity is the edge device and the identification information which the edge device has associated with the entity is metadata relating to the edge device and / or the endpoint device.
[0018] In another aspect of the present disclosure, there is provided a system that comprises a plurality of computer processors and one or more computer readable storage media for storing computer-implemented instructions. The plurality of computerprocessors are configured to execute the computer-implemented instructions to cause the system to perform the above method.
[0019] In yet another aspect of the present disclosure, there is provided method performed by an edge device to authenticate an entity to a third-party application running on an endpoint device connected to the edge device. The third-party application is in communication with a third-party cloud. The method comprises intercepting, at an edge device, an entity authentication request issued from the third-party application running on the endpoint device, the entity authentication request comprising third-party identification information identifying the third-party. The method also comprises authenticating the entity using identification information which the edge device has associated with the entity and sending an authentication confirmation to the third-party cloud.
[0020] In some examples, the entity authentication request is intercepted en route to a secure cloud associated with the edge device.
[0021] In some examples, intercepting the entity authentication request is performed by an active agent configured to encrypt, route, attenuate, and / or filter information flows through the edge device.
[0022] In some examples, the method further comprises, after authenticating the entity using identification information which the edge device has associated with the entity, sending information indicative of the authentication to a secure cloud.
[0023] In some examples, sending an authentication confirmation to the third-party cloud includes generating an encrypted authentication token with an encryption key shared with the secure cloud and sending the encrypted authentication token to the third- party application running on the endpoint device.
[0024] In some examples, the entity is a user of the endpoint device and the identification information which the edge device has associated with the entity is information relating to the endpoint device.
[0025] In some examples, the entity is the edge device and the identification information which the edge device has associated with the entity is metadata relating to the edge device and / or the endpoint device.
[0026] In yet another aspect of the present disclosure, there is provided an edge device comprising one or more computer processors and one or more computer readablestorage media for storing computer-implemented instructions, wherein the one or more computer processors are configured to execute the computer-implemented instructions to cause the system to perform the above method.
[0027] in yet another aspect of the present disclosure, there is provided non- transitory computer program product comprising computer-implemented instructions to cause a computer system to execute the above method.DRAWINGS
[0028] The drawings included herewith are for illustrating various examples of methods and systems of the present specification and are not intended to limit the scope of what is taught in any way. In the drawings:
[0029] FIGURE 1 shows a schematic diagram of an implementation of a system in accordance with embodiments of the present disclosure;
[0030] FIGURE 2 shows a schematic diagram of an instantiated virtualized security environment in accordance with embodiments of the present disclosure;
[0031] FIGURE 3 shows a method carried out by an active agent in accordance with embodiments of the present disclosure;
[0032] FIGURE 4 shows another method carried out by an active agent in accordance with embodiments of the present disclosure;
[0033] FIGURE 5 shows a schematic diagram of an instantiated virtualized security environment in accordance with embodiments of the present disclosure;
[0034] FIGURE 6 shows a schematic diagram of a method of authenticating a user and an edge device to a secure cloud;
[0035] FIGURE 7 shows a schematic diagram of a method of authenticating a user and an endpoint device to a secure cloud;
[0036] FIGURE 8 shows a schematic diagram of a first part of a method of authenticating a user to an application running on an endpoint device in accordance with embodiments of the present disclosure:
[0037] FIGURE 9 shows a schematic diagram of a second part of a method of authenticating a user to an application running on an endpoint device in accordance with embodiments of the present disclosure;
[0038] FIGURE 10 shows a method carried out by a system in accordance with the present disclosure:
[0039] FIGURE 11 shows a method carried out by an edge device in accordance with the present disclosure;
[0040] FIGURE 12 shows a schematic diagram of an edge device in accordance with embodiments of the present disclosure;
[0041] FIGURE 13 shows a schematic diagram of a second part of a method of authenticating a user to an application running on an endpoint device in accordance with another embodiment of the present disclosure;
[0042] FIGURE 14 shows a method carried out by a system in accordance with another embodiment of the present disclosure;
[0043] FIGURE 15 shows a schematic diagram of a first part of a method of authenticating a user to an application running on an endpoint device in accordance with yet another embodiment of the present disclosure;
[0044] FIGURE 16 shows a schematic diagram of a second part of a method of authenticating a user to an application running on an endpoint device in accordance with yet another embodiment of the present disclosure; and
[0045] FIGURE 17 shows a method carried out by a system in accordance with yet another embodiment of the present disclosure.DESCRIPTION OF VARIOUS EMBODIMENTS
[0046] Various embodiments in accordance with the teachings herein will be described below to provide an example of at least one embodiment of the claimed subject matter. No embodiment described herein limits any claimed subject matter. The claimed subject matter is not limited to devices, systems, or methods having all of the features of any one of the devices, systems, or methods described below or to features common to multiple or all of the devices, systems, or methods described herein. It is possible that there may be a device, system, or method described herein that is not an embodiment of any claimed subject matter.
[0047] Any subject matter that is described herein that is not claimed in this document may be the subject matter of another protective instrument, for example, a continuing patent application, and the applicants, inventors, or owners do not intend toabandon, disclaim, or dedicate to the public any such subject matter by its disclosure in this document.
[0048] It will be appreciated that for simplicity and clarity of illustration, where considered appropriate, reference numerals may be repeated among the figures to indicate corresponding or analogous elements. In addition, numerous specific details are set forth in order to provide a thorough understanding of the embodiments described herein. However, it will be understood by those of ordinary skill in the art that the embodiments described herein may be practiced without these specific details. In other instances, well-known methods, procedures, and components have not been described in detail so as not to obscure the embodiments described herein. Also, the description is not to be considered as limiting the scope of the embodiments described herein.
