Adaptive Access Platform for Zero Trust Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security architectures are stretched by the distribution of resources across cloud and on-premises infrastructure, leading to fragmentation of identity tools, increased operational overhead, and vulnerabilities, particularly in remote and hybrid work environments, where users access corporate resources from public networks, necessitating a solution for secure authentication and authorization without relying on VPNs.

Innovation Solution

An adaptive access platform that uses an agent and identity tokens to provide context-rich authentication and authorization, considering user, device, and process visibility, with a unified identity plane for granular access control, allowing secure exchange and authorization across distributed IT environments, and integrating with existing systems for enhanced security and reduced user friction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter security and VPN are used to secure distributed access, then network-based security and identity tools can be relied upon, but the attack surface is amplified and security operations are complicated

Engineering Contradiction:
Improvesecurity protectionVSAvoidattack surface
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an adaptive access platform as an intermediary layer between users and distributed resources. This platform implements zero-trust authentication and authorization, replacing reliance on network-based security with identity-based security. The platform mediates all access requests, evaluating contextual factors (device state, location, time, user behavior) to dynamically determine authorization, thereby securing access without requiring VPN tunnels and reducing the attack surface exposed over public networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes authorization parameters based on contextual evaluation. Instead of static permissions, the adaptive access platform continuously assesses multiple parameters (device security posture, geographic location, time of access, user behavior patterns) and adjusts authorization decisions in real-time. This parametric approach enables flexible security control that adapts to changing conditions without expanding the attack surface.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple fragmented identity tools are deployed for cloud and on-premises resources, then coverage across distributed infrastructure is achieved, but operational overhead and complexity increase

Engineering Contradiction:
Improvecoverage of identity toolsVSAvoididentity tool fragmentation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The adaptive access platform serves as a universal identity and authorization system that works across both cloud and on-premises resources. Instead of deploying separate identity tools for different infrastructure types, this single platform provides unified authentication and authorization capabilities that adapt to various resource types and deployment environments, eliminating the need for multiple fragmented identity systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges cloud-based identity management with on-premises security requirements into a single adaptive access platform. By combining these previously separate functions into one unified system, the platform eliminates the operational overhead of managing multiple identity tools while maintaining comprehensive coverage across hybrid infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If granular authorization is implemented through multiple identity silos, then deeper authentication granularity is achieved, but user friction increases and productivity decreases

Engineering Contradiction:
Improveauthorization granularityVSAvoiduser friction
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The adaptive access platform implements dynamic authorization that adjusts granularity based on contextual risk assessment. Instead of applying uniform fine-grained authorization to all access requests, the system dynamically evaluates context (device state, location, time, user behavior) and adjusts the level of authorization scrutiny accordingly. This dynamic approach enables granular control where needed while providing seamless access in low-risk scenarios, maintaining both security precision and user productivity.

Inventive Principle:
Principle #15Dynamics

4Ease of manufacture

If TLS is used for encrypted transport in distributed access, then interoperability and ease of deployment are improved, but authentication for the actor and granular authorization are lacking

Engineering Contradiction:
Improveease of deploymentVSAvoidauthentication and authorization capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The adaptive access platform acts as an intermediary authentication and authorization layer that works in conjunction with TLS-encrypted transport. While TLS provides secure channel encryption, the adaptive platform adds actor authentication and granular authorization capabilities through its zero-trust architecture. This layered approach maintains the ease of TLS deployment while supplementing it with the missing authentication and authorization functionalities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240078295A1Systems, devices and methods for authentication and authorization to provide adaptive access to resources
Publication Date: 2024.03.07 SAILPOINT TECHNOLOGIES INC
  • US20240078295A1 patent drawing
  • US20240078295A1 patent drawing
  • US20240078295A1 patent drawing

AI summary

An apparatus, system, or method for authentication, authorization, and access-control is disclosed. The method includes receiving identity information from one or more sources regarding a user attempting to access a resource. The method also includes consolidating the received identity information into a contextualized identity for the user and determining whether to authenticate the user based on the contextualized identity. The method further includes receiving at least one piece of contextual information related to the user and determining whether to enforce a policy based on the authentication of the contextualized identity and at least one piece of contextual information.