Enterprise Mobility Management Identity Assertion for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise authentication systems face challenges in securely accessing cloud-based services from mobile devices, particularly when users need to manage multiple passwords and encounter security and privacy concerns, such as unauthorized access due to inadequate security controls on devices.

Innovation Solution

A system that establishes a unique device-associated identity using a mobile device managed by an Enterprise Mobility Management (EMM) solution, allowing secure access to cloud-based services through VPN security protocols like MobileIron, leveraging PKI and EMM services to authenticate users even on unmanaged devices, using techniques such as inline authentication, push notifications, and identity provider authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users enter passwords to login to each cloud service individually, then user identity can be verified with each service, but it becomes cumbersome and difficult to manage multiple passwords

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an Enterprise Mobility Management (EMM) server as an intermediary that issues device certificates to mobile devices. These certificates serve as a trusted intermediary credential that cloud services can verify, eliminating the need for users to manage multiple passwords while maintaining strong authentication security through certificate-based verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The device certificate issued by the EMM server serves multiple functions: it authenticates the user's identity, verifies device security compliance, and enables access to multiple cloud services simultaneously. This universal credential replaces the need for service-specific passwords across different cloud platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If push notification authentication is used on any physical device, then user identity verification is simplified, but security controls are inadequate allowing unauthorized access

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The EMM server performs preliminary security assessments of the mobile device before issuing authentication credentials. It pre-verified device security controls, installed security policies, and configured compliance requirements. This preliminary action ensures that only secure, compliant devices receive authentication credentials, preventing unauthorized access while maintaining ease of use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device itself serves as the security control mechanism through its integrated certificate store and security policies. The device's secure element or trusted execution environment self-protects the authentication credentials and enforces security requirements, eliminating the need for external security checks while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple passwords are required for different applications, then access control to each service is maintained, but user productivity decreases due to forgetting passwords

Engineering Contradiction:
Improveaccess controlVSAvoiduser efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of requiring users to remember and manually enter multiple passwords, the system uses automated certificate-based authentication where the device automatically presents its certificate to cloud services. This copying mechanism replicates the authentication credential across multiple services without user intervention, maintaining access control while eliminating password management overhead and improving productivity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11368449B2Asserting a mobile identity to users and devices in an enterprise authentication system
Publication Date: 2022.06.21 IVANTI INC
  • US11368449B2 patent drawing
  • US11368449B2 patent drawing
  • US11368449B2 patent drawing

AI summary

In an embodiment, a system for asserting a mobile identity to users and devices in an enterprise authentication system includes a communication interface and a processor coupled to the interface. The processor is configured to receive, via the communication interface and from a first device, a request to authenticate a user to a service using a unique identity associated with a second device. The processor is configured to determine, based at least in part on the unique identity, an identity certificate associated with the request, generate an identity assertion based at least in part on the identity certificate, and provide the identity assertion via the communication interface to a requesting node with which the request to authenticate is associated.