Device Trust Verification for Spoof-Resistant Request Origination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack effective methods to detect and mitigate insider threats and anomalies within cloud environments, particularly in complex networked systems where user behavior patterns can indicate potential security risks.

Innovation Solution

Implementing a data platform with agents that collect and analyze user behavior data to construct polygraphs, which are graphs of logical entities connected by behaviors, to identify deviations from typical patterns and detect anomalies in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IP address and user agent tracking methods are used to identify request origination, then basic request routing is achieved, but security against spoofing and insider threats is insufficient

Engineering Contradiction:
Improverequest origination verificationVSAvoiddevice trust architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the trust verification process into multiple independent components: hardware trust anchors (TPM, secure enclaves), software agents, certificate authorities, and policy engines. Each component performs a specific function in the chain of trust, allowing the system to achieve high reliability through modular verification rather than relying on a single complex identification mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces certificate authorities and policy servers as intermediary components between the device and the service platform. These intermediaries issue and verify cryptographic certificates that prove device identity and trust status, eliminating the need for direct IP address or user agent-based identification and providing secure, spoof-resistant verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive user behavior data collection is implemented to detect anomalies, then insider threat detection capability is improved, but privacy concerns and data processing complexity increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddata processing system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing baseline user behavior patterns and device trust profiles before anomalies occur. The policy server pre-configures expected behavior ranges and trust thresholds, allowing the anomaly detection system to quickly compare actual behavior against pre-established norms without requiring complex real-time analysis of every data point.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial monitoring by focusing data collection on specific, security-relevant behaviors rather than attempting to track all user activities. The system collects behavioral data selectively based on risk assessment and policy requirements, achieving effective anomaly detection while minimizing privacy intrusion and data processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If cryptographic certificate verification is implemented for each request, then security against spoofing is strengthened, but request processing time increases

Engineering Contradiction:
Improvedevice identity verificationVSAvoidrequest processing delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs cryptographic certificate verification in advance during device enrollment and initial authentication. Once verified, the device receives cached trust credentials that can be presented with subsequent requests without requiring full cryptographic verification each time. This preliminary action reduces per-request processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic certificates as verifiable copies of device identity that can be efficiently transmitted and validated. Instead of performing complex real-time cryptographic proofs for each request, the system uses pre-issued certificates as portable, tamper-evident copies of trust information that can be quickly verified by the policy server.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250306740A1Adding device trust to generate a stronger notion of request origination
Publication Date: 2025.10.02 FORTINET INC
  • US20250306740A1 patent drawing
  • US20250306740A1 patent drawing
  • US20250306740A1 patent drawing

AI summary

Approaches to electronic device security are described. A representation of user information describing a user device, visible in a graphical presentation of a user-specific polygraph via a graphical user interface (GUI) presented via a display device is generated. First information associated with the user is gathered. Second information indicating activity associated with the user that has been generated by an application executed on the electronic computing device is gathered. Determining whether the user of the electronic computing device has deviated from normal activity by correlating portions of the first information with portions of the second information. Directing the user to an approval workflow via the browser in response to a determination that the user has deviated from normal activity.