Assertion Proxy for Non-Intrusive SSO Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Cloud Access Security Brokers (CASBs) modify the trust relationship between Service Providers (SP) and Identity Providers (IDP) during federated Single Sign-On (SSO), compromising security and violating Service Level Agreements (SLAs) by accessing and modifying assertion contents, which is undesirable for organizations.

Innovation Solution

The Netskope-CASB (N-CASB) functions as an assertion proxy that preserves the trust relationship between SP and IDP by encrypting assertions at the IDP and forwarding them to the SP, preventing access and modification by the CASB, thus maintaining the integrity of the trust relationship and adhering to SLAs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional CASB is inserted to enforce security policies, then security control capability is improved, but the trust relationship between SP and IDP is compromised

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidtrust relationship integrity
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent introduces an assertion proxy as an intermediary component that sits between the IDP and SP. The proxy receives assertions from the IDP, enforces security policies, and then forwards validated assertions to the SP. This mediator approach allows security enforcement without requiring the CASB to directly modify or access sensitive assertion contents, thereby preserving the trust relationship while maintaining security control capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a CASB accesses and modifies assertion contents, then security enforcement is improved, but SLA compliance deteriorates

Engineering Contradiction:
Improvesecurity enforcementVSAvoidSLA compliance
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent extracts the security policy enforcement functionality from the assertion content itself and implements it as a separate validation layer in the assertion proxy. Instead of modifying assertion contents to enforce security, the system validates security requirements against the assertion metadata and structure without altering the protected assertion data. This extraction approach maintains both security enforcement and SLA compliance.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If federated SSO is implemented across multiple SaaS applications, then user identity management efficiency is improved, but security policy enforcement complexity increases

Engineering Contradiction:
Improveidentity management efficiencyVSAvoidsecurity policy enforcement complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal assertion proxy that can handle multiple SaaS applications through a single federated SSO infrastructure. The proxy is designed to work with various assertion formats and security policies across different applications, providing multi-functional security enforcement. This universal approach maintains identity management efficiency while managing policy enforcement complexity through a standardized interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11647010B2Single sign-on access to cloud applications
Publication Date: 2023.05.09 NETSKOPE INC
  • US11647010B2 patent drawing
  • US11647010B2 patent drawing
  • US11647010B2 patent drawing

AI summary

The technology disclosed relates to non-intrusively enforcing security during federated single sign-on (SSO) authentication without modifying a trust relationship between a service provider (SP) and an identity provider (IDP). In particular, it relates to an assertion proxy receiving a verified assertion from an IDP obtained from an assertion that is generated when a user logs into a service provider (SP) and is verified in dependence upon the IDP's public key. It also relates to evaluating the verified assertion against one or more security policies. It further relates to forwarding the verified assertion evaluated to the SP and causing establishment of a single sign-on (SSO) authenticated session without modifying the assertion.