Identity Broker for Continuous Conditional Server Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of mobile devices and cloud-based solutions has made it challenging for enterprises to maintain secure network perimeters, as existing solutions like MDM and MAM often compromise privacy or require complex integration with third-party identity providers, and there is a need for continuous conditional access to servers while ensuring compliance with varying cryptographic regulations across different geographic locations.

Innovation Solution

An identity broker is used to monitor the security of client devices in real-time, assessing their compliance with local regulations by dynamically substituting or modifying software components, such as encryption modules, to ensure compliance with local cryptographic standards, thereby providing continuous conditional access to servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MDM and MAM solutions are used to maintain secure network perimeters, then security is improved, but privacy is compromised and integration complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity broker as an intermediary component that mediates between client devices and servers. This broker handles authentication and authorization requests, reducing the need for complex direct integrations between MDM/MAM systems and third-party identity providers. The identity broker simplifies the architecture by centralizing identity management functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity broker is designed to perform multiple functions including authentication, authorization, and security policy enforcement. This multi-functional approach reduces the need for separate specialized components, thereby reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If encryption modules are dynamically substituted to comply with local regulations, then regulatory compliance is improved, but system complexity increases

Engineering Contradiction:
Improveregulatory complianceVSAvoidsoftware component complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic substitution of encryption modules based on the client device's geographic location. The system continuously monitors location data and automatically replaces encryption components with versions that comply with local cryptographic regulations. This dynamic adaptation allows the system to meet varying regulatory requirements without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies different encryption standards and modules based on the specific geographic location of the client device. Each region receives locally-appropriate encryption implementations that comply with that jurisdiction's regulations, rather than using a uniform global standard. This localized approach optimizes compliance while managing complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If continuous security monitoring is implemented, then security reliability is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The identity broker implements periodic security assessments rather than continuous monitoring. It evaluates client device security states at regular intervals and triggers authentication requests based on these periodic checks. This approach maintains security reliability while reducing the constant processing overhead associated with continuous real-time monitoring.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system uses feedback from periodic security assessments to dynamically adjust authentication requirements. When security conditions change or compliance issues are detected, the identity broker responds by triggering appropriate authentication flows. This feedback mechanism ensures security is maintained without requiring constant active monitoring.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10785230B1Monitoring security of a client device to provide continuous conditional server access
Publication Date: 2020.09.22 LOOKOUT INC
  • US10785230B1 patent drawing
  • US10785230B1 patent drawing
  • US10785230B1 patent drawing

AI summary

An identity broker receives a request for access by a client device to a service provided by a server. In response to the request, the identity broker determines an identity of the client device using a client certificate. The identity broker also determines whether the client device is in a secure state. If the client device is secure, the identity broker sends an authentication request to an identity provider. After the identity provider authenticates the client device, the identity broker passes the authentication to the server, which establishes a session with the client device to provide the service.