[0049] It should also be noted that the terms “connected” or “connecting" as used herein can have several different meanings depending in the context in which these terms are used. For example, the terms connected and connecting can have a mechanical or data communication connotation. For example, as used herein, the terms connected and connecting can indicate that two elements or devices can be directly linked to one another or linked to one another through one or more intermediate elements or devices via electrical and / or electromagnetic and / or optical signals, depending on the particular context, so as to be in data communication with other connected devices.
[0050] It should also be noted that, as used herein, the wording "and / or” is intended to represent an inclusive-or. That is, “X and / or Y” is intended to mean X or Y or both, for example. As a further example, "X, Y, and / or Z" is intended to mean X or Y or Z or any combination thereof.
[0051] The example embodiments of the devices, systems, or methods described in accordance with the teachings herein may be implemented as a combination of hardware and software. For example, the embodiments described herein may be implemented, at least in part, by using one or more computer programs, executing on one or more programmable devices comprising at least one processing element and at least one storage element (i.e., at least one volatile memory element and at least one non-volatile memory element). The hardware may comprise input devices including one or more of a touch screen, a keyboard, a mouse, buttons, keys, sliders, and the like, as well as oneor more of a display, a printer, and the like depending on the implementation of the hardware.
[0052] It should also be noted that there may be some elements that are used to implement at least part of the embodiments described herein that may be implemented via software that is written in a high-level programming language. The program code may be written in Rust, C++, C#, JavaScript, Python, or any other suitable programming language and may comprise modules or classes, as is known to those skilled in the art. Alternatively, or in addition thereto, some of these elements implemented via software may be written in assembly language, machine language, or firmware as needed. In either case, the language may be a compiled or interpreted language.
[0053] At least some of these software programs may be stored on a computer readable medium such as, but not limited to, a ROM, a magnetic disk, an optical disc, solid-state storage, a USB key, and the like that is readable by a device having a processor, an operating system, and the associated hardware and software that is necessary to implement the functionality of at least one of the embodiments described herein. The software program code, when read by the device, configures the device to operate in a new, specific, and predefined manner (e.g., as a specific-purpose computer) in order to perform at least one of the methods described herein.
[0054] At least some of the programs associated with the devices, systems, and methods of the embodiments described herein may be capable of being distributed in a computer program product comprising a computer readable medium that bears computer usable instructions, such as program code, for one or more processing units. The medium may be provided in various forms, including non -transitory forms such as, but not limited to, one or more diskettes, compact disks, tapes, chips, and magnetic and electronic storage. In alternative embodiments, the medium may be transitory in nature such as, but not limited to, wire-line transmissions, satellite transmissions, internet transmissions (e.g., downloads), media, digital and analog signals, and the like. The computer-useable instructions may also be in various formats, including compiled and non-compiled code.
[0055] As used herein, the term “virtual environment" means any computing environment on a device that allows software to act as though it is alone on that deviceand has full control of that device. As understood herein, virtual environments include, but are not limited to, virtual machines and containers.
[0056] As used herein, the term “virtual machine” means the virtualization or emulation of an entire device (e.g., including the CPU, RAM, and peripherals) and requires the provisioning of an entire operating system (i.e., including the kernel of the operating system).
[0057] As used herein, the term “container” means the virtualization or emulation of parts of a device (e.g., in such a way that certain uses of the device are hidden) and non-emulated (but restricted) access to resources present on the host device, such as the kernel of the operating system.
[0058] As used herein, the term “endpoint device” means any networked device in which information flows are consumed and / or generated. Endpoint devices include, but are not limited to, user devices such as laptops, smartphones, tablets, and televisions, as well as Internet of Things (loT) devices, such as refrigerators and smart thermostats. End point devices, as defined herein also include hardware and / or software servers that provide functionality to other endpoint devices.
[0059] As used herein, the term “restricted service" means any network-accessible service where the abilities to read, modify, and / or delete information stored by that service, or cause actions to be taken by that service, is dependent on the identification and / or authentication of the user who is seeking to perform that action.
[0060] As used herein, the term “edge device” means any device that provides an endpoint device with an entry point to a network. Edge devices include, but are not limited to, network access devices (e.g., routers, gateways and Wi-Fi access points) and user devices (e.g., laptops, smartphones, tablets) having tethering capabilities and / or being capable of acting as wireless access points and routers for devices connected thereto.
[0061] As used herein, the term “information flow” means network traffic including, but not limited to, one or more network packets in a packet-switched network.
[0062] As used herein, the term “encrypted tunnel” means an encrypted information flow spanning a public or private network.
[0063] As used herein, the term “active agent” means a continuously running, autonomous piece of software that performs security functions (e.g., information flow management, access and monitoring) in accordance with security policies.
[0064] As used herein, the term “isolated local network" means an isolated network in which packets can travel freely within the network but cannot egress or ingress the network without being subject to security policies carried out by an active agent.
[0065] As used herein, the expression “networking parameters” means any measurable factor or setting that defines a data network or sets conditions of its operation.
[0066] As used herein, the term “metadata” means any data that provides characteristics about information flows, including summaries and interpretations thereof, including potentially verbatim parts of the information flows.
[0067] As used herein, the term “user profile" means a collection of information including the configuration of active agents relating to a use, as well as networking parameters and metadata related to the user. User profiles may also include policies including roles for directing the management of information flows for a user.
[0068] As used herein, the term “network destination" means the destination of an information flow sent by an end point device in a packet switched network. Network destinations include, but are not limited to, endpoint devices on the same or different isolated networks, unrestricted services, restricted services, etc.
