Identity Broker Adapting Encryption for Regional Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for monitoring security and providing continuous conditional access to servers face challenges in managing encryption compliance across different geographical regions with varying cryptography regulations, particularly in countries like China and Russia, where encryption standards and access requirements change frequently, posing risks to data security and compliance.

Innovation Solution

An identity broker system dynamically monitors client devices for compliance with local regulatory requirements by substituting or modifying encryption components and policies in real-time based on the device's geographic location, ensuring continuous access while adhering to local security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strong encryption is used to protect data security, then data security is improved, but compliance with local cryptography regulations deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidcompliance with local regulations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption component is made dynamic by detecting the device's geographic location and automatically substituting different encryption components based on local regulations. The system transitions from a static encryption approach to a dynamic one that adapts to different regulatory environments, allowing strong encryption where permitted and compliant encryption where restricted.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the encryption parameters (strength, algorithm, key management) based on the detected geographic location. By monitoring location data and comparing it against a database of cryptographic regulations, the system adjusts encryption parameters to meet local requirements while maintaining data security where possible.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If encryption components are substituted based on location, then compliance with local regulations is improved, but system complexity increases

Engineering Contradiction:
Improvecompliance with local regulationsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

An identity broker is introduced as an intermediary component that handles the complexity of encryption component substitution. The broker receives authentication requests, detects geographic location, determines applicable regulations, and substitutes appropriate encryption components automatically. This intermediary absorbs the system complexity while presenting a simple interface to users and applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-configuring multiple encryption components with different security levels and preparing a database of cryptographic regulations for various locations. When the device connects, the system has already prepared the necessary components for substitution, reducing the complexity of real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If continuous security monitoring is implemented, then security risk assessment is improved, but processing time increases

Engineering Contradiction:
Improvesecurity risk assessmentVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security monitoring is implemented as periodic action rather than continuous monitoring. The system checks the device's geographic location and encryption compliance at key moments (authentication requests, connection events) rather than continuously monitoring all activities. This periodic approach maintains security assessment capability while reducing processing time and resource consumption.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11818129B2Communicating with client device to determine security risk in allowing access to data of a service provider
Publication Date: 2023.11.14 LOOKOUT INC
  • US11818129B2 patent drawing
  • US11818129B2 patent drawing
  • US11818129B2 patent drawing

AI summary

An identity broker receives a request for access by a client device to a service provided by a server. In response to the request, the identity broker communicates with a client device to determine whether a security risk is associated with allowing the client device to access data of a service provider. If the client device is secure, the identity broker sends an authentication request to an identity provider. After the identity provider authenticates the client device, the identity broker passes the authentication to the server, which establishes a session with the client device to provide the service. The security state of the client continues to be monitored to determine whether access should continue to be permitted to data associated with a service provider.