Agentless Managed Device Identification with Server-Side Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for identifying managed devices rely on client-side agents, which consume resources, require ongoing maintenance, and limit dynamic policy changes, leading to inefficiencies in cybersecurity management.
Innovation Solution
A system that uses an Adaptive Access Control Service (AACS) and Managed Device Identification Service (MDIS) to determine if a device is managed by comparing a client certificate with a stored certificate, allowing for agentless identification and dynamic security policy application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If client-side agents are used for managed device identification, then device identification can be achieved, but system resources are consumed and ongoing maintenance is required
Solution Approach 1:
The patent extracts the identification logic from the client device and relocates it to the server-side authentication service. Instead of running identification software on client devices (agents), the system uses server-based certificate validation to determine device management status, eliminating client resource consumption while maintaining identification reliability
Solution Approach 2:
The patent introduces an intermediary authentication service that mediates between the client device and the security policy enforcement system. This intermediary validates device certificates and determines managed status without requiring direct agent installation on client devices, reducing client resource usage while enabling accurate identification
2Reliability
If client-side agents are used for managed device identification, then device identification can be achieved, but ongoing maintenance and updates are required
Solution Approach 1:
The patent extracts maintenance requirements from client devices and consolidates them on the server side. Certificate validation logic and identification rules are maintained centrally in the authentication service, eliminating the need to update and maintain identification agents on numerous client devices, thereby reducing maintenance complexity while preserving identification accuracy
Solution Approach 2:
The system implements self-service identification where devices automatically present their certificates for validation without requiring manual agent configuration or updates. The authentication service autonomously validates certificates and determines managed status, eliminating the need for ongoing client-side maintenance while maintaining reliable identification
3Reliability
If client-side agents are used for security policy enforcement, then security policies can be applied, but dynamic policy changes are limited
Solution Approach 1:
The patent implements dynamic security policy enforcement where the authentication service can modify policy decisions in real-time based on current device state, user context, and security requirements. Policies are not statically configured in client agents but dynamically evaluated server-side, allowing flexible adaptation to changing conditions while maintaining reliable policy enforcement
Solution Approach 2:
The system incorporates feedback mechanisms where the authentication service continuously evaluates device certificates, user identity, and security context to dynamically adjust policy enforcement. This feedback loop enables real-time policy adaptation without requiring client agent updates, enhancing both policy reliability and dynamicity
4Reliability
If client-side agents are deployed for device identification, then managed devices can be identified, but device complexity increases
Solution Approach 1:
The patent extracts identification functionality from client devices and consolidates it in the server-based authentication service. This centralization simplifies client device architecture by removing agent software while maintaining reliable managed device identification through server-side certificate validation
Solution Approach 2:
The authentication service is designed as a universal component that handles multiple functions: certificate validation, device identification, user authentication, and security policy enforcement. This multi-functional approach consolidates complexity into a single service rather than distributing it across client devices and multiple specialized components
Data Source
AI summary
Systems, methods, and apparatuses directed to efficiently determining whether a device making a request to access an application or service is a managed device and using that information to set an appropriate security policy for the device or the request to access the application or service. In some embodiments, a service or server (referred to as a Managed Device Identification Service) is configured to request a client certificate from a device that is requesting access to a cloud-based application or service as part of a protocol handshake. If a certificate is received, it is compared to a stored certificate to determine if the device is a managed device and as a result, the appropriate security policy.