[0069] In accordance with the teachings herein, there are provided various embodiments of devices, systems, and methods for providing improved authentication from edge infrastructure.
[0070] The devices, systems, and methods disclosed herein are directed to providing enhanced, secure networking and connectivity from edge infrastructure. The functionalities are delivered by way of user profiles being flexibly deployed and synchronized “at the network edge”. User profiles in accordance with the present disclosure can be deployed to multiple edge locations, and every deployment provides full user device isolation.
[0071] Active agents being instantiated using user profiles in accordance with the present disclosure can be virtualized and designed to run on a wide range of edgeinfrastructure that meet performance and security standards. As such, the devices, systems and methods of the present disclosure offer significant security and performance advantages over known endpoint-based solutions and provide significant flexibility and cost advantages over vendor-specific solutions.
[0072] The edge infrastructure provided by the devices, systems, and methods disclosed herein provides multiple capabilities that are currently poorly delivered via the cloud or via user endpoint devices. By being directly in the stream of data, the edge infrastructure provided by the devices, systems, and methods disclosed herein can authenticate flows of information in sophisticated ways. In prior art systems, these authentication, security, and routing functions are predominately performed on user endpoints, and in infrastructure located in the cloud, as opposed to the edge (e.g., VPNs). Such prior art systems therefore particularly subject to security vulnerabilities, including those resulting from lack of user isolation, lack of unified user risk models, compromised performance, complexity and cost of end point device management, lack of support for increasingly diverse types of endpoints, and compromise of user privacy.
[0073] The devices, systems, and methods disclosed herein solve many of the problems associated with authentication in prior art systems. While most prior art systems manage users’ online connectivity and security on every endpoint device, the devices, systems, and methods disclosed herein manage users’ online connectivity and security via a user profile which includes networking parameters and metadata such as, but not limited to, user authorization credentials, including biometrics, a list of approved user devices authorized on the profile, specific network settings pertaining to approved devices, Domain Name System (DNS) filtering settings, Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) settings, user notification preferences, network traffic routing information, network traffic blocking and authorization settings, baseline traffic definition on a per-profile basis, baseline traffic definition on a per-authorized device basis, anomaly history versus all baselines, and quantitative risk indicators derived from a range of factors, including detected anomalies and past IDS / IPS events. As will be appreciated by the skilled reader, baseline traffic relates to patterns of information flows having specific characteristics (e.g., source, destination, type of data, time of day, etc.).
[0074] As such, the user profiles created, used, updated and synchronized by the devices, systems, and methods disclosed herein do not need to exist on endpointdevices, and are not permanently attached to edge infrastructure, instead, these user profiles exist and are managed securely in the cloud, and deployed, semi-permanently or on-demand temporarily, to edge infrastructure using virtualization, as described in more detail elsewhere herein.
[0075] FIGURE 1 shows a schematic diagram of an implementation of a system 100 in accordance with embodiments of the present disclosure, in this example, system 100 includes edge devices, 101 , 102, 103 and secure cloud infrastructure 113, which is connected to edge device 101 , 102 and 103 via the internet, as disclosed in more detail elsewhere herein. The secure cloud infrastructure is part of the system of the present disclosure and acts as a secure service for managing user profiles and identification and authentication of users and devices. As will be appreciated by the skilled reader, the secure cloud infrastructure can be formed of functionally and / or structurally distributed computing resources forming a cloud-based secure computing environment.
[0076] The system further includes Wi-Fi networks 109, 110, 111 , which may be created at different physical locations, such as a user's home, office and hotel room. For example, network 109 may be created by router 104 at a user’s home, network 110 may be created by router 102 at a user’s office and network 111 may be created by router 105 in a hotel room. Network 109 created by router 104 may have endpoint devices 117, 118, 130 and 132 connected thereto via, for example, a wireless communication protocol such as IEEE 802.11 . Similarly, network 110 created by router 102 may have endpoint devices 128, 129, 119, 120 and 121 connected thereto and network 111 created by router 105 may have endpoint devices 103, 126, 125, 124, 127, 122 and 123 connected thereto.
[0077] As will be appreciated by the skilled reader, the endpoint devices connected to wireless networks 109, 110, 111 may include any suitable endpoint device, including, but not limited to smartphones (such as 132, 118, 120, 122, 124), tablets (such as 130, 123, 126), laptop computers (such as 117, 119, 103), televisions (such as 127), desktop computers (such as 129), printers (such as 121 and 128), and video cameras and / or any other Internet of Things (loT) device (such as 125).
[0078] The system 100 also includes edge devices 101 , 102, 103, configured to establish isolated networks 106, 107, 108, respectively. Isolated networks 106, 107, 108 are created in accordance with security policies forming part of the user profile of the user, as described in more detail elsewhere herein. Edge device 101 may be a dedicatedpiece of hardware that is connected in a wired or wireless way to router 104. Non-limiting examples of edge device 101 include wireless access points and wireless routers. Edge device 102 may be a wireless router 102, which may be provided by an Internet Service Provider (ISP). In some embodiments, edge device 103 may be a laptop with the capability to create a wireless Wi-Fi network.
[0079] The skilled reader will appreciate that edge devices in accordance with the present disclosure need not be of a particular type or manufacturer, provided that they have the software functionality described herein.
[0080] An example edge device 1200 in accordance with the present disclosure is shown in FIGURE 12. In some embodiments, the edge device 1200 includes a router or Wi-Fi access point running an application with storage, communication, and processing means. However, it is contemplated that in other embodiments, other computer systems may be used as an edge device. For example, in some embodiments, the edge device may include a desktop computer, a tablet computer, a laptop, or similar, or in other embodiments, a smart phone running an operating system such as, for example, Android®, iOS®, Windows® mobile, or similar.
