Authentication Proxy for Cloud Application Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication solutions for cloud-based applications do not differentiate between managed and unmanaged client devices, leading to security vulnerabilities as they do not consider the varying security levels of devices accessing the applications, potentially allowing unauthorized access and data breaches.

Innovation Solution

A method and system that utilize a compliance server to assess the device posture of client devices, determining access policies based on their security configurations, and an authentication proxy to grant or deny access to cloud-based applications accordingly, ensuring that only compliant devices with adequate security measures can access sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication solutions (username and password) are used for cloud-based applications, then ease of operation is improved, but security is worsened because they do not differentiate between managed and unmanaged client devices

Engineering Contradiction:
Improveauthentication processVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements device-specific authentication by evaluating individual device attributes (OS type, version, security software, hardware configuration) and assigning different trust levels and access policies to each device. This allows the system to treat each client device uniquely based on its security posture rather than applying uniform authentication to all devices.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary authentication system that sits between the user and the cloud-based application. This intermediary evaluates device posture, determines trust levels, and enforces access policies before allowing access to the application, thereby adding a security layer without significantly impacting user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device-specific access control is implemented, then security is improved by differentiating between managed and unmanaged devices, but device complexity increases due to additional authentication requirements

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs device evaluation and trust level determination in advance, before the user attempts to access the cloud-based application. By pre-assessing device posture and configuring appropriate access policies beforehand, the system reduces the complexity of real-time authentication decisions and streamlines the actual access process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the authentication parameters from simple username/password verification to a multi-factor evaluation including device attributes, security software presence, OS version, and hardware configuration. This parameter expansion enables more granular security control while maintaining systematic management through policy-based enforcement.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11115417B2Secured access control to cloud-based applications
Publication Date: 2021.09.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11115417B2 patent drawing
  • US11115417B2 patent drawing
  • US11115417B2 patent drawing

AI summary

A method and proxy device for securing an access to a cloud-based application are presented. In an embodiment, the method includes receiving an authentication token that includes an identity of a user of a client device requesting an access to the cloud-based application. The method further includes receiving, from an agent executed in the client device, a client certificate; retrieving, from a compliance server, a device posture of the client device, wherein the device posture is retrieved respective of the received client certificate; identifying an access policy for the client device to access the cloud-based application, and determining whether to grant an access to the cloud-based application based in part on the compliance of the client device with the identified access policy. In an embodiment, the access policy is identified based at least on the retrieved device posture.