Proxy-Based Authentication for Secure Credential Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems are vulnerable to security breaches as clients possess target access credentials, which can be hijacked, and they lack accountability in shared accounts, with human users often using simple, reused passwords, leading to security threats and difficulty in attributing actions.
Innovation Solution
A proxy-based authentication method where the proxy receives client credentials, verifies them, and provides target access credentials for authentication, ensuring the client does not possess target access credentials, and includes a privileged access management system for monitoring and managing these credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If clients possess target access credentials for direct authentication, then authentication can be performed without a proxy, but security is compromised as credentials can be hijacked and exposed
Solution Approach 1:
The patent introduces a proxy server as an intermediary between the client and target. The proxy receives client credentials, verifies them, and issues target access credentials without exposing them to the client. This mediator architecture allows authentication to function while preventing credential theft, as the proxy controls the credential issuance and the client never possesses target access credentials.
2Reliability
If a proxy is introduced to secure authentication, then credential exposure is prevented, but the client must change protocols to accommodate the proxy's special protocol
Solution Approach 1:
The patent employs credential copying where the proxy creates target access credentials as copies or derivatives of the client credentials. These copied credentials are generated locally at the proxy without requiring changes to the client's original protocol. The proxy translates between the client's native protocol and the target's required protocol, maintaining client simplicity while enabling secure authentication.
3Ease of operation
If shared accounts are used for access, then ease of operation is improved, but accountability is lost as actions cannot be attributed to specific users
Solution Approach 1:
The patent segments the authentication process into distinct phases: client authentication to the proxy, and proxy authentication to the target. Each phase uses separate credentials and can be independently tracked. The proxy maintains audit logs that segment and attribute actions to specific clients, even when using shared target accounts. This segmentation enables both ease of operation (shared accounts work) and accountability (actions are traceable).
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
A system and method for secure authentication facilitates improving the security of authentication between a client and a target by using an innovative authentication module on a proxy. The client can connect to the proxy using a native protocol and provides client credentials to the proxy. The proxy uses an authentication module to authenticate the client and then to provide target access credentials for proxy-target authentication, thereby giving the client access to the target through the proxy. The invention facilitates connection between the client and the target without requiring the client to be in possession of the target access credentials. The proxy can optionally be connected to a privileged access management system which can provide and/or store target access credentials. Proxy-provided target access credentials facilitate preventing a client security breech from exposing target access credentials.