Assertion Proxy for Non-Intrusive SSO Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Cloud Access Security Brokers (CASBs) modify the trust relationship between Service Providers (SP) and Identity Providers (IDP) during federated Single Sign-On (SSO), compromising security and violating Service Level Agreements (SLAs) by accessing and modifying assertion contents, which is undesirable for organizations.
Innovation Solution
The Netskope-CASB (N-CASB) functions as an assertion proxy that preserves the trust relationship between SP and IDP by encrypting assertions at the IDP and forwarding them to the SP, preventing access and modification by the CASB, thus maintaining the integrity of the trust relationship and adhering to SLAs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional CASB is inserted to enforce security policies, then security control capability is improved, but the trust relationship between SP and IDP is compromised
Solution Approach 1:
The patent introduces an assertion proxy as an intermediary component that sits between the IDP and SP. The proxy receives assertions from the IDP, enforces security policies, and then forwards validated assertions to the SP. This mediator approach allows security enforcement without requiring the CASB to directly modify or access sensitive assertion contents, thereby preserving the trust relationship while maintaining security control capability.
2Reliability
If a CASB accesses and modifies assertion contents, then security enforcement is improved, but SLA compliance deteriorates
Solution Approach 1:
The patent extracts the security policy enforcement functionality from the assertion content itself and implements it as a separate validation layer in the assertion proxy. Instead of modifying assertion contents to enforce security, the system validates security requirements against the assertion metadata and structure without altering the protected assertion data. This extraction approach maintains both security enforcement and SLA compliance.
3Productivity
If federated SSO is implemented across multiple SaaS applications, then user identity management efficiency is improved, but security policy enforcement complexity increases
Solution Approach 1:
The patent implements a universal assertion proxy that can handle multiple SaaS applications through a single federated SSO infrastructure. The proxy is designed to work with various assertion formats and security policies across different applications, providing multi-functional security enforcement. This universal approach maintains identity management efficiency while managing policy enforcement complexity through a standardized interface.
Data Source
AI summary
The technology disclosed relates to non-intrusively enforcing security during federated single sign-on (SSO) authentication without modifying a trust relationship between a service provider (SP) and an identity provider (IDP). In particular, it relates to an assertion proxy receiving a verified assertion from an IDP obtained from an assertion that is generated when a user logs into a service provider (SP) and is verified in dependence upon the IDP's public key. It also relates to evaluating the verified assertion against one or more security policies. It further relates to forwarding the verified assertion evaluated to the SP and causing establishment of a single sign-on (SSO) authenticated session without modifying the assertion.