[0081] In some embodiments, the edge device 1200 may comprise one or more processors 1201 , one or more networking interfaces 1202, and memory 1205. In some embodiments, the edge device 1200 may also comprise one or more Input / Output (I / O) interface(s) 1203 and a display 1204. The term "processor" as used herein refers to any quantity and combination of a processor and may be provided through the use of dedicated hardware as well as hardware capable of executing software in association with appropriate software. When provided by a processor, the functionality described herein may be provided by a single dedicated processor, by a single shared processor, or by a plurality of individual processors, some of which may be shared. Other hardware, conventional and / or custom, may also be included.
[0082] In some embodiments, one or more processors 1201 , one or more memories 1207 and one or more networking interfaces 1202 are configured for bidirectional data communication through the internal network 1206 of the edge device 1200, and accordingly can include network adaptors and drivers suitable for the type of network used. One or more memories 1205 may include volatile storage and non-volatile storage for storing program code executed by one or more processors 1201 and / or dataused during operation of one or more processors 1201. A memory of one or more memories 1205 may be a semiconductor medium (including, for exampie, a solid-state memory), a magnetic storage medium, an optical storage medium, and / or any other suitable type of memory. In some embodiments, one or more memories 1205 include a virtualized security environment 1207, as described in more detail elsewhere herein.
[0083] In the example shown in FIGURE 1 , edge devices 101 , 102, 103 are configured to connect to a subset of the devices included in networks 109, 110, 111. In particular, edge device 101 is configured to establish an isolated network 106 including endpoint devices 117 and 118, exclusively, edge device 102 is configured to establish an isolated network 107 including endpoint device 119, 120 and 121 , exclusively, and edge device 103 is configured to establish an isolated network 108 including edge device 103 and endpoint devices 122 and 123, exclusively. In the embodiment shown in FIGURE 1 , each isoiated network 106, 107, 108 is established using the same user profile, and in accordance with the method described herein.
[0084] The user profile contains a plurality of networking parameters and metadata associated with the one or more endpoint devices 205 and one or more network destinations, such as restricted service 218. At step 301 , active agent 211 receives the user profile and associates it with the user of endpoint device 205. Then, at step 302, active agent monitors and manages information flows to and from all end point devices associated with the user profile and other network destinations (such as restricted service 218). In some embodiments, active agent 210 may be instantiated as part of a virtual machine 211 , as shown in FIGURE 2, or alternatively, as part of a virtual container, or alternatively, instantiated directly by edge device 102 without any virtualization or containerization.
[0085] As will be appreciated, active agent 211 may use the above method to manage multiple users at once, each according to that user’s user profile.
[0086] Once configured, at step 304, active agent 211 may also establish and remove secure communication links 216 with various network destinations, as required by endpoint devices 205, 209, and in accordance with policies set out in a user’s user profile. For example, a secure communication link (such as an encrypted tunnel / connection) may be established between edge device 200 and a network destination. In the example shown in FIGURE 2, a first encrypted connection 216 isestablished between active agent 211 and restricted service 218. As will be appreciated by the skilled reader, an encrypted connection can include, but is not limited to, access to a remote (e.g. office) LAN. Such access may be established via, for example, IPSec, OpenVPN, etc., or other known protocols. Other examples of encrypted connections include, but are not limited to, a WireGuard™ tunnei, a cloud access security broker (CASB) connection, and a connection secured using secure file transfer protocol (FTPS).
[0087] in some embodiments, an example of which is shown in FIGURE 2, a single active agent 211 running on a single edge device 200 may enact different user profiles associated with different users, and may connect to different endpoint devices 205, 209 using different means, as required. Moreover, a single user may have multiple user profiles (e.g., one associated with work, another associated with persona! use). Active agent 211 is configured to monitor and manage information flows to and from one or more endpoint devices 205, 209. In some embodiments, examples of managing and monitoring information flows to and from one or more endpoint devices 205, 209 include, but are not limited to, the following capabilities.
[0088] In some embodiments, active agent 211 is configured to generate and collect metadata about information flows and endpoint devices. In some embodiments, such metadata may include the timing and volume of information flows, their sources and destinations, the types of resources being accessed (e.g., a web site or a video chat), and the organization(s) responsible for the resource(s) being accessed via that information flow.
[0089] In some embodiments, active agent 211 is configured to record metadata, both locally and at a centralized location. For example, active agent 211 may be configured to record and store metadata locally and send metadata to secure cloud 220 for further processing.
[0090] In some embodiments, active agent 211 is configured to establish behavioral baselines (also known as baseline traffic) for endpoint devices based on stored metadata, where the usual behavior of users and end point devices can be compared to subsequent behaviors to detect compromised endpoint devices, compromised identities, or malicious actions. A non-limiting example of this is a situation in which a corporation may provide employees with access to a suite of software as a service (SaaS) business tools from a first supplier and an employee of the corporationstarts using business tools form a second supplier. In such a situation, the baseline traffic may be characterized as being between an employee’s device(s) and the servers of the first supplier, and a deviation from such baseline traffic may be when information flows are directed towards servers of the second supplier. Another non-limiting example of this is a situation in which baseline traffic to a networked printer is characterized by documents being sent to the printer from various locations, and a deviation from such baseline traffic may be when the printer begins sending out packets to the internet, which deviation could be an indication that the printer has been compromised and is now part of a botnet. As will be appreciated by the skilled reader, in each example, the baseline and deviation can be recognized without knowing anything specific about what is going on, just that an established pattern of usage has changed.
