Access Credential Locker for Scalable Zero-Trust Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN solutions struggle to scale quickly in response to sudden changes in user access needs, such as during 'work from home' scenarios, and may not adequately secure access to cloud-hosted enterprise systems.

Innovation Solution

The implementation of a secure access service edge (SASE) with a zero-trust framework, utilizing a client intelligent application (CIA) on user devices, an SASE intelligent application (SIA) on the SASE, and a cloud access module (CAM) on the enterprise edge, to establish communication sessions using access credentials decrypted with keys from both the user device and the enterprise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional VPN solutions are used to provide access to enterprise systems, then security can be maintained, but the system cannot scale quickly in response to sudden changes in user access needs

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the authentication process into multiple independent components: access credentials are divided into shareable portions distributed to users and non-shareable portions retained by the enterprise. This segmentation allows the system to scale by adding users without requiring centralized authentication infrastructure, while maintaining security through distributed credential verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential structure that mediates between users and enterprise systems. The access credential acts as a self-contained authentication token that enables direct user-to-system communication without requiring traditional VPN gateway infrastructure, thus improving scalability while maintaining security through the credential's embedded verification mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access credentials are stored centrally for easy retrieval, then access ease is improved, but security is compromised as the central storage becomes a target for attacks

Engineering Contradiction:
Improveaccess easeVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The access credential is segmented into multiple portions with different security characteristics. Shareable portions can be distributed to users for easy access, while non-shareable portions remain securely stored by the enterprise. This segmentation eliminates the need for a single central storage target, reducing security risks while maintaining access ease through distributed credential components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the access credential have different security qualities assigned to them based on their function. The shareable portion is designed for easy distribution and use by users, while the non-shareable portion is designed for secure enterprise retention and verification. This local quality differentiation allows each component to be optimized for its specific purpose without compromising overall security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250117470A1Access to cloud-distributed applications via access credential locker service
Publication Date: 2025.04.10 AT&T INTELLECTUAL PROPERTY I L P
  • US20250117470A1 patent drawing
  • US20250117470A1 patent drawing
  • US20250117470A1 patent drawing

AI summary

A processing system may obtain a request from a user device to activate an access credential locker for use in accessing at least one enterprise system of an enterprise via the processing system, the request comprising a token that identifies the access credential locker, obtain a first key from the user device, transmit, to the enterprise, a request for a second key, obtain the second key from the enterprise in response to the request, apply the first key and the second key to the access credential locker, the access credential locker being encrypted in accordance with the first and second keys and being decrypted via the applying of the first and second keys, and establish a communication session between the user device and the at least one enterprise system via the processing system using at least one access credential that is stored in the decrypted access credential locker.