Identity Security Gateway Agent for Passwordless Privileged Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face challenges in managing privileged access, particularly in WebUI environments, where traditional methods lack reliable password management and security features, leading to inefficiencies and security concerns, especially for smaller businesses with limited IT resources.

Innovation Solution

A single sign-on (SSO) mechanism is employed to facilitate user access to WebUI service providers, separating the assertion and SSO process from user credentials, using an agent component to abstract authentication and session information, and providing abstracted credentials, ensuring secure feature retention and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password management methods are used in WebUI environments, then user access can be established, but security features are insufficient and password management becomes complex and time-consuming

Engineering Contradiction:
Improvesecurity featuresVSAvoidpassword management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts password management functionality from the WebUI environment and relocates it to an external identity provider. The identity provider handles credential storage, validation, and management separately from the WebUI service, eliminating the need for WebUI providers to implement their own password management systems while maintaining strong security features.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an identity provider as an intermediary between users and WebUI service providers. This intermediary handles authentication requests, manages credentials securely, and returns authentication results to the WebUI provider without exposing password management complexity to either the user or the service provider.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If SSO federation is used to manage credentials via offsite systems, then access to multiple WebUI providers is facilitated, but session control and privilege protections are lost

Engineering Contradiction:
Improveaccess to multiple providersVSAvoidsession control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent inverts the traditional SSO model by having the identity provider return a negative assertion when credentials are invalid or sessions should be terminated, rather than requiring positive authentication for each action. This allows the WebUI provider to maintain control over session validity and privilege protections while still enabling access to multiple providers through a single credential management system.

Inventive Principle:
Principle #13The other way round (Inversion)

3Ease of operation

If manual password management via password reset functions is used, then user credentials can be updated, but the process is time-consuming and lacks automation

Engineering Contradiction:
Improvecredential update capabilityVSAvoidtime for password management
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements self-service credential management through the identity provider, which automatically handles password generation, validation, and updates. Users can reset their credentials through automated processes managed by the identity provider without requiring manual intervention from IT departments or password reset functions in the WebUI providers, significantly reducing the time required for credential management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11368448B2Passwordless privilege access
Publication Date: 2022.06.21 SAILPOINT TECHNOLOGIES INC
  • US11368448B2 patent drawing
  • US11368448B2 patent drawing
  • US11368448B2 patent drawing

AI summary

Systems and methods for network security are provided. Various embodiments of the present technology provide systems and methods for an identity security gateway agent that provides for privileged access. Embodiments include a system and method that uses a single sign-on (SSO) (or similar) mechanism to facilitate a user accessing web-based service providers, but separates the assertion and entire SSO process from the user credential.