Device Claim Format Conversion for Enterprise Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems lack flexibility and accuracy in determining device attributes for secure access to applications, as they are not configured to process device claims in their conventional forms, such as X.509 certificates, which limits their ability to drive application functionality and ensure trustworthy access.

Innovation Solution

Converting device claims from X.509 certificates into Security Assertion Markup Language (SAML) tokens, allowing applications to process them in a form they can consume, and ensuring their trustworthiness through a remote attestation process, which verifies the device's state and characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device claims are provided in conventional X.509 certificate form, then security and authentication are maintained, but applications cannot process them directly due to format incompatibility

Engineering Contradiction:
ImprovesecurityVSAvoidapplication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a format conversion mechanism that acts as an intermediary between X.509 certificates and application processing requirements. The system converts device claims from X.509 certificate format into application-compatible formats (such as JSON or custom data structures), enabling applications to process device attributes without directly handling cryptographic certificate formats. This intermediary conversion layer maintains security while improving adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the format parameters of device claims from structured cryptographic certificate format (X.509) to application-friendly data formats. This involves transforming the representation of device attributes while preserving the underlying security credentials, allowing applications to access device information in a consumable format without compromising authentication reliability.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If applications directly process device claims without format conversion, then processing speed is improved, but format incompatibility prevents accurate assessment of device attributes

Engineering Contradiction:
Improveprocessing speedVSAvoiddevice attribute accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent performs format conversion in advance, before applications need to process device claims. By pre-converting device claims from X.509 format to application-compatible formats and caching the converted data, the system enables fast application processing without sacrificing attribute accuracy. The preliminary conversion ensures that when applications access device attributes, they receive pre-processed, accurate information in the correct format.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If device claims are converted to application-compatible formats, then application processing capability is improved, but trustworthiness verification becomes more complex

Engineering Contradiction:
Improveapplication processingVSAvoidverification process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the trust verification process from the format conversion process. Instead of verifying trustworthiness after conversion (which would complicate the application layer), the system extracts and verifies device claim authenticity at the conversion stage itself. The format conversion mechanism includes built-in verification that the source X.509 certificate is valid and the device attributes are authentic, separating verification complexity from application processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8528069B2Trustworthy device claims for enterprise applications
Publication Date: 2013.09.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8528069B2 patent drawing
  • US8528069B2 patent drawing
  • US8528069B2 patent drawing

AI summary

Embodiments of the invention enable a client device to procure trustworthy device claims describing one or more attributes of the client device, have those device claims included in a data structure having a format suitable for processing by an application, and use the data structure which includes the device claims in connection with a request to access the application. The application may use the device claims to drive any of numerous types of application functionality, such as security-related and/or other functionality.