Authentication Object Ledger for Forgery Detection in Zero Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current zero trust network security implementations lack stateful, deterministic means for detecting authentication forgeries and fail to track all authentication objects, leading to vulnerabilities in protocols like SAML, Kerberos, and OAuth2, which are exploited by attackers for unauthorized access.
Innovation Solution
Implement a system with a master ledger to store all authentication objects and install authentication object agents at domain controllers and local hosts to track and compare authentication objects in real-time, using stateful deterministic methods to detect and prevent forged authentication attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authentication and authorization processes are used in perimeter-based networks, then users and devices inside the perimeter can access network resources based on traditional authentication, but the security is inadequate when networks span multiple geographic regions and physical environments
Solution Approach 1:
The patent segments the authentication verification process into multiple independent components: a master ledger storing authentication objects at domain controllers, local host log extensions at individual hosts, and a verification system that queries both sources. This segmentation allows the system to maintain security across distributed geographic regions by verifying authentication objects locally and centrally without relying on a single perimeter defense.
2Reliability
If current zero trust network security implementations are used, then network security is improved, but there is no stateful, deterministic means for detecting authentication forgeries
Solution Approach 1:
The patent implements feedback mechanisms where the verification system continuously queries the master ledger and local host log extensions to verify authentication objects. When a mismatch or forgery is detected, the system provides feedback by flagging the authentication attempt as suspicious and can trigger alerts or blocking actions. This stateful verification process maintains deterministic detection capability while preserving zero trust security architecture.
Solution Approach 2:
The patent introduces an intermediary verification system that acts as a mediator between authentication requests and network resource access. This intermediary queries both the master ledger and local host log extensions to verify authentication objects before granting access, providing deterministic detection of forgeries without requiring changes to the underlying zero trust security implementation.
3Measurement precision
If authentication objects are tracked and verified in real-time across the network, then detection of forged authentications is improved, but resource strain on network assets increases
Solution Approach 1:
The patent performs preliminary actions by pre-storing authentication objects in the master ledger at domain controllers and maintaining local host log extensions at each host before authentication requests occur. When authentication requests are made, the verification system queries these pre-populated sources rather than generating or verifying authentication objects in real-time, significantly reducing computational resource strain during actual authentication operations.
Solution Approach 2:
The patent creates copies of authentication objects by storing them in both the master ledger at domain controllers and in local host log extensions at individual hosts. This copying strategy allows the verification system to query local copies first, reducing network traffic and centralized processing requirements, while maintaining the ability to verify authentication objects with high measurement precision.
4Ease of operation
If protocols like SAML, Kerberos, and OAuth2 are used for authentication, then single-sign-on capability is achieved, but vulnerabilities exist that are exploited by attackers for unauthorized access
Solution Approach 1:
The patent applies preliminary anti-action by implementing a verification system that proactively checks authentication objects against the master ledger and local host log extensions before attackers can exploit vulnerabilities in SAML, Kerberos, or OAuth2 protocols. This preliminary verification prevents unauthorized access by detecting forged authentication objects early in the authentication process, countering potential attacks before they can compromise single-sign-on functionality.
Data Source
AI summary
A system and method for implementation of zero trust computer network security combined with stateful authentication object tracking, authentication object manipulation and forgery detection, and assessment of authentication and identity attack surface. The methodology involves gathering all authentication objects issued by a network, storing the authentication objects in a master ledger for use in stateful deterministic authentication object tracking, and running detection functions that compare authentication objects presented for access to network resources with the master ledger. In an embodiment, an authentication object agent is installed at the domain controller level. In another embodiment, a log extension utility is installed at the local host computer level to provide additional log data for additional cyberattack detections.