[0091] In some embodiments, active agent 211 is configured to route, encrypt, filter, and attenuate the bandwidth of information flows based on analysis of the stored metadata, and / or based on user profile configuration, for the purposes of enhancing or optimizing security and / or Quality of Service (QoS). In some embodiments, such analysis may be performed locally (e.g., by the active agent 211 , 213 on edge device 200) or remotely by secure cloud 220. In some embodiments, such analysis can be performed by a combination of local and remote analysis, in which some analysis is performed locally on edge device 200 and some remotely on the secure cloud 220, for example.
[0092] In some embodiments, active agent 211 is configured to generate alerts to be sent to the users associated with the user profiles used to instantiate and configure active agents 211 , 213. Such alerts may be sent to the users themselves and / or to one or more contacts at the organization whose restricted services are being accessed.
[0093] With reference to FIGURE 2 and 4, a method for authorizing an endpoint device will now be described. At step 401 , a user opens their laptop 204 and a connection is established between the laptop and the edge device 200. Because the laptop is listed in the user profile that was used to instantiate and configure active agent 211 , active agent 211 will recognize laptop 204 at step 402 as a device listed in the user profile associated with the user.
[0094] At that point, and until the laptop 204 is authorized by the user, active agent 211 will isolate laptop 204 as described elsewhere herein. As such, laptop 204 will not have the ability to send or receive traffic flows through edge device 200 until such timeas the user has authorized laptop 204. Then, at step 404, active agent 211 sends an authorization request to secure cloud 220, which in turn sends an authorization request to the app running on smartphone 205. The app notifies the user that the laptop requires authorization and allows the user to authorize the laptop. Then, at step 405, if authorized by the user, the response is sent to the secure cloud, which in turn sends the authorization to the active agent 211. If no authorization is received by the system from the user, then the system may wait for an authorization to be received or simply not authorize laptop 204. If, on the other hand, an authorization is received, then the active agent 211 is notified by the secure cloud 220 and the laptop is authenticated. Once authenticated, at step 407, active agent 211 monitors and manages information flows between laptop 204 and network destinations using information contained in the user profile. As such, authentication can be “extended” from the user to a new endpoint device, as described in more detail elsewhere herein,
[0095] As described in more detail elsewhere herein, active agent 211 may require authentication of all devices joining the secure network. The authentication process may request a biometric authentication, two-factor or multi-factor authentication, and the like, via the secure cloud 220 and an app running on, for example, a smartphone 205. Other types of authentication may be implemented without diverting from the scope of the disclosure. The system disclosed herein may require ongoing user identity monitoring to ensure "perpetual" authentication.
[0096] In some embodiments, active agent 211 is configured to extended authentication of users to applications running on endpoint devices, as described with reference to FIGURES 6 to 11 , and 13 to 17.
[0097] FIGURE 5 shows a schematic diagram of an instantiated virtualized security environment in accordance with embodiments of the present disclosure. In this example, system 500 includes edge device 102 and secure cloud infrastructure 113, which is connected to edge device 102 via the internet, as disclosed in more detail elsewhere herein. The secure cloud infrastructure 113 is part of the system of the present disclosure and acts as a secure service for managing user profiles and identification and authentication of users and devices. As wili be appreciated by the skilled reader, the secure cloud infrastructure 113 can be formed of functionally and / or structurally distributed computing resources forming a cloud-based secure computing environment.
[0098] The system further includes Wi-Fi network 110 which may be created at different physical locations, such as a user's home, office and hotel room. For exampie, network 110 may be created by router 102 at a user’s home. Network 110 created by router 102 may have endpoint devices 160, 161 , 162, 163, 164, 165 and 166 connected thereto via, for example, a wireless communication protocol such as IEEE 802.11 .
[0099] As will be appreciated by the skilled reader, the endpoint devices connected to wireless network 110 may include any suitable endpoint device, including, but not limited to smartphones (such as 160), tablets (such as 162), laptop computers (such as 163 and 165), televisions (such as 161 ), printers (such as 164), and video cameras and / or any other Internet of Things (loT) device (such as 166).
[0100] The system 100 also includes edge devices (implemented in a container of router 102, in this example) configured to establish isolated network 107. Isolated network 107 is created in accordance with security policies forming part of the user profile of the user, as described in more detail elsewhere herein. Edge device 102 may be a wireless router 102, which may be provided by an Internet Service Provider (ISP).
[0100] The skilled reader will appreciate that edge devices in accordance with the present disclosure need not be of a particular type or manufacturer, provided that they have the software functionality described herein.
[0101] In this example, a laptop 163 is connected to an edge device running an active agent 211 , as described in more detail elsewhere herein. Prior to any application authentication, the secure cloud (e.g., the organization responsible for managing and orchestrating secured networking on edge device 102) and the third-party cloud (e.g., an organization which is associated with an app running on endpoint device 163) exchange a cryptographic key 502. In other embodiments, as described in more detail elsewhere herein, cryptographic key 502 may be shared between the secure cloud 113 and one or more edge devices 502.
[0102] Also, as shown in FIGURE 6, and described in more detail elsewhere herein, the user of endpoint device 163 authenticates themselves to the secure cloud 113 using, for example, biometric authentication through smartphone 160. This also authenticates (to the secure cloud) the device that the user used for authentication (i.e., smartphone 160, in this example). Separately, and as also described elsewhere herein, active agent 211 of edge device 102 authenticates itself with secure cloud 113.
