Token Injection Control System for Network Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networked services face security vulnerabilities due to costly and burdensome authentication and authorization systems, which are prone to configuration mistakes and leave resources vulnerable to threats like network spoofing and credential leakage, and impose development and testing costs on application developers.

Innovation Solution

A computer-implemented method and system that transparently injects identity and access tokens into network requests, using security policies to selectively route communications, thereby enhancing authentication and authorization without requiring changes to underlying services, reducing security vulnerabilities, and simplifying resource security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication and authorization systems are deployed to protect networked resources, then security against data breaches and service disruption is improved, but management burden on system administrators increases and configuration mistakes increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication and authorization systems into a unified system that operates transparently. The control system integrates identity tokens, access tokens, and security policies into a single coordinated mechanism that automatically manages access without requiring separate management of multiple AuthNZ systems, thereby reducing management burden while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a control system as an intermediary between client resources and networked resources. This control system automatically handles authentication and authorization by injecting identity tokens and access tokens into network requests, and by intercepting and routing requests according to security policies, thereby eliminating the need for administrators to directly manage multiple AuthNZ systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication and authorization systems are used, then access control is implemented, but network spoofing and credential leakage vulnerabilities remain

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary authentication and authorization actions by injecting identity tokens and access tokens into network requests before they reach the destination. The control system validates these tokens and establishes security policies in advance, ensuring that even if credentials are leaked later, the pre-established token-based access control prevents unauthorized access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical authentication mechanisms (passwords, certificates) with a token-based system. Identity tokens and access tokens serve as substitutes for traditional credentials, and the control system's automatic token validation and request routing mechanism replaces manual authentication processes, thereby eliminating vulnerabilities associated with credential leakage and network spoofing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If authentication and authorization systems require source code modifications, then security is enhanced, but development and testing costs increase and portability is limited

Engineering Contradiction:
ImprovesecurityVSAvoiddevelopment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The control system acts as an intermediary that handles all authentication and authorization logic externally. Client resources simply make network requests to the control system, which automatically injects tokens and enforces security policies. This eliminates the need for clients to modify their source code, thereby reducing development and testing costs while maintaining enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The control system provides universal authentication and authorization services to multiple client resources without requiring client-specific code modifications. The system can serve different protocols and applications through a single unified mechanism, thereby improving portability and reducing development costs across diverse services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If authentication and authorization systems are deployed individually without coordination, then implementation is simplified, but cross-layer coordination capability is lost

Engineering Contradiction:
Improveimplementation simplicityVSAvoidcross-layer coordination
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent merges multiple authentication and authorization layers into a single coordinated system. The control system centrally manages identity tokens, access tokens, and security policies across all layers, enabling automatic cross-layer coordination. This unified approach maintains implementation simplicity while restoring cross-layer coordination capability that was lost in distributed implementations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11075955B2Methods and systems for use in authorizing access to a networked resource
Publication Date: 2021.07.27 BANYAN SECURITY INC
  • US11075955B2 patent drawing
  • US11075955B2 patent drawing
  • US11075955B2 patent drawing

AI summary

A control system authorizes access to a networked resource. The control system includes a client agent associated with a client resource running at a user device, and a destination agent associated the networked resource. The client agent transparently injects one or more identity tokens associated with the client resource and one or more access tokens associated with the networked resource into a network request issued by the client resource and directed to the networked resource. The destination agent intercepts the network request and uses the access tokens to selectively route the network request in accordance with one or more security policies associated with the access tokens.