Validated Telemetry Authentication for Zero-Trust Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a zero-trust computing environment, the inability to configure and authenticate telemetry collection and transmission hinders continuous validation of access to protected resources, leading to the use of stale or inadequate telemetry.
Innovation Solution
Implementing a policy decision point to manage telemetry collection and transmission, with a remote access controller that authenticates telemetry based on a defined telemetry chain and signaling pathways, ensuring only critical telemetry is validated before transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If telemetry collection and transmission is configured without authentication in a zero-trust environment, then the system operation simplicity is improved, but the security and reliability of access validation deteriorates
Solution Approach 1:
The patent introduces a policy decision point as an intermediary component that mediates between telemetry sources and the zero-trust access control system. This policy decision point collects telemetry data, validates it against security policies, and makes access decisions based on the validated telemetry, thereby maintaining security without requiring complex authentication configurations at each telemetry source.
Solution Approach 2:
The system implements self-service telemetry collection where telemetry sources automatically publish their data to the policy decision point without requiring manual authentication configurations. The policy decision point then validates and processes this telemetry data autonomously, reducing operational complexity while maintaining security through centralized policy enforcement.
2Reliability
If all telemetry streams are authenticated, then the security of the zero-trust environment is improved, but the system complexity and processing overhead increases
Solution Approach 1:
The patent applies local quality by implementing selective authentication where only specific telemetry streams requiring security validation are authenticated through the policy decision point, while other telemetry streams are processed without complex authentication. This targeted approach maintains security for critical data while reducing overall system complexity.
Solution Approach 2:
The system performs partial authentication by validating only the portions of telemetry data that are necessary for security decisions, rather than authenticating all telemetry streams in full. This partial action approach provides sufficient security validation while minimizing processing overhead and system complexity.
3Loss of information
If telemetry data is collected and transmitted without prioritization, then the completeness of monitoring information is improved, but the response time for critical security events deteriorates
Solution Approach 1:
The patent implements continuous telemetry collection and transmission to ensure no monitoring information is lost, while simultaneously applying prioritization rules that ensure critical security events are processed and responded to first. This continuous action with prioritization maintains both information completeness and timely response to critical events.
Solution Approach 2:
The system uses feedback mechanisms where the policy decision point continuously monitors telemetry streams, identifies critical security events based on predefined criteria, and triggers prioritized processing for these events while maintaining continuous collection of all telemetry data for complete monitoring coverage.