[0103] While the embodiments disclosed herein are described with reference to the authentication of a user, the devices, systems and methods of authentication disclosed herein may be additionally or alternatively applied to the authentication of an edge device 102. Thus, in the embodiments described herein, an edge device 102 may authenticate a user or may authenticate itself (at step 1102 of FIGURE 11 , for example).
[0104] In some embodiments, in situations in which a third-party organization does not require user authentication using the devices, systems and methods described herein, the devices, systems and methods described herein may be used to provide a supplementary factor in a multi-factor authentication process. When a user logs into a third-party app running on an endpoint device and enters a username and password, the third-party app may create a request to authenticate the edge device 102 to which the endpoint device is connected. This may, for example, provide the third-party with an authentication of the location of the edge device 102 (and by extension the location of the endpoint device), thereby providing another authentication factor in, for example, a multi-factor authentication process.
[0105] In this example, as shown in FIGURE 7, the user may connect their laptop 163 to active agent 211 of edge device 102 and uses then authentication capability of their smartphone 160 (as described in more detail elsewhere herein) to authenticate laptop 163 to edge device 102. This authentication state may be maintained by the gateway.
[0106] With reference to FIGURES 8 to 11 , a method in accordance with the present disclosure will now be described. Endpoint device 163 may run any number of applications which may require authentication of an entity, such as a user or an edge device. An application is a software program designed to perform specific tasks for users. Applications can be web-based, mobile, or desktop, and they typically interact with users through a graphical user interface (GUI). While the example provided below relates to web-based applications, the skilled reader will understand that the systems, methods and devices described herein are may be used with any type of application requiring authentication of a user.
[0107] At step 1001 , in some embodiments, an application running on endpoint device 163 issues an authentication request. As used herein, the issuance of an authentication request includes generating an authentication request and sending it to apredetermined destination. In some embodiments, the application running on endpoint device 163 generates an authentication request and sends it to secure cloud 113. In other embodiments, an application running on endpoint device 163 generates an authentication request and sends it to edge device 102.
[0108] The application may be associated with a particular third-party organization. Non-limiting examples of organizations include banks, retail stores, governments, etc. After the user launches the application, the application generates a user authentication request and sends it to secure cloud 113. The user authentication request may include, among other pieces of information, information identifying the third- party organization.
[0109] Then, at step 1002, active agent 211 intercepts the user authentication request in transit through edge device 102 when the application generates an authentication request and sends it to secure cloud 113. It should be noted that it is the active agent’s traffic monitoring capabilities (as described in more detail elsewhere herein) that allow it to intercept entity authentication requests. As will be appreciated by the skilled reader, such an interception may be accomplished by rewriting the destination address of the authentication request packets to be that of the active agent, interpreting and responding to those packets directiy, or other similar, commonly used methods.
[0110] The active agent 211 then associates the authentication request with a user ID by leveraging the authentication confirmation information maintained by active agent 211 itself, as described in more detail elsewhere herein. At step 1003, the edge device then sends the authentication request and information relating to the user ID to secure cloud 113. Accordingly, because the active agent 211 has already authenticated the user in accordance with the methods described herein, once the active agent 211 send the authentication request and the information related to the user ID to the secure cloud 113, the secure cloud can consider that the user has in fact been authenticated. In other words, the secure cloud has previously established trust between itself and the active agent 211 , and the active agent 211 has previously established trust between itself and the user of the end point device.
[0111] The secure cloud 113 may then, at step 1004, encode the information related to the user ID and encrypts it using shared key 502. As will be appreciated by the skilled reader, in all embodiments described herein, any other suitable form of commonencryption method that may be shared between two parties could be used instead of a shared key, such as, for example, a public / private key pair. In some embodiments, the secure cloud 113 also encodes other user metadata in the encrypted token. Non -limiting examples of the metadata that can be encoded and encrypted include information relating to the level of trust associated with the authentication method (e.g., biometric, two-factor authentication, other), information identifying the edge device, as well as its physical location (e.g., home, office, other), and metadata derived from the active agent’s observation of network traffic, as described in more detail elsewhere herein, such as an estimate of the security level of the endpoint device 163 and / or of the local network 109- 111.
[0112] The token is then sent back to the application running on endpoint device 163 via active agent 211 on edge device 102, at step 1005. As will be appreciated by the skilled reader, the token may alternatively be sent to endpoint device 163 via other routes / means.
[0113] Finally, at step 1107, endpoint device 102 may send the authentication token to the third-party cloud for decryption (using shared key 502) and eventual authentication by the third-party by association of the user of the application with the authenticated user identification information.
[0114] In another embodiment, a website may require authentication of a user. In this example, on the endpoint device 163, the user may use a browser to navigate to a website, such a banking website (in this example, ABC Bank). On the login page for the website, there may be a button that states "log on with Company X" (Company X being, for example, the provider of the secure edge services).
[0115] In some embodiments, the button may represent a link to a URL, such as https^ / edge.cyberlucent.com / authVorg^abcbank, which may resolve to a well-known IP address, which the active agent 211 is constantly looking for as packets pass through it, and, when detected, it answers directly instead of passing the connection along. In other words, from the endpoint device’s perspective, whatever edge device 102 that it is connected to is what answers any edge.cyberiucent.com API calls.
[0116] If there is no active agent 211 on edge device 102, any traffic may pass unimpeded to the aforementioned well-known IP address, which may be controlled bythe organization providing secure edge computing services and which returns with data indicating that there is no active agent on edge device 102.
[0117] in some embodiments, before the active agent 211 responds to the HTTPS request, it first contacts the secure cloud 113, sending it information which may include device and / or user IDs of the device and / or user requiring authentication, organization identification information allowing the secure cloud to identify the organization. In some embodiments, the organization identification information can be transmitted from the application by way of the URL, as shown in the example herein (i.e., “auth?org-abcbank'T Another piece of information that wili be implicitly received by secure cloud 113 is the identification information identifying edge device 102.
