Agent-Based Authorization Delegation for Enterprise Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based network environments lack the configurability and customization necessary to effectively control access to enterprise resources at a device and application-specific level, often allowing unrestricted access to sensitive information and services.
Innovation Solution
A system and method that involves a remote server authorizing client devices and applications to access resources, using an agent application to request and delegate authorization, ensuring that only authenticated and compliant devices and applications can access enterprise resources, with revocable credentials and compliance checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Cloud-based network environments are used to access enterprise resources, then accessibility and convenience are improved, but security control and customization at device and application levels deteriorate
Solution Approach 1:
The patent segments authorization control into multiple levels: user-level, device-level, and application-level. Each layer has its own authorization credentials and policies, allowing granular control over access to enterprise resources. The authorization system divides credentials into different types (device credentials, application credentials, user credentials) that can be independently managed and revoked.
Solution Approach 2:
The patent introduces an authorization server as an intermediary between clients and enterprise resources. This server mediates all access requests by verifying authorization credentials, evaluating policies, and making authorization decisions. The intermediary enables centralized security control while maintaining the convenience of Cloud-based access.
2Ease of operation
If unrestricted access is permitted in Cloud-based environments, then ease of access is improved, but protection of sensitive information and services deteriorates
Solution Approach 1:
The patent implements local quality by assigning different authorization credentials and policies to different applications and devices. Each application receives specific credentials that limit its access to only the enterprise resources it needs, rather than providing blanket access. This ensures that even if one application is compromised, the damage is contained to its specific authorization scope.
Solution Approach 2:
The authorization credentials and policies are dynamic and can be modified in real-time. The system can revoke credentials, update policies, and respond to changing security requirements without requiring changes to the underlying infrastructure. This dynamic control allows the system to adapt to emerging threats while maintaining ease of access for authorized users.
3Reliability
If device-level and application-specific access control is implemented, then security and customization are improved, but system complexity increases
Solution Approach 1:
The patent implements a universal authorization framework that handles multiple types of credentials (user, device, application) and multiple authorization scenarios through a single centralized authorization server. This multi-functional system evaluates different policy types and verifies various credential formats using a common evaluation engine, reducing the need for separate systems for each authorization type.
Solution Approach 2:
The system incorporates feedback mechanisms where the authorization server communicates with clients about authorization decisions, policy violations, and credential status. This feedback loop enables the system to maintain security while providing clear guidance to clients about what access is granted or denied and why, simplifying the user experience despite the underlying complexity.
4Reliability
If centralized policy management is used, then security control is improved, but flexibility and customization at client level may deteriorate
Solution Approach 1:
The patent merges centralized policy management with client-level customization by combining server-side policy evaluation with client-side credential presentation. The centralized server maintains security policies and makes final authorization decisions, while clients have the flexibility to present different types of credentials (device credentials, application credentials, user credentials) and receive customized authorization responses based on their specific needs and contexts.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed are various embodiments for delegating security authorization to at least one application executed on a client device. A computing device is employed to send (305) to a remote server, from an agent application, a request for a first access credential. The first access credential is received (310) from the remote server and a determination is made by the agent application in communication with a managed application, that the managed application requires a second access credential. In response to the determination being made that the managed application requires the second access credential, the second access credential is sent (315) to the managed application, from the agent application. An indication that the agent is authorized to be in communication with managed applications regarding a need for access credentials is stored and the agent application determines where at least one of the managed applications requires an access credential.