Proxy-Based Authentication for Secure Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems are vulnerable to security breaches as clients possess target access credentials, which can be hijacked, and they lack accountability in shared accounts, with human users often using simple, reused passwords, leading to security threats and difficulty in attributing actions.

Innovation Solution

A proxy-based authentication method where the proxy receives client credentials, verifies them, and provides target access credentials for authentication, ensuring the client does not possess target access credentials, and includes a privileged access management system for monitoring and managing these credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If clients possess target access credentials for direct authentication, then authentication can be performed without a proxy, but security is compromised as credentials can be hijacked and exposed

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a proxy server as an intermediary between the client and target. The proxy receives client credentials, verifies them, and issues target access credentials without exposing them to the client. This mediator architecture allows authentication to function while preventing credential theft, as the proxy controls the credential issuance and the client never possesses target access credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a proxy is introduced to secure authentication, then credential exposure is prevented, but the client must change protocols to accommodate the proxy's special protocol

Engineering Contradiction:
ImprovesecurityVSAvoidclient protocol requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs credential copying where the proxy creates target access credentials as copies or derivatives of the client credentials. These copied credentials are generated locally at the proxy without requiring changes to the client's original protocol. The proxy translates between the client's native protocol and the target's required protocol, maintaining client simplicity while enabling secure authentication.

Inventive Principle:
Principle #26Copying

3Ease of operation

If shared accounts are used for access, then ease of operation is improved, but accountability is lost as actions cannot be attributed to specific users

Engineering Contradiction:
Improveaccount accessVSAvoidaction attribution
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the authentication process into distinct phases: client authentication to the proxy, and proxy authentication to the target. Each phase uses separate credentials and can be independently tracked. The proxy maintains audit logs that segment and attribute actions to specific clients, even when using shared target accounts. This segmentation enables both ease of operation (shared accounts work) and accountability (actions are traceable).

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3119059B1A system and method for secure proxy-based authentication
Publication Date: 2019.05.01 CYBER ARK SOFTWARE LTD
  • EP3119059B1 patent drawingFigure 1A~1B
  • EP3119059B1 patent drawingFigure 2
  • EP3119059B1 patent drawingFigure 3

AI summary

A system and method for secure authentication facilitates improving the security of authentication between a client and a target by using an innovative authentication module on a proxy. The client can connect to the proxy using a native protocol and provides client credentials to the proxy. The proxy uses an authentication module to authenticate the client and then to provide target access credentials for proxy-target authentication, thereby giving the client access to the target through the proxy. The invention facilitates connection between the client and the target without requiring the client to be in possession of the target access credentials. The proxy can optionally be connected to a privileged access management system which can provide and/or store target access credentials. Proxy-provided target access credentials facilitate preventing a client security breech from exposing target access credentials.