Access Credential Locker for Scalable Zero-Trust Enterprise Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN solutions struggle to scale quickly in response to sudden changes in user access needs, such as during 'work from home' scenarios, and may not adequately secure access to cloud-hosted enterprise systems.
Innovation Solution
The implementation of a secure access service edge (SASE) with a zero-trust framework, utilizing a client intelligent application (CIA) on user devices, an SASE intelligent application (SIA) on the SASE, and a cloud access module (CAM) on the enterprise edge, to establish communication sessions using access credentials decrypted with keys from both the user device and the enterprise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional VPN solutions are used to provide access to enterprise systems, then security can be maintained, but the system cannot scale quickly in response to sudden changes in user access needs
Solution Approach 1:
The system segments the authentication process into multiple independent components: access credentials are divided into shareable portions distributed to users and non-shareable portions retained by the enterprise. This segmentation allows the system to scale by adding users without requiring centralized authentication infrastructure, while maintaining security through distributed credential verification.
Solution Approach 2:
The patent introduces an intermediary credential structure that mediates between users and enterprise systems. The access credential acts as a self-contained authentication token that enables direct user-to-system communication without requiring traditional VPN gateway infrastructure, thus improving scalability while maintaining security through the credential's embedded verification mechanisms.
2Ease of operation
If access credentials are stored centrally for easy retrieval, then access ease is improved, but security is compromised as the central storage becomes a target for attacks
Solution Approach 1:
The access credential is segmented into multiple portions with different security characteristics. Shareable portions can be distributed to users for easy access, while non-shareable portions remain securely stored by the enterprise. This segmentation eliminates the need for a single central storage target, reducing security risks while maintaining access ease through distributed credential components.
Solution Approach 2:
Different portions of the access credential have different security qualities assigned to them based on their function. The shareable portion is designed for easy distribution and use by users, while the non-shareable portion is designed for secure enterprise retention and verification. This local quality differentiation allows each component to be optimized for its specific purpose without compromising overall security.
Data Source
AI summary
A processing system may obtain a request from a user device to activate an access credential locker for use in accessing at least one enterprise system of an enterprise via the processing system, the request comprising a token that identifies the access credential locker, obtain a first key from the user device, transmit, to the enterprise, a request for a second key, obtain the second key from the enterprise in response to the request, apply the first key and the second key to the access credential locker, the access credential locker being encrypted in accordance with the first and second keys and being decrypted via the applying of the first and second keys, and establish a communication session between the user device and the at least one enterprise system via the processing system using at least one access credential that is stored in the decrypted access credential locker.


