Secure privileged access management

The method and system using a broker and agent to establish secure sessions without disclosing client credentials address the challenge of credential leakage, ensuring secure and confidential communication.

WO2026115536A1PCT designated stage Publication Date: 2026-06-04CYATA SECURITY LTD

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
CYATA SECURITY LTD
Filing Date
2025-10-26
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Modern communication technologies increase the difficulty in maintaining confidentiality and integrity of communications due to leakage of client credentials, such as public/private key pairs and passwords, during secure sessions, which can compromise security.

Method used

A method and system utilizing a broker and agent to establish a secure communications session by sequestering client credentials, with the broker acting as an opaque proxy to negotiate encryption keys and maintain a secure pass-through channel without disclosing the credentials to the client or agent, allowing a seamless handover to the client.

Benefits of technology

Ensures secure communication sessions are maintained without exposing client secrets, providing a robust defense against cyberattacks and maintaining confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IL2025050938_04062026_PF_FP_ABST
    Figure IL2025050938_04062026_PF_FP_ABST
Patent Text Reader

Abstract

A method of providing a secure end-to-end encrypted communication session between a client and a server, the method comprising: receiving a request for a secure communications session between a client and a server; responsive to the request establishing a secure session between a secure broker and the server using secret credentials associated with the client that are available to the broker but unavailable to the client; and handing over the session to the client in a handover that preserves session context and does not disclose the secret credentials.
Need to check novelty before this filing date? Find Prior Art

Description

SECURE PRIVILEGED ACCESS MANAGEMENTRELATED APPLICATIONS

[0001] The present application claims the benefit under 35 U.S.C. 119(e) of U.S. Provisional Application 63 / 726,263 filed on November 28, 2024, the disclosure of which is incorporated herein in its entirety by reference.FIELD

[0002] Embodiments of the disclosure relate to methods of protecting confidential material.BACKGROUND

[0003] Modern computer and communications technologies provide a global web of communications networks that supports an intense exchange of information and has democratized the production and consumption of information and accelerated changes in the ways people work and play. The technologies enable the information technology (IT) and the operations technology (OT) that are the bedrocks of today’s society and provide methods, devices, infrastructures, and protocols for controlling industrial equipment, supporting business operations, and generating and propagating data, voice, and video content via the internet. However, the same technologies and the benefits they provide have substantially increased the difficulty in providing and maintaining legitimate personal and collective rights to confidentiality, and in protecting the integrity and safety of the selfsame industrial and business operations that the technologies have enabled against violation and damage from cyberattacks.

[0004] In response to the challenges to maintaining integrity and confidentiality of communications, various security methods and systems have been engineered to prevent, intercept, and defend against infringement of personal and business privacy. Typically, the methods involve constraining communications to be conducted between properly identified parties over secure communications sessions. The secure sessions encrypt messages passed between the parties during the sessions to prevent third party access to information contained in the messages. For example, enterprises generally restrict access to confidential information comprised in their servers to clients that are able to present credentials that identify the clients, demonstrate client privilege to the information, and can establish a secure communication session with the servers over which to access the information. To establish a secure session and access the information, a client requests access to the server and engages in a handshake in which the client presents required credentials and cooperates with the server to establish methods of hashing and encrypting communications between them.

[0005] Whereas once established, a secure session operates to protect communications between a client and a server, the security of the session and that of the client and / or server may be compromised by leakage of confidential data, such as public / private key pairs, permissions, and passwords, of the client credentials. Leakage may by way of example, result from ineffective and / or compromised client security maintenance and / or temporary exposure of the data during the handshake. Mitigating leakage and maintaining advantageous levels of security in the intense environment of modem information exchange over today’s web of interconnected networks, different communications protocols, and devices are complex tasks.SUMMARY

[0006] An aspect of an embodiment of the disclosure relates to methods and systems for establishing a secure communications session between a server and a client application hosted on a user’s (U) user equipment (UE).

[0007] The method comprises sequestering from the client, the user, and the UE a set of secret client credentials that the client requires for establishing a secure session with the server and providing a broker that has access to the client’s credentials and an agent that does not have access to the client credentials for mediating establishment of the session. The agent is configured to establish a secure agent-client communication session, receive a request for the session from the user or from the client, and forward the request to the broker. The broker is configured so that in response to receiving the request from the agent, the broker accesses the client credentials. The broker then controls the agent to operate as an opaque proxy between the broker and the server to establish a secure, optionally TLS, pass-through channel that supports a secure communications session between the broker and the server. In establishing the secure broker-server session, the broker negotiates with the server via the agent a cipher suite and associated encryption keys for the session for the client’s secret credentials to complete establishment of the agent-server session.

