Device Claim Format Conversion for Enterprise Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems lack flexibility and accuracy in determining device attributes for secure access to applications, as they are not configured to process device claims in their conventional forms, such as X.509 certificates, which limits their ability to drive application functionality and ensure trustworthy access.
Innovation Solution
Converting device claims from X.509 certificates into Security Assertion Markup Language (SAML) tokens, allowing applications to process them in a form they can consume, and ensuring their trustworthiness through a remote attestation process, which verifies the device's state and characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device claims are provided in conventional X.509 certificate form, then security and authentication are maintained, but applications cannot process them directly due to format incompatibility
Solution Approach 1:
The patent introduces a format conversion mechanism that acts as an intermediary between X.509 certificates and application processing requirements. The system converts device claims from X.509 certificate format into application-compatible formats (such as JSON or custom data structures), enabling applications to process device attributes without directly handling cryptographic certificate formats. This intermediary conversion layer maintains security while improving adaptability.
Solution Approach 2:
The patent changes the format parameters of device claims from structured cryptographic certificate format (X.509) to application-friendly data formats. This involves transforming the representation of device attributes while preserving the underlying security credentials, allowing applications to access device information in a consumable format without compromising authentication reliability.
2Productivity
If applications directly process device claims without format conversion, then processing speed is improved, but format incompatibility prevents accurate assessment of device attributes
Solution Approach 1:
The patent performs format conversion in advance, before applications need to process device claims. By pre-converting device claims from X.509 format to application-compatible formats and caching the converted data, the system enables fast application processing without sacrificing attribute accuracy. The preliminary conversion ensures that when applications access device attributes, they receive pre-processed, accurate information in the correct format.
3Adaptability or versatility
If device claims are converted to application-compatible formats, then application processing capability is improved, but trustworthiness verification becomes more complex
Solution Approach 1:
The patent extracts the trust verification process from the format conversion process. Instead of verifying trustworthiness after conversion (which would complicate the application layer), the system extracts and verifies device claim authenticity at the conversion stage itself. The format conversion mechanism includes built-in verification that the source X.509 certificate is valid and the device attributes are authentic, separating verification complexity from application processing.
Data Source
AI summary
Embodiments of the invention enable a client device to procure trustworthy device claims describing one or more attributes of the client device, have those device claims included in a data structure having a format suitable for processing by an application, and use the data structure which includes the device claims in connection with a request to access the application. The application may use the device claims to drive any of numerous types of application functionality, such as security-related and/or other functionality.


