Protected Resource Discovery Tokens for Zero Trust Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Zero Trust access models, resources are discoverable from public networks and not-yet-trusted devices, raising security concerns, as existing systems rely solely on authentication to protect resources.
Innovation Solution
Implementing a Discovery Token Service that requires endpoint devices to establish a minimum level of trust through multi-factor authentication before allowing discovery of protected resources, using tokens signed with asymmetric or symmetric keys to verify identity and enforce access policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If resources are made discoverable from public networks in a Zero Trust access model, then accessibility and ease of operation are improved, but security and protection against unauthorized access deteriorate
Solution Approach 1:
The patent introduces a gateway as an intermediary component that sits between public networks and protected resources. This gateway enforces multi-factor authentication and token validation, allowing resources to remain discoverable while preventing unauthorized access. The gateway mediates all discovery requests, verifying device trustworthiness before permitting access to resource location information.
Solution Approach 2:
The system performs preliminary authentication and authorization checks before allowing resource discovery. Devices must complete multi-factor authentication and receive valid tokens beforehand. This preliminary action ensures that only trusted devices can discover resources, preventing unauthorized access while maintaining discoverability for authenticated users.
2Object-affected harmful factors
If multi-factor authentication and token validation are implemented before resource discovery, then security is improved, but device complexity and authentication overhead increase
Solution Approach 1:
The gateway serves multiple functions: it acts as an authentication enforcement point, a token validation service, a discovery controller, and a policy enforcement mechanism. By consolidating these functions into a single universal component, the system reduces overall complexity while maintaining strong security controls for resource discovery.
3Object-affected harmful factors
If resource discovery is limited to authenticated devices only, then security is improved, but accessibility and ease of operation for legitimate users may deteriorate
Solution Approach 1:
The system dynamically changes the trust parameter based on authentication state. Unauthenticated devices receive no discovery information, while authenticated devices receive appropriate resource location data. This parameter change approach maintains security by controlling access based on authentication status while ensuring legitimate users can access resources seamlessly.
Data Source
AI summary
According to an embodiment, a system comprises one or more processors and one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations. The operations comprise determining that an endpoint device has requested to discover a location of a protected resource that is protected by a gateway, determining whether the endpoint device has provided a token that is valid, and permitting the endpoint device to discover the location of the protected resource based on determining that the endpoint device has provided the token that is valid. The token indicates that the endpoint device successfully completed a first multi-factor authentication procedure in connection with accessing an authentication enforcement resource.