[0008] Following establishment, the broker controls the agent to implement a substantially seamless handover of the agent-server session to the client so that the client may communicate with the server via the agent. The handover provides the agent with encryption keys for the session and is performed without disclosing the client secret credentials to either the agent, the client, the user, or the UE. Optionally, the session keys provided to the agent in the handover are encryption keys that have been renegotiated by the broker and server subsequent to establishing the agent-server session. Following the handover the agent operates as a full man- in-the-middle proxy between the server and the client.

[0009] In accordance with an embodiment of the disclosure, a system for implementing the method comprises an agent and a broker configured to cooperate with a client and target server as described above to establish a secure session between the client and server.

[0010] A procedure in accordance with an embodiment of the disclosure for establishing a secure communication session between a client application and a server without disclosing client credentials may be referred to as a zero-knowledge handover or simply “Z-HAND”.

[0011] It is noted that whereas the method is described with respect to providing a secure session between a client and server, the method is not limited to sessions between a client and server. The method may be used to establish a secure session between any communicating endpoints.

[0012] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.BRIEF DESCRIPTION OF THE FIGURES

[0013] Non-limiting examples of embodiments of the invention are described below with reference to figures attached hereto that are listed following this paragraph. Identical structures, elements or parts that appear in more than one figure are generally labeled with a same numeral in all the figures in which they appear. A label labeling an icon representing a given feature in a figure of an embodiment of the disclosure may be used to reference the given feature. Dimensions of components and features shown in the figures are chosen for convenience and clarity of presentation and are not necessarily shown to scale.

[0014] Fig. 1 shows a flow diagram of a Z-HAND method for establishing a secure communications session for communication between a client and server, in accordance with an embodiment of the disclosure; and

[0015] Figs. 2A-2C show a graphical schematic of a Z-Hand system and its operation in implementing a Z-HAND method for establishing a secure communications session, in accordance with an embodiment of the disclosure.DETAILED DESCRIPTION

[0010] In the discussion, unless otherwise stated, adjectives such as “substantially” and “about” modifying a condition or relationship characteristic of a feature or features of an embodiment of the disclosure, are understood to mean that the condition or characteristic is defined to withintolerances that are acceptable for operation of the embodiment in an application for which it is intended. Wherever a general term in the disclosure is illustrated by reference to an example instance or a list of example instances, the instance or instances referred to, are by way of nonlimiting example instances of the general term, and the general term is not intended to be limited to the specific example instance or instances referred to. The phrase “in an embodiment”, whether or not associated with a permissive, such as “may”, “optionally”, or “by way of example”, is used to introduce for consideration an example, but not necessarily required, configuration of possible embodiments of the disclosure. Each of the verbs, “comprise” “include” and “have”, and conjugates thereof, are used to indicate that the object or objects of the verb are not necessarily a complete listing of components, elements or parts of the subject or subjects of the verb. Unless otherwise indicated explicitly or by context, the word “or” in the description and claims is considered to be the inclusive “or” rather than the exclusive or, and indicates at least one of, or any combination of more than one of items it conjoins. Whereas features and actions of flow diagrams shown in the figures and discussed in the specification are presented and discussed substantially in an ordered sequence of flow diagram blocks, the features and actions in a given flow diagram may be undertaken in an order other than that presented in the flow diagram.

[0016] Fig. 1 shows a flow diagram 200 that illustrates setup for and use of a Z-HAND procedure, also referenced by the label 200, in accordance with an embodiment of the disclosure.

[0017] In a block 202 procedure 200 engages in a Z-HAND setup procedure in which a user’s (U) user equipment (UE), an agent, and a secure broker, and optionally a target server, are configured to cooperate in implementing Z-HAND and the agent and broker are configured so that the broker may operate to control the agent to implement Z-HAND. In an embodiment, the setup procedure comprises optionally four setup action items. Whereas the action items are referenced by ordinal numbers for convenience of presentation, the numbers are not intended to indicate an order in which action items are required to be performed and the action items may be performed in an order different from that implied by the ordinals.

[0018] In a first action item an agent is installed, optionally, in the UE. In a second action item at least one or any combination of more than one of the agent, the UE, a client hosted in the UE, and / or a target server, are configured so that all requests to establish a communications session between the client and the server are directed to the agent for processing. Directing requests for a session with the server to the agent may be achieved by any of various methods and may for example be implemented by configuring the agent to listen to a loopback socketto which requests may be directed, configuring a UE internal router table, and / or a DNS cache to direct requests to the agent. Directing requests to the agent may alternatively or additionally be provided by configuring the target server to refuse requests for a session unless received from the agent. In a third action item a secure broker is provided that has access to secret client credentials that are required by the client for establishing a session with the target server but are unavailable to the agent, the client, the U, and the UE. The broker may for example have access to a secure vault to which the agent, client, and UE do not have access and in which the secret client credentials are stored. Alternatively, or additionally the broker may be configured to obtain Just in Time (JIT) credentials, optionally generated by an algorithm configured to generate the JIT and comprised in a vault. In a fourth action item the agent and broker are configured so that they can use any appropriate authentication protocol to establish a secure agent-broker control plane session over which to communicate.

[0019] In a block 204 a user (U) of the UE requests a secure session with the target server for the client application and in a block 206 the request is directed to the agent for example by implementing a procedure discussed above with respect to item 2 of block 202. Whereas the request may have been submitted by the user to the agent, it is assumed for clarity and simplicity of presentation that the request is made by the client in response to the user U invoking the client. In a block 208 the agent and broker establish secure agent-broker session, over which the agent then sends details of the request. Optionally in a block 210 the agent and client establish a secure agent-client communication session. In an embodiment, the secure agent-client session is established by the client and agent negotiating a cipher suite and associated encryption keys for the session and authenticating the session, optionally using placeholder credentials. Optionally, the secure agent-client session is via a loopback interface encrypted using the TLS (Transport Layer Security) protocol.

[0020] In a block 212 the broker controls the agent to act as an opaque proxy between the broker and target server and initiate a setup procedure to establish a secure pass-thorough session between the broker and target server as endpoints. For the setup, in a block 214 the broker controls the agent to open a connection to the target server and on top of the connection the broker and server negotiate via the agent as an opaque proxy a cipher suite and associated encryption keys for the secure pass-through broker-server session. In a block 216 the broker utilizes the client’s secret credentials over the encrypted, encrypted broker-server session to authenticate the session in the name of the client. As in the case of the encryption keys, the agent never “sees” the credentials or the keys.

[0021] In a block 218 the broker optionally renegotiates the broker-server session encryption keys to provide the broker-server session with new session encryption keys. In a block 220 the broker provides the agent with the original or renegotiated encryption keys and instructs the agent to operate in a “forward mode” in which role the agent uses the keys to provide encrypted communications, between the client application and target server via the secure agent-server and agent-client sessions. In the forward mode the agent operates as a full man-in the-middle (MITM) proxy that terminates both the transport layer protocols (e.g. TCPO or UDP) and the encryption / session layer protocols (e.g. TLS or DTLS) associated with the agent-server and agent-client connections to mediate the connection between client and server.

[0022] In an embodiment, optionally in a block 222 the broker instructs the agent to detour or mirror messages transmitted during the session between the client and server to the broker for monitoring.

[0023] Figs. 2A-2C schematically illustrate a Z-Hand system 20 and its operation in implementing a Z-HAND method such as that illustrated by flow diagram 200 for establishing a secure communications session, in accordance with an embodiment of the disclosure. Components of the Z-hand system 20 may include any combination of processing and / or memory resources and computer-executable instructions configured to perform their respective functions. Each component may be implemented on bare-metal hardware, virtualized resources, or a combination thereof.

[0024] Fig. 2A schematically shows Z-Hand system 20 processing a request from a user U to connect an App A3 from among a group of Apps 38 (Al, A2 . . . AN) hosted in the user’s UE 30 to a server S3 from a group of servers 100 (SI, S2 ... SM 100) in the internet, in accordance with an embodiment of the disclosure. Z-Hand system 20 comprises a Z-Hand agent 22, optionally hosted in the user UE 30, a secure broker 24, and a vault 26 in which user U credentials are stored. User equipment UE 30 comprises an IP stack 32, a loopback interface 34, and an input device optionally a keyboard 36. Embodiments of Z-Hand agent 22, broker 24, vault 24, and UE IP stack and loopback interface 34 and how they are configured in accordance with an embodiment to cooperate to establish a secure communication channel that supports sessions between two network entities are described above with reference to flow chart 200.

[0025] Fig. 2A shows user U inputting a request represented by arrows 40 directed from keyboard 36 through A3 to IP stack 32 to connect App A3, with server S3. Conventionally, after entering IP stack 32, request 40 would be forwarded by the stack to S3 via an external network interface (not shown) and an outbound communication channel represented by adashed arrow 40x. However, in accordance with an embodiment IP stack 32 is configured to forward requests for connecting an App 38 to a server 100 to Z-Hand agent 22. Fig. 2A therefore schematically shows outbound channel 40x “X-d” to indicate it is unavailable to the request and the request forwarded as indicated by arrows 40' to loopback interface 34 for reception by Z-Hand agent 22, which is configured to listen to loopback interface 34. In accordance with an embodiment, Z-Hand agent 22 notifies Z-Hand broker 24 of the request in a message 40" transmitted to the broker, optionally over a secure channel represented by a block arrow 50.

[0026] As schematically shown in Fig. 2B, responsive to receiving notification of user request 40, Z-Hand broker 24 accesses vault 26 and downloads from the vault secret credentials represented by a double headed arrow 26' via a secure channel 52 that A3 is required to present to server S3 to establish a secure session with the server. Broker 24 controls Z-Hand agent 22 to operate as an opaque proxy between the broker and target server and uses the downloaded credentials to establish a secure pass-thorough channel 60 that supports a secure session between the broker and target server as endpoints. In an embodiment pass-through channel 60 comprises a TLS secure channel terminated at Z-Hand broker 24 and server S3 on top of TCP channels (not shown) terminated at broker 24 and Z-Hand agent 22 and Z-Hand agent 22 and server S3.

[0027] In an embodiment following establishment of secure pass-through channel 60 shown in Fig. 2B Z-Hand broker 24 optionally renegotiates encryption keys, tears down the TCP channel between the broker and Z-Hand agent 22 that supports pass-through channel 60 and provides the agent with the original or renegotiated encryption keys. The broker reconfigures the TCP channel between Z-Hand agent 22 and server S3 that supported pass-through channel 60 as a secure channel 60* that terminates at Z-Hand agent 22 and connects to secure channels 54 and uses the encryption keys provided by Z-Hand broker 24 to support secure communications between server S3 App A3. Following establishment of secure channel 60*, Z-Hand agent 22 operates as a full man-in the-middle (MITM) proxy that terminates both the transport layer protocols (e.g. TCPO or UDP) and the encryption / session layer protocols (e.g. TLS or DTLS) associated with the Z-Hand agent-server S3 and Z-Hand agent-app A3 connections to mediate the connection between app A3 and server S3.

[0028] There is therefore provided in accordance with an embodiment of the disclosure a method of providing a secure end-to-end encrypted communication session between a first resource and a second resource, the method comprising: receiving a request from a first resource for a secure communications session with a second resource; responsive to the requestestablishing a secure pass-through session via an agent operating as a pass-through opaque proxy between a secure broker and the second resource and using secret credentials associated with the first resource that are available to the broker but unavailable to the first resource and the agent; and handing over the session to the first resource in a handover that preserves session context and does not disclose the secret credentials to the first resource or the agent. Optionally, using the secret credentials comprises accessing the credentials from a secure vault. Additionally, or alternatively, using the secret credentials may comprise generating a just-in- time (JIT) set of credentials.

[0029] In an embodiment the secure pass-through connection comprises a transport layer connection between the broker and the agent and a transport layer connection between the agent and the second resource. Optionally, the transport layer connections comprise a connection oriented transport layer connection. Additionally, or alternatively the transport layer connections may comprise a connectionless transport layer connection. In an embodiment the secure pass-through session is established on top of the transport layer connections.

[0030] In an embodiment handing over the session to the first resource comprises tearing down the transport layer connection between the broker and the agent. Optionally, handing over the session comprises establishing at least one communication channel between the agent and the first resource. Optionally, the at least one communication channel between the agent and first resource is a secure connection. Additionally, or alternatively, handing over the session comprises controlling the agent to operate as a full man-in-the-middle (MITM) proxy between the second resource and the first resource via the transport layer connection between the agent and the second resource and the at least one connection between the agent and the first resource.

[0031] In an embodiment handing over the session comprises providing the agent with encryption keys negotiated between the broker and second resource in establishing the secure pass-through connection between. Optionally, handing over the session comprises renegotiating the encryption keys prior to handing over the session.

[0032] In an embodiment the method comprises configuring the agent to receive the request and notify the broker of the request. Optionally, the method comprises configuring the broker to operate to control the agent in establishing the secure pass-through session responsive to receiving the request. In an embodiment the method comprises configuring the broker to operate to handover the secure pass-through session to the first resource.

[0033] In an embodiment the first resource is a client hosted in a user equipment (UE). In an embodiment the method comprises the second resource is a server.

[0034] There is further provided in accordance with an embodiment of the disclosure a method of providing a secure end-to-end encrypted communication session between a client and a server, the method comprising: receiving a request for a secure communications session between a client and a server; responsive to the request establishing a secure session between a secure broker and the server using secret credentials associated with the client that are available to the broker but unavailable to the client; and handing over the session to the client in a handover that preserves session context and does not disclose the secret credentials.

[0035] There is also provided in accordance with an embodiment of the disclosure a system comprising bare metal and / or virtualized components having computer executable instructions for performing any of the methods disclosed in the above discussions.

[0036] In the description and claims of the present application, each of the verbs, “comprise” “include” and “have”, and conjugates thereof, are used to indicate that the object or objects of the verb are not necessarily a complete listing of components, elements or parts of the subject or subjects of the verb.

[0037] Descriptions of embodiments of the disclosure in the present application are provided by way of example and are not intended to limit the scope of the disclosure. The described embodiments comprise different features, not all of which are required in all embodiments. Some embodiments utilize only some of the features or possible combinations of the features. Variations of embodiments of the disclosure that are described, and embodiments comprising different combinations of features noted in the described embodiments, will occur to persons of the art. The scope of the invention is limited only by the claims.

Claims

CLAIMS1. A method of providing a secure end-to-end encrypted communication session between a first resource and a second resource, the method comprising: receiving a request from a first resource for a secure communications session with a second resource; responsive to the request establishing a secure pass-through session via an agent operating as a pass-through opaque proxy between a secure broker and the second resource and using secret credentials associated with the first resource that are available to the broker but unavailable to the first resource and the agent; and handing over the session to the first resource in a handover that preserves session context and does not disclose the secret credentials to the first resource or the agent.

2. The method according to claim 1 wherein using the secret credentials comprises accessing the credentials from a secure vault.

3. The method of according to claim 1 wherein using the secret credentials comprises generating a just-in-time (JIT) set of credentials.

4. The method according to claim 1 wherein the secure pass-through connection comprises a transport layer connection between the broker and the agent and a transport layer connection between the agent and the second resource.

5. The method according to claim 4 wherein the transport layer connections comprise a connection oriented transport layer connection.

6. The method according to claim 4 wherein the transport layer connections comprise a connectionless transport layer connection.

7. The method according to claim 4 wherein the secure session is established on top of the transport layer connections.

8. The method according to claim 4 wherein handing over the session to the first resource comprises tearing down the transport layer connection between the broker and the agent.

9. The method of claim 8 wherein handing over the session comprises establishing at least one communication channel between the agent and the first resource.

10. The method of claim 9 wherein the at least one communication channel between the agent and first resource is a secure connection.

11. The method according to claim 9 wherein handing over the session comprises controlling the agent to operate as a full man-in-the-middle (MITM) proxy between the second resource and the first resource via the transport layer connection between the agent and the second resource and the at least one connection between the agent and the first resource.

12. The method according to claim 1 wherein handing over the session comprises providing the agent with encryption keys negotiated between the broker and second resource in establishing the secure pass-through connection between.

13. The method of claim 12 wherein handing over the session comprises renegotiating the encryption keys prior to handing over the session.

14. The method according to claim 1 and comprising configuring the agent to receive the request and notify the broker of the request.

15. The method according to claim 14 and comprising configuring the broker to operate to control the agent in establishing the secure pass-through session responsive to receiving the request.

16. The method according to claim 1 and comprising configuring the broker to operate to handover the secure pass-through session to the first resource.

17. The method according to claim 1 wherein the first resource is a client hosted in a user equipment (UE).

18. The method according to claim 1 wherein the second resource is a server.

19. A method of providing a secure end-to-end encrypted communication session between a client and a server, the method comprising: receiving a request for a secure communications session between a client and a server; responsive to the request establishing a secure session between a secure broker and the server using secret credentials associated with the client that are available to the broker but unavailable to the client; and handing over the session to the client in a handover that preserves session context and does not disclose the secret credentials.

20. A system comprising bare metal and / or virtualized components having computer executable instructions for performing the method of any of claims 1-19.