[0118] In some embodiments, the secure cloud 113 may have pre-established information in respect of the organization. For example, the secure cloud 113 may hold shared key 502, the human-readable name of the organization (e.g., "ABC Bank”, in one or more natural languages) and the redirect URL chosen by the organization that will be used by the active agent 211 to redirect the browser running on the endpoint device 163 once authentication has been completed (e.g., “https: / / abcbank.com / login’5). Furthermore, the secure cloud 113 may keep records of whether the user has consented to share identifiable information with the organization, as well as how much of such information.
[0119] The secure cloud 113 then encrypts a combination of information identifying the endpoint device and / or the user, as well as information identifying the edge device 102 using shared key 502. The result of this encryption is used to create a token, which is then sent to active agent 211 on edge device 102.
[0120] The active agent 211 on edge device 102 then responds to the initiating request initially made by the browser with a redirect to a URL containing information relating to the token (e.g., https^ / abcbank.com / log^lucid^AbCdSF, where “AbCd3F" is the truncated token.
[0121] The organization’s website then decrypts the token that is has received using its copy of shared key 502 and uses the contained identification information to inform its login process. The user is now logged into the organization's website.
[0122] As will be appreciated by the skilled reader, FIGURE 11 shows the method 1100 carried out by edge device 102 in the method carried out by system 500, as shownin FIGURES 8 to 10, in accordance with embodiments of the present invention, in particular, at step 1101 , in some embodiments, active agent 211 intercepts the user authentication request in transit through edge device 102 when the application generates an authentication request and sends it to secure cloud 113.
[0123] Then, at step 1102, active agent 211 authenticates the user by associating the authentication request with a user ID and by leveraging the authentication confirmation information maintained by active agent 211 itself, as described in more detail elsewhere herein. At step 1103, the edge device 102 then sends the authentication request and authentication confirmation information relating to the user ID to secure cloud 113. Accordingly, because the active agent 211 has already authenticated the user in accordance with the methods described herein, once the active agent 211 sends the authentication request and the information related to the user ID to the secure cloud 113, the secure cloud can consider that the user has in fact been authenticated.
[0124] The secure cloud 113 may then encode the information related to the user ID and encrypts it using shared key 502, as described in more detail elsewhere herein, to produce an encrypted authentication token, which the secure cloud 113 sends to the edge device 102. Then, at step 1104, the token is received by the active agent, before it is sent to the application running on endpoint device 163, at step 1105.
[0125] Now, with reference to FIGURE 13 and FIGURE 14, a method of authenticating an entity, such as a user or an edge device, according to another embodiment of the present disclosure will now be described. At step 1401 , end point device browses to a website in the third-party cloud 601. The third-party cloud 601 generates a random (secret) token which is sends to the web app in addition to the session ID cookie, which is received by the edge device 163 at step 1403. The token and session ID are kept associated in the third-party cloud database.(0126] Then, at step 1405 the web app generates and sends an authentication request to the secure cloud, which request contains information identifying the third-party and the random token. As used herein, the issuance of an authentication request includes generating an authentication request and sending it to a predetermined destination. In some embodiments, the application running on endpoint device 163 generates an authentication request and sends it to secure cloud 113. In otherembodiments, an application running on endpoint device 163 generates an authentication request and sends it to edge device 102,
[0127] At step 1406, the authentication request and token are received by active agent 211 , As described elsewhere herein, when received, the active agent 211 appends information identifying a user (e.g., user ID information), and sends it to the secure cloud 113, At step 1408, the secure cloud 113 determines if consent for that third-party has been granted by the user, and if it has, the secure cloud 113 forwards the request, the user ID and the token to the third-party cloud at step 1409,
[0128] Once the request is received, the third-party cloud looks up the contained token in its database, which returns the previously saved session ID, which is that of the web app on the user's laptop. The third-party cloud then updates that session with the user info (i.e, it is now a logged-in session) and then sends a message to the web app which indicates that the session is now logged in.
[0129] Now, with reference to FIGURE 15 and FIGURE 16, a method of authenticating an entity, such as a user or an edge device, according to yet another embodiment of the present disclosure will now be described. This embodiment requires that at some point previously, the secure cloud 113 generated a first public / private key pair for a particular user and distributed the public key widely to all active agents 211 associated with that particular user, the pair also being saved in database of the secure cloud 113. This embodiment also requires that at some point previously, each active agent 211 generates a second public / private key pair and sends the public key to the secure cloud.
[0130] At step 1701, the web app issues an authentication request. As used herein, the issuance of an authentication request includes generating an authentication request and sending it to a predetermined destination. In some embodiments, the application running on endpoint device 163 generates an authentication request and sends it to secure cloud 113. In other embodiments, an application running on endpoint device 163 generates an authentication request and sends it to edge device 102. At step 1702, the active agent intercepts the authentication request and generates and sends an encrypted token to the endpoint device 163 at step 1703. The token may contain the ID of the active agent 211 which performed the interception, which is encrypted using the first public key. It also contains information identifying a user (e.g., user ID), which isencrypted using the second public key. The web app sends this token, at step 1704, to the third-party cloud 601, which it forwards unaltered to the secure cloud 113. At step 1705, the secure cloud 113 receives the encrypted token from the third-party cloud. Because of the mutually authenticated connection between the secure cloud and the third-party cloud, the secure cloud trusts that this request is from the third-party cloud.
[0131] At step 1706, the secure cloud 113 may decrypt the active agent ID contained in the token with its own private key. It may then decrypt the user ID portion using the public key that it has on record for that active agent 211 , which verifies that it was a trusted active agent which generated the token. Then, the secure cloud 113 looks up whether the user has consented to releasing identifying information to that third-party. If so, it responds to the third-party cloud 601 with the user ID, and any other user metadata that the user has consented to release at step 1707. Finally, the third-party cloud 601 updates that session with the user info (i.e. it is now a logged-in session) and responds to the web app indicating that the session is now logged in.
[0132] While the applicant's teachings described herein are in conjunction with various embodiments for illustrative purposes, it is not intended that the applicant’s teachings be limited to such embodiments as the embodiments described herein are intended to be examples. On the contrary, the applicant's teachings described and illustrated herein encompass various alternatives, modifications, and equivalents, without departing from the embodiments described herein, the general scope of which is defined in the appended claims.
Claims
CLAIMS1. A method of authenticating an entity to a third-party application running on an end point device, the third-party application being in communication with a third-party cloud, the method comprising: issuing, from the third-party appii cation running on the end point device, an entity authentication request comprising third-party identification information identifying the third- party; intercepting, at an edge device, the entity authentication request from the third-party application running on the endpoint device; authenticating the entity using identification information which the edge device has associated with the entity; sending an authentication confirmation to the third-party cloud.
2. The method of claim 1 , wherein issuing an entity authentication request comprises generating an entity authentication request and sending it to a secure cloud associated with the edge device.
3. The method of ciaim 1 or 2, where intercepting the entity authentication request is performed by an active agent configured to encrypt, route, attenuate, and / or fiiter information flows through the edge device.4, The method of any one of claims 1 to 3, wherein the method further comprises, after authenticating the entity using identification information which the edge device has associated with the entity: sending information indicative of the authentication to a secure cloud; generating an authentication token and encrypting it with a common encryption method shared with the third-party cioud; and sending the encrypted authentication token to the third-party cioud via the third-party application running on the endpoint device.
5. The method of any one of claims 1 to 3, wherein the method further comprises: establishing a communication session between the third-party application and the third-party cloud; receiving a session token associated with the communication session at the third- party application from the third-party cloud and inciuding the session token with the entity authentication request; and after authenticating the entity using identification information which the edge device has associated with the entity: sending information indicative of the authentication to a secure cloud together with the session token; generating an authentication token associated with the session token and encrypting it with an encryption method shared with the third-party cloud; and sending the encrypted authentication token to the third-party cloud.
6. The method of any one of claims 1 to 3, wherein sending an authentication confirmation to the third-party cloud includes: generating an encrypted authentication token at the edge device with an encryption key shared with the secure cloud; sending the encrypted authentication token from the edge device to the third-party application running on the endpoint device; sending the encrypted authentication token from the third-party application running on the end point device to the third-party cloud; sending the encrypted authentication token from the third-party cloud to the secure cloud; decrypting the encrypted authentication token at the secure cloud and sending authentication confirmation information to the third-party cloud.
7. The method of any one of claims 1 to 6, wherein the entity is a user of the endpoint device and the identification information which the edge device has associated with the entity is information relating to the endpoint device.
8. The method of any one of claims 1 to 6, wherein the entity is the edge device and the identification information which the edge device has associated with the entity is metadata relating to the edge device and / or the endpoint device.
9. A system comprising a plurality of computer processors and one or more computer readable storage media for storing computer-implemented instructions, wherein the pluralityof computer processors are configured to execute the computer-implemented instructions to cause the system to perform the method of any one of claims 1 to 8.
10. A method performed by an edge device to authenticate an entity to a third-party application running on an end point device connected to the edge device, the third-party application being in communication with a third-party cioud, the method comprising: intercepting, at an edge device, an entity authentication request issued from the third- party application running on the end point device, the entity authentication request comprising third-party identification information identifying the third-party; authenticating the entity using identification information which the edge device has associated with the entity; sending an authentication confirmation to the third-party cloud.
11. The method of claim 10, wherein the entity authentication request is intercepted en route to a secure cloud associated with the edge device.
12. The method of claim 10 or 11 , where intercepting the entity authentication request is performed by an active agent configured to encrypt, route, attenuate, and / or fiiter information flows through the edge device.
13. The method of any one of claims 10 to 12, wherein the method further comprises, after authenticating the entity using identification information which the edge device has associated with the entity, sending information indicative of the authentication to a secure cioud.
14. The method of any one of ciaims 10 to 12, wherein sending an authentication confirmation to the third-party cloud includes: generating an encrypted authentication token with an encryption key shared with the secure cioud; and sending the encrypted authentication token to the third-party application running on the end point device.
15. The method of any one of ciaims 10 to 14, wherein the entity is a user of the endpoint device and the identification information which the edge device has associated with the entity is information relating to the endpoint device.
16. The method of any one of claims 10 to 14, wherein the entity is the edge device and the identification information which the edge device has associated with the entity is metadata relating to the edge device and / or the endpoint device.
17. An edge device comprising one or more computer processors and one or more computer readable storage media for storing computer-implemented instructions, wherein the one or more computer processors are configured to execute the computer-implemented instructions to cause the system to perform the method of any one of claims 10 to 16.
18. A non-transitory computer program product comprising computer- implemented instructions to cause a computer system to execute the method of any one of claims 10 to16.
Citation Information
Patent Citations
User and Device Authentication in Enterprise Systems
US20140331060A1
Attribute Based Encryption Key Based Third Party Data Access Authorization
US20240275584A1
Hybrid authentication systems and methods
WO2019000092A1