Capability Proxy for Device Authentication Without VPN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise systems require devices to connect to a virtual private network (VPN) or use network edge infrastructure for device authentication when accessing cloud applications, which limits accessibility and introduces complexity.

Innovation Solution

A system that uses a capability proxy on client computing devices to intercept authentication responses and transmit security assertions via an HTTP-based interface, allowing secure device authentication without the need for VPN or network edge infrastructure, enabling operating-system independent authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN or network edge infrastructure is used for device authentication, then security is improved, but device complexity and accessibility are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication capability from the network infrastructure (VPN, firewall) and embeds it directly into the client device through a capability proxy. The security assertion module retrieves authentication tokens locally from the device's secure environment, eliminating the need for network-based authentication intermediaries while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The capability proxy acts as an intermediary component within the client device that mediates between the authentication challenge from the cloud application and the security assertions stored in the device's secure environment. This local intermediary eliminates the need for external network infrastructure intermediaries like VPN servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VPN or network edge infrastructure is used for device authentication, then security is improved, but accessibility is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication capability is extracted from the network infrastructure and embedded directly in the client device. This allows devices to authenticate with cloud applications directly over the public internet without needing to connect to corporate network infrastructure, significantly improving accessibility while maintaining security through local assertion validation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The client device performs self-service authentication by locally retrieving and presenting security assertions to cloud applications. The device independently manages its own authentication credentials and can authenticate with any cloud application supporting the protocol, eliminating dependency on specific network infrastructure and improving ease of operation.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If capability proxy with HTTP-based interface is used, then ease of operation is improved, but device complexity is worsened

Engineering Contradiction:
Improveoperating-system independenceVSAvoidsoftware component complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The capability proxy implements a universal HTTP-based interface that can retrieve and manage multiple types of security assertions and platform features through standardized web protocols. This multi-functional approach allows the same interface to handle authentication, feature access, and credential management across different operating systems, improving ease of operation while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10462121B2Technologies for authentication and single-sign-on using device security assertions
Publication Date: 2019.10.29 INTEL CORP
  • US10462121B2 patent drawing
  • US10462121B2 patent drawing
  • US10462121B2 patent drawing

AI summary

Technologies for remote device authentication include a client computing device, an identity provider, and an application server in communication over a network. The identity provider sends an authentication challenge to the client. A capability proxy of the client intercepts an authentication challenge response and retrieves one or more security assertions from a secure environment of the client computing device. The capability proxy may be an embedded web server providing an HTTP interface to platform features of the client. The client sends a resource access token based on the security assertions to the identity provider. The identity provider verifies the resource access token and authenticates the client computing device based on the resource access token in addition to user authentication factors such as username and password. The identity provider sends an authentication response to the client, which forwards the authentication response to the application server. Other embodiments are described and claimed.