Agentless Single Sign-On With Encrypted Protocol Data Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network identity access methods face security vulnerabilities, such as impersonation and port forwarding, leading to single points of failure and limited functionality, especially when gateways are compromised.

Innovation Solution

A system and method using encryption and existing communication protocols to securely manage network identity access, enabling actions on resources without complex setups, adaptable to new protocols and identities, utilizing a gateway to encrypt and decrypt data elements using standard fields.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If port forwarding techniques are used for network identity access, then access to trusted resources is enabled, but security vulnerabilities and single points of failure arise

Engineering Contradiction:
Improveaccess to resourcesVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between network identities and resources. Instead of direct port forwarding, the system uses protocol data elements (PDEs) as intermediaries to carry authentication information, eliminating the need for complex port forwarding setups while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical port forwarding mechanism with a data-driven approach using protocol data elements. Instead of configuring network ports and forwarding rules, the system substitutes these with encrypted data elements that carry authentication information within existing protocol packets.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If port forwarding is used for network access, then resource access is enabled, but device complexity and setup requirements increase

Engineering Contradiction:
Improveresource access capabilityVSAvoidsetup complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes existing communication protocols universal by embedding multiple functions within them. The protocol data elements serve multiple purposes: authentication, authorization, and action transmission all within the same protocol framework, eliminating the need for separate port forwarding configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the fundamental parameters of how access is controlled. Instead of using network layer parameters (ports, routing tables), the system uses data element parameters (encrypted PDEs, authentication tokens) that can be carried within any existing protocol packet, simplifying the setup significantly.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If port forwarding techniques are used, then access to trusted resources is possible, but functionality is limited to simple access actions

Engineering Contradiction:
Improveresource accessVSAvoidaction versatility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic action specification through protocol data elements. Instead of static port forwarding rules, the system uses dynamic PDEs that can specify different actions (file access, printing, logging) based on the content of the data elements, allowing versatile functionality to be dynamically assigned.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary authentication and authorization actions before resource access. The system pre-processes authentication information into protocol data elements during the authentication phase, so that when resource access is needed, the actions to be performed are already determined and encoded in the PDEs.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If encryption is used to secure data elements, then security is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs encryption and authentication actions in advance during the initial authentication phase. Protocol data elements are encrypted and prepared beforehand, so that when resource access is requested, the heavy computational burden of encryption has already been performed, allowing faster subsequent access operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous authentication context through protocol data elements. Once authenticated, the PDEs carry authentication information throughout the session, eliminating the need for repeated encryption and authentication operations, thus reducing overall time loss while maintaining security.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12432048B2Agentless single sign-on techniques
Publication Date: 2025.09.30 CYBER ARK SOFTWARE LTD
  • US12432048B2 patent drawing
  • US12432048B2 patent drawing
  • US12432048B2 patent drawing

AI summary

Described herein are methods, systems, and computer-readable storage media for using a network identity. Techniques may include obtaining and encrypting a first data element using an encryption key and storing the encrypted first data element mapped to a network identity. Techniques may further include receiving a request from the network identity to perform an action on a resource and authenticating the network identity using an existing protocol, decrypting the first data element using a second data element calculated based on standard fields of the existing protocol, and enabling the action on the resource using the first data element.