Policy-Based PRA Authentication via Zero Trust Credential Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on solutions for Privileged Remote Access (PRA) systems rely on third-party authentication systems that do not follow zero trust methodologies, putting user credentials at risk and requiring target PRA systems to support external authentication methods.

Innovation Solution

A cloud-based system implements policy-based seamless authentication through zero trust private networks, automatically retrieving and decrypting credentials using preconfigured policies based on user identity and other criteria, eliminating the need for users to provide credentials and protecting them from exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party authentication systems are used for single sign-on, then authentication functionality is provided, but user credentials are exposed to security risks and zero trust methodology is not followed

Engineering Contradiction:
Improvecredential securityVSAvoidzero trust compliance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary credential service that sits between the user and the PRA system. This service retrieves credentials from a secure database, decrypts them using crypto services, and provides them to the PRA system without exposing them to third-party authentication systems. The intermediary maintains zero trust compliance while enabling authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the credential retrieval and management functionality from external third-party systems and places it within a controlled, zero-trust-compliant environment. By taking out the credential storage and decryption processes from external systems and implementing them locally with proper security controls, the system eliminates credential exposure risks while maintaining authentication capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If traditional authentication methods are used, then PRA systems can be accessed, but user credentials must be stored in external systems and users must manually provide credentials

Engineering Contradiction:
Improveauthentication convenienceVSAvoidcredential exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements self-service authentication where the system automatically retrieves and provides credentials without requiring user action. The credential service autonomously queries the database, decrypts credentials using crypto services, and supplies them to the PRA system. This eliminates the need for users to manually input credentials while keeping them out of external authentication systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary credential retrieval and decryption before the authentication process begins. Credentials are pre-configured in the database with associated decryption keys, and the system proactively retrieves and decrypts them when needed. This preliminary preparation eliminates the need for users to provide credentials during the authentication moment while maintaining security through controlled access to decrypted credentials.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If credentials are stored in external authentication systems, then authentication is enabled, but credentials are vulnerable to security breaches and do not follow zero trust principles

Engineering Contradiction:
Improveauthentication compatibilityVSAvoidcredential protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a nested structure where encrypted credentials are stored in a secure database, decrypted by crypto services in a controlled environment, and then used for authentication. The decryption process is nested within the credential service, which itself is nested within the zero trust architecture. This nested approach allows authentication compatibility while maintaining credential protection through multiple layers of security.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent creates an inert, controlled environment for credential storage and decryption. The database stores credentials in an encrypted, inactive state. Decryption occurs only in a controlled, monitored environment with strict access controls. This inert atmosphere approach protects credentials from external threats while enabling authentication when needed, following zero trust principles.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS20240323189A1Policy based authentication for Privileged Remote Access (PRA) systems
Publication Date: 2024.09.26 ZSCALER INC
  • US20240323189A1 patent drawing
  • US20240323189A1 patent drawing
  • US20240323189A1 patent drawing

AI summary

Systems and methods for policy based seamless authentication for PRA systems through zero trust private networks. The various systems and methods described herein include steps of receiving a request to access a Privileged Remote Access (PRA) system; determining if any credential rules apply to a console associated with the request; retrieving credentials associated with any of a user and the console from a database, thereby avoiding the user being required to provide credentials; and providing access to the requested PRA system based on the retrieved credentials.