Proxy Gateway Authentication for Shared Account Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods do not securely enable access to applications hosted on servers, particularly in shared account scenarios, where multiple users need to access resources while maintaining accountability for actions performed.
Innovation Solution
A secure method using a proxy gateway that allows users without authentication data to connect to applications by establishing a primary and secondary session, using multi-channel protocols like SSH or RDP, and executing computer code to obtain and transmit authentication data, ensuring secure and concurrent access across multiple users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users share a common account to access applications, then resource utilization improves, but accountability and security tracking deteriorate
Solution Approach 1:
The patent segments the authentication process into two distinct identities: a shared account identity for resource access and a unique user identity for accountability tracking. The proxy gateway maintains a mapping between these identities, allowing multiple users to access the same application through a shared account while the system separately tracks which user performed which action. This segmentation resolves the contradiction by enabling both shared access and individual accountability simultaneously.
2Ease of operation
If authentication data is stored on the client device, then access convenience improves, but security risk increases
Solution Approach 1:
The patent extracts the authentication data from the client device and stores it securely on the server side within the proxy gateway. The client only needs to provide initial authentication credentials to establish a session, after which the proxy gateway handles all subsequent authentication operations. This extraction eliminates the security vulnerability of storing sensitive authentication data on potentially compromised client devices while maintaining convenient access through the established session.
Solution Approach 2:
The proxy gateway acts as an intermediary between the client and the application server, managing authentication data securely. Instead of the client device directly storing and managing sensitive credentials, the proxy gateway mediates the authentication process by storing credentials securely and managing their distribution to applications. This intermediary approach maintains ease of operation while reducing security risks associated with client-side credential storage.
3Reliability
If a proxy gateway is introduced to manage authentication, then security improves, but system complexity increases
Solution Approach 1:
The patent implements a universal proxy gateway that handles multiple authentication scenarios and protocols through a single unified system. The proxy gateway can manage authentication for multiple applications, support different authentication methods, and serve multiple users simultaneously. This multi-functionality reduces the need for separate authentication systems for different applications, thereby limiting the increase in system complexity while maintaining high security standards across all access points.
Data Source
AI summary
A secure method connects to an application run on a server from a client computer device, by a user who does not have the authentication data of the account declared in the application, the account including at least one proxy ID. The disclosure also relates to the application and associated authentication data, implementing a proxy [mandatary gateway] including a memory for recording, for each user declared by a primary account comprising at least one user ID, the list of resource targets C and accounts to which the user has access.

