Scan Assistant Authentication for Network Asset Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network computing systems face challenges in authenticated asset assessment due to the need for administrative or root-level credentials, which complicate credential management and increase the risk of unauthorized access if credentials become compromised.
Innovation Solution
The implementation of a scan assistant within the network system that authenticates a scan engine without requiring third-party credentials, using a reversed two-way client certificate authentication method to simplify deployment and reduce the risk of credential compromise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrative or root-level credentials are used for authenticated asset assessment, then authentication reliability is improved, but device complexity and ease of operation deteriorate due to complex credential management and deployment challenges
Solution Approach 1:
The patent introduces a credential service as an intermediary component that manages authentication credentials centrally. Instead of embedding credentials directly in scan engines or requiring manual administrative credential management, the credential service acts as a mediator that provides credentials to authorized components through standardized interfaces. This resolves the contradiction by maintaining authentication reliability through centralized credential management while reducing device complexity by eliminating the need for each scan engine to independently manage sensitive credentials.
2Reliability
If administrative or root-level credentials are used for authenticated asset assessment, then authentication reliability is improved, but ease of operation worsens due to challenges in credential distribution and integration with third-party services
Solution Approach 1:
The patent implements self-service mechanisms where the credential service automatically discovers, manages, and distributes credentials to scan engines and other components without requiring manual administrative intervention for each credential deployment. The system includes automated credential rotation, renewal, and revocation capabilities that operate autonomously. This resolves the contradiction by maintaining authentication reliability while dramatically improving ease of operation, as administrators no longer need to manually distribute and manage complex credentials across multiple systems.
3Measurement precision
If traditional authenticated scanning is implemented, then measurement precision of asset state is improved, but loss of time increases due to requirement for ad-hoc or scheduled assessments and remediation verification scans
Solution Approach 1:
The patent transforms the traditional periodic or ad-hoc assessment model into a continuous monitoring system. The scan assistant and credential service enable ongoing authenticated access to assets, allowing the system to continuously collect and update asset state information without requiring repeated full assessment cycles. This resolves the contradiction by maintaining measurement precision through continuous data collection while eliminating time loss associated with scheduling and executing periodic assessments and remediation verification scans.
4Productivity
If continuous updates on asset risk are required, then productivity is improved, but device complexity increases due to need for continuous monitoring and assessment mechanisms
Solution Approach 1:
The patent creates multi-functional components that perform multiple roles. The credential service not only manages authentication credentials but also coordinates continuous monitoring activities, manages scan engine lifecycles, and handles remediation verification. The scan assistant similarly integrates multiple functions including event monitoring, scan coordination, and result aggregation. This resolves the contradiction by enabling continuous risk updates that improve productivity while avoiding the complexity increase that would result from adding separate dedicated components for each function.
Data Source
AI summary
A method for asset assessment is provided. The method includes receiving, by a scan engine, an event message from a scan assistant associated with an asset of a network system. The asset includes at least one computing resource. The event message includes an indication of one or more events associated with the asset. The method also includes responsive to receiving the event message, transmitting, by the scan engine, a request to the scan assistant for executing one or more scan operations on the asset and to determine a state of the asset based on at least one of an amount of available network resources or a schedule associated with the asset. The method further includes executing, by the scan engine, the one or more scan operations on the asset after transmitting the request.


