Gateway Proxy Authentication for Software Robots

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software robots face challenges in securely acquiring access credentials to access cloud-based services offered by remote service providers, due to their distributed and numerous nature, making secure access complicated and less secure.

Innovation Solution

Implementing a gateway proxy that issues intermediate authentication tokens to local processing agents, allowing them to access cloud-based services securely without distributing service provider authentication credentials beyond the proxy, thus enabling efficient and secure access for large numbers of agents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software robots directly acquire access credentials from service providers, then authentication can be performed, but security is compromised due to the distributed and numerous nature of software robots

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway proxy as an intermediary component that sits between software robots and cloud-based services. The gateway proxy receives authentication requests from software robots, validates them against stored credentials, and returns authentication tokens. This mediator architecture allows software robots to authenticate without directly handling sensitive credentials, thereby improving security while maintaining manageable authentication processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access credentials are distributed to each software robot, then authentication is simplified for individual robots, but security risks increase due to widespread credential distribution

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts sensitive access credentials from the distributed software robot environment and centralizes them in a secure location within the gateway proxy. Instead of each robot holding credentials, the credentials are extracted and stored centrally, with robots receiving only temporary authentication tokens. This extraction approach simplifies the authentication process for robots while significantly reducing security risks associated with credential distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a gateway proxy is introduced to manage authentication, then security is improved by centralizing credential management, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway proxy is designed as a universal authentication service that handles multiple functions: validating software robot identities, managing credentials, issuing authentication tokens, and controlling access to various cloud-based services. By consolidating these diverse authentication functions into a single multi-functional component, the system improves security without proportionally increasing complexity, as the gateway proxy serves as a centralized hub for all authentication-related operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240236046A1Authentication of software robots with gateway proxy for access to cloud-based services
Publication Date: 2024.07.11 AUTOMATION ANYWHERE INC
  • US20240236046A1 patent drawing
  • US20240236046A1 patent drawing
  • US20240236046A1 patent drawing

AI summary

Improved techniques for secure access to cloud-based services via a gateway proxy. The improved techniques can efficiently manage remote access to cloud-based services by local processing agents in a secure manner using an intermediate authentication token issued by a gateway proxy to authorized local processing agents. The intermediate authentication token can be used to obtain authentication credentials of service providers that are needed to access the cloud-based services that are offered by service providers. In some embodiments, the authentication credentials of service providers need only be distributed to the gateway proxy and need not be distributed beyond the gateway proxy. The improved techniques are well suited for used with robotic process automation systems in which local processing agents, such as software agents, perform user tasks in an automated fashion.