Identity Provider Token Management for Compliant Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for accessing computing resources, particularly on small form factor devices like smartphones and smartwatches, result in poor user experience due to frequent credential prompts, and are vulnerable to security lapses when not managed according to enterprise security policies, allowing attackers to impersonate users for extended periods.

Innovation Solution

An identity provider integrates with unified endpoint management (UEM) via API to manage clients, issuing short-lived access tokens and refresh tokens, ensuring compliance with enterprise policies by verifying device compliance status through digital signatures and cryptographic nonces, thereby reducing security risks and enhancing user convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed each time the user attempts to access the resource, then security is maintained, but user convenience deteriorates due to frequent credential prompts

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication and issues access tokens before the user needs to access resources repeatedly. The access token is valid for a specified duration, allowing the user to access resources multiple times without re-entering credentials. This preliminary authentication action resolves the contradiction by maintaining security through initial verification while improving convenience through extended access periods.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access token enables continuous access to resources throughout its validity period without requiring repeated authentication. The token remains valid and can be used multiple times for accessing different resources or re-accessing the same resource, providing continuous useful action (access) without interruption or repeated user intervention.

Inventive Principle:
Principle #20Continuity of useful action

2Ease of operation

If access tokens with extended duration are issued to improve user convenience, then user convenience is improved, but security deteriorates due to vulnerability to credential theft and impersonation

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system changes the parameter of token duration based on the level of trust and security requirements. Instead of using a single fixed duration, the system can issue tokens with different validity periods - shorter for less secure contexts and longer for trusted environments. This parameter adjustment allows optimization of both convenience and security by matching token duration to the specific access scenario.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The access token acts as an intermediary between the user's authentication credentials and the resource access. Instead of directly using permanent credentials, the system introduces a time-limited access token that mediates the access relationship. This intermediary token can be revoked or expire, providing a security mechanism that balances the convenience of extended access with the ability to limit exposure in case of credential compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If clients not managed according to enterprise security policies are allowed to access resources, then user convenience is improved, but security deteriorates due to risk of attacker impersonation

Engineering Contradiction:
Improveaccess availabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback mechanisms where the identity provider continuously monitors and verifies the status of clients attempting to access resources. The feedback loop includes checking whether a client is properly managed and compliant with enterprise security policies before issuing access tokens. This feedback ensures that only compliant clients gain access, preventing attacker impersonation while maintaining availability for authorized users.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system takes preliminary anti-action by verifying client compliance and managing device registration before access is granted. The identity provider checks whether the client device is registered and compliant with security policies in advance, preventing potentially harmful access attempts before they can occur. This preliminary verification blocks malicious actors from obtaining access tokens while allowing legitimate compliant clients to access resources.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11658984B2Authenticating access to computing resources
Publication Date: 2023.05.23 CITRIX SYSTEMS INC
  • US11658984B2 patent drawing
  • US11658984B2 patent drawing
  • US11658984B2 patent drawing

AI summary

Described embodiments provide systems, methods, computer readable media for accessing services via identity providers. A computing device may transmit, responsive to a request from a client to access a service, a value to the client. The client may be configured to access the service using an access token. The computing device may receive, from the client, a signature, the signature generated using the value, a device identifier, and a first encryption key. The computing device may determine, using the value and a second encryption key, the device identifier from the signature. The computing device may identify a status of the client according to the device identifier. The computing device may provide, responsive to the status, a new access token to permit access to the access and a refresh token to obtain subsequent access tokens.