Enterprise Mobility Management Identity Assertion for Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise authentication systems face challenges in securely accessing cloud-based services from mobile devices, particularly when users need to manage multiple passwords and encounter security and privacy concerns, such as unauthorized access due to inadequate security controls on devices.
Innovation Solution
A system that establishes a unique device-associated identity using a mobile device managed by an Enterprise Mobility Management (EMM) solution, allowing secure access to cloud-based services through VPN security protocols like MobileIron, leveraging PKI and EMM services to authenticate users even on unmanaged devices, using techniques such as inline authentication, push notifications, and identity provider authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users enter passwords to login to each cloud service individually, then user identity can be verified with each service, but it becomes cumbersome and difficult to manage multiple passwords
Solution Approach 1:
The patent introduces an Enterprise Mobility Management (EMM) server as an intermediary that issues device certificates to mobile devices. These certificates serve as a trusted intermediary credential that cloud services can verify, eliminating the need for users to manage multiple passwords while maintaining strong authentication security through certificate-based verification.
Solution Approach 2:
The device certificate issued by the EMM server serves multiple functions: it authenticates the user's identity, verifies device security compliance, and enables access to multiple cloud services simultaneously. This universal credential replaces the need for service-specific passwords across different cloud platforms.
2Ease of operation
If push notification authentication is used on any physical device, then user identity verification is simplified, but security controls are inadequate allowing unauthorized access
Solution Approach 1:
The EMM server performs preliminary security assessments of the mobile device before issuing authentication credentials. It pre-verified device security controls, installed security policies, and configured compliance requirements. This preliminary action ensures that only secure, compliant devices receive authentication credentials, preventing unauthorized access while maintaining ease of use.
Solution Approach 2:
The mobile device itself serves as the security control mechanism through its integrated certificate store and security policies. The device's secure element or trusted execution environment self-protects the authentication credentials and enforces security requirements, eliminating the need for external security checks while maintaining strong security controls.
3Reliability
If multiple passwords are required for different applications, then access control to each service is maintained, but user productivity decreases due to forgetting passwords
Solution Approach 1:
Instead of requiring users to remember and manually enter multiple passwords, the system uses automated certificate-based authentication where the device automatically presents its certificate to cloud services. This copying mechanism replicates the authentication credential across multiple services without user intervention, maintaining access control while eliminating password management overhead and improving productivity.
Data Source
AI summary
In an embodiment, a system for asserting a mobile identity to users and devices in an enterprise authentication system includes a communication interface and a processor coupled to the interface. The processor is configured to receive, via the communication interface and from a first device, a request to authenticate a user to a service using a unique identity associated with a second device. The processor is configured to determine, based at least in part on the unique identity, an identity certificate associated with the request, generate an identity assertion based at least in part on the identity certificate, and provide the identity assertion via the communication interface to a requesting node with which the request to authenticate is associated.


