SaaS Access Monitoring via Mobile Certificate Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Account takeover incidents are prevalent in cloud-based services, particularly in software as a service (SaaS) applications, where attackers gain access to user accounts and modify credentials, leading to security breaches and data vulnerabilities.
Innovation Solution
A method and system for monitoring access that involves sending a certificate to a client, requesting and verifying a second certificate upon access requests, and notifying based on the verification results, incorporating a mobile device management (MDM) module and a verification server to enhance security and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used in cloud-based SaaS applications, then ease of operation is maintained, but security against account takeover attacks deteriorates
Solution Approach 1:
The system performs preliminary actions by sending a notification to the user's mobile device before granting access to the SaaS application. The mobile device management module proactively requests a certificate from the user's mobile device and verifies it against the original certificate before allowing the authentication process to complete, preventing account takeover attacks in advance
Solution Approach 2:
The patent introduces a mobile device management module as an intermediary between the SaaS application and the user's authentication credentials. This intermediary module manages certificates on the mobile device, verifies user identity through certificate matching, and controls access to the SaaS application, adding a security layer without significantly impacting user experience
2Reliability
If certificate verification is implemented for every access request, then security against account takeover is improved, but device complexity increases
Solution Approach 1:
The mobile device management module serves multiple functions: it manages certificates on the mobile device, communicates with the SaaS application gateway, verifies user identity through certificate matching, and controls access permissions. By consolidating these diverse functions into a single universal module, the system achieves improved access control without proportionally increasing overall system complexity
3Measurement precision
If real-time certificate verification is performed, then detection precision of unauthorized access is improved, but processing time increases
Solution Approach 1:
The system performs certificate verification as a preliminary step in the authentication process, before the user is granted access to the SaaS application. By verifying the certificate match between the mobile device and the original certificate in advance, the system ensures high detection precision for unauthorized access attempts while keeping the overall authentication time acceptable
Data Source
AI summary
A method for monitoring access of users to Internet SaaS applications includes the CISO (company Internet security office) in the configuration and operation of the method, instead of relying only on whatever security the SaaS application implements. Certificates, not accessible to users, are pushed to a user's client. When an access request is received from a client by an application, a gateway requests from the client the certificate. After a notification and approval process with the user, a received certificate is verified, user access to the application is allowed or denied, and the CISO notified of the attempted access.


