Proxy Gateway Authentication for Shared Account Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods do not securely enable access to applications hosted on servers, particularly in shared account scenarios, where multiple users need to access resources while maintaining accountability for actions performed.

Innovation Solution

A secure method using a proxy gateway that allows users without authentication data to connect to applications by establishing a primary and secondary session, using multi-channel protocols like SSH or RDP, and executing computer code to obtain and transmit authentication data, ensuring secure and concurrent access across multiple users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users share a common account to access applications, then resource utilization improves, but accountability and security tracking deteriorate

Engineering Contradiction:
Improveshared account accessVSAvoidaccountability tracking
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication process into two distinct identities: a shared account identity for resource access and a unique user identity for accountability tracking. The proxy gateway maintains a mapping between these identities, allowing multiple users to access the same application through a shared account while the system separately tracks which user performed which action. This segmentation resolves the contradiction by enabling both shared access and individual accountability simultaneously.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If authentication data is stored on the client device, then access convenience improves, but security risk increases

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication data from the client device and stores it securely on the server side within the proxy gateway. The client only needs to provide initial authentication credentials to establish a session, after which the proxy gateway handles all subsequent authentication operations. This extraction eliminates the security vulnerability of storing sensitive authentication data on potentially compromised client devices while maintaining convenient access through the established session.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The proxy gateway acts as an intermediary between the client and the application server, managing authentication data securely. Instead of the client device directly storing and managing sensitive credentials, the proxy gateway mediates the authentication process by storing credentials securely and managing their distribution to applications. This intermediary approach maintains ease of operation while reducing security risks associated with client-side credential storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a proxy gateway is introduced to manage authentication, then security improves, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal proxy gateway that handles multiple authentication scenarios and protocols through a single unified system. The proxy gateway can manage authentication for multiple applications, support different authentication methods, and serve multiple users simultaneously. This multi-functionality reduces the need for separate authentication systems for different applications, thereby limiting the increase in system complexity while maintaining high security standards across all access points.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10498733B2Secure transfer of authentication information
Publication Date: 2019.12.03 WALLIX
  • US10498733B2 patent drawing
  • US10498733B2 patent drawing

AI summary

A secure method connects to an application run on a server from a client computer device, by a user who does not have the authentication data of the account declared in the application, the account including at least one proxy ID. The disclosure also relates to the application and associated authentication data, implementing a proxy [mandatary gateway] including a memory for recording, for each user declared by a primary account comprising at least one user ID, the list of resource targets C and accounts to which the user has access.