Proxy-Based Device Identity Proof for Trusted Broker Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud security brokers lack a standardized method for verifying device identity and health, leading to inefficiencies and increased complexity in integrating endpoint security products, and existing solutions degrade user experience due to latency and scalability issues.
Innovation Solution
A method and system that utilize a proxy to verify user devices by ensuring requests originate from a known IP address, using a secret to authenticate with a security broker, allowing minimal configuration and integration with existing brokers, while ensuring only healthy devices gain access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a proxy is used to verify device identity by checking requests from known IP addresses, then device identity verification is simplified and works with various security brokers, but the proxy may become a bottleneck affecting scalability and user experience
Solution Approach 1:
The patent introduces a proxy as an intermediary component that sits between user devices and security brokers. The proxy verifies device identity by checking if requests originate from known IP addresses and by validating a secret provided by the device. This intermediary approach enables compatibility with multiple security brokers without requiring changes to the brokers themselves, while distributing the verification load to improve scalability.
2Reliability
If endpoint security products are integrated with cloud security brokers, then device health verification is enabled, but integration complexity increases significantly
Solution Approach 1:
The proxy acts as a mediator that simplifies the integration between endpoint security products and cloud security brokers. Instead of requiring direct complex integration between endpoint security and multiple broker systems, the proxy handles the verification process by checking device health status and validating secrets, thereby enabling device health verification while keeping integration complexity manageable.
Solution Approach 2:
The proxy is designed as a universal component that can work with multiple different security brokers and endpoint security products through a standardized interface. It performs multiple functions including IP address verification, secret validation, and device health checking, thereby enabling broad compatibility without increasing integration complexity for each specific broker-product combination.
3Reliability
If traditional identity verification methods are used without a proxy, then the verification process is direct, but user experience degrades due to latency and the system lacks standardized device verification
Solution Approach 1:
The system performs preliminary actions by pre-configuring known IP addresses and secrets before verification is needed. When a device connects, the proxy can quickly verify its identity by checking against these pre-configured values, avoiding the need for complex real-time verification processes. This preliminary preparation reduces verification latency while maintaining reliable device identity verification.
Data Source
AI summary
A method for use in granting access to a target to a user device, comprising: receiving at a proxy a request to access the target; forwarding by the proxy the access request to a security broker when the user device is verified by the proxy to know a prescribed secret, wherein the request is forwarded so as to appear to originate from a prescribed set of internet protocol (IP) addresses that the security broker recognizes as trusted; receiving by the proxy from the security broker (i) an access token, the access token being submittable to the target by the user device to gain access thereto and (ii) instructions for transmission to the user device for causing the user device to be redirected to an address indicating the requested target; and transmitting by the proxy toward the user device the access token and the instructions.


