Cloud Identity Access Token Detection via API Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches to securing access credentials in cloud computing environments are often complex, time-consuming, costly, and require specific security knowledge, making it difficult for organizations to effectively manage and detect compromised or unsecured access tokens, which can lead to security risks such as unauthorized data access or cryptocurrency mining operations.

Innovation Solution

The solution involves associating access tokens with digital signatures and additional identifying information, which are inserted into API communications between managed network resources and cloud environments, allowing for the identification of potentially compromised access tokens by analyzing API communication logs and comparing them against trusted validation resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security measures are implemented for access credentials (secure storage, periodic rotation, monitoring, auditing), then security reliability is improved, but device complexity and time consumption increase significantly

Engineering Contradiction:
Improveaccess credentials securityVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based security service as an intermediary that manages access credential security. This service handles signature generation, validation, and monitoring, transferring the security management burden from the organization's internal systems to an external specialized service, thereby reducing local complexity while maintaining high security standards

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal security management system that can handle multiple access credentials, multiple cloud environments, and various security operations (rotation, monitoring, validation) through a single platform. This multi-functional approach consolidates numerous security tasks into one system, reducing overall management complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security measures are implemented for access credentials including monitoring and auditing, then security reliability is improved, but loss of time increases due to significant time and effort required for management

Engineering Contradiction:
Improveaccess credentials securityVSAvoidtime for security management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements automated self-service mechanisms where the security system automatically generates signatures, validates credentials, detects compromises, and performs rotations without requiring manual intervention. This automation eliminates time-consuming manual security management tasks while maintaining comprehensive monitoring and auditing capabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary security actions by pre-generating signatures and establishing validation rules before access credentials are compromised. The system proactively monitors and detects potential security issues before they can cause harm, reducing the time needed for reactive security responses

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If digital signatures and identifying information are associated with access tokens and inserted into API communications, then measurement precision for detecting compromised tokens is improved, but device complexity increases

Engineering Contradiction:
Improvecompromised access token detection accuracyVSAvoidAPI communication structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the security validation logic from the core API communication flow and places it in a separate cloud-based security service. The digital signatures are generated and validated as distinct security layers, allowing precise detection of compromised tokens without entangling the validation complexity with the main API communication structure

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11223480B2Detecting compromised cloud-identity access information
Publication Date: 2022.01.11 CYBER ARK SOFTWARE LTD
  • US11223480B2 patent drawing
  • US11223480B2 patent drawing
  • US11223480B2 patent drawing

AI summary

Systems and methods are provided for identifying potentially compromised cloud-based access information. The systems and methods include providing a unique signature for insertion into application programming interface (API) communications to be sent from a network resource to a cloud application executable in a cloud environment. The unique signature can be associated with an access token that a particular identity can use to request access to the cloud application. The systems and methods include accessing a log associated with the cloud environment, identifying the unique signature and the access token using information in the log, accessing a trusted validation resource storing signature information associated with the access token, determining whether the unique signature is valid, and determining whether the access token is potentially compromised.