Authentication Agent for Secure Sensitive Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in accessing sensitive work-related content on portable devices due to security limitations in browser applications, which can restrict access or require inconvenient software usage.
Innovation Solution
Implementing a separate authentication agent on the client device that manages sensitive data securely, allowing it to be stored in a secure location inaccessible to unsecure applications, while enabling access to restricted content through a conventional browser by rendering content remotely and transmitting only image data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive content is accessed through conventional browsers on portable devices, then user convenience is improved, but security is compromised due to browser limitations
Solution Approach 1:
The system segments the access process into two distinct components: a conventional browser for user interaction and an authentication agent for security management. The browser handles user convenience while the agent enforces security policies, allowing both requirements to be satisfied simultaneously through functional separation.
Solution Approach 2:
The authentication agent acts as an intermediary between the user/browser and the sensitive content. It mediates all access requests by verifying credentials and enforcing security policies, allowing the browser to remain simple and convenient while the agent ensures security requirements are met.
2Reliability
If specific security software is required to access sensitive content, then security is improved, but user convenience deteriorates due to restrictive usage requirements
Solution Approach 1:
The authentication agent provides universal security functionality that works across multiple browser applications and devices. Instead of requiring specific security software, the agent implements a standardized authentication mechanism that can be accessed through any conventional browser, making the security solution both secure and convenient.
3Ease of operation
If authentication credentials are stored in the browser, then access is simplified, but security is compromised as credentials become accessible to unsecure applications
Solution Approach 1:
The authentication credentials are extracted from the browser environment and stored separately in a secure location managed by the authentication agent. This separation removes the harmful factor of credential exposure while maintaining the benefit of simplified access through the agent's secure management.
Solution Approach 2:
The authentication agent serves as an intermediary that manages credential storage and retrieval securely. Credentials are stored in a protected location inaccessible to the browser, and the agent mediates access by providing credentials only when authentication is verified, preventing exposure while enabling access.
Data Source
AI summary
An agent can be installed that is separate from an unsecure application, such as a third party browser, executing on a client device. Content to be displayed by, or accessible to, the application can be rendered or determined remotely, such that only unrestricted data is received by the application. Restricted data to be stored on the device, as may include one or more authentication credentials, can be transmitted over a secure connection to the agent, which can store the sensitive information to a secure location on the client device that is inaccessible to the application. Such management allows the sensitive information to be stored on the client device and provided with requests for restricted data, for example, while preventing the restricted data from being exposed to the application on the client device.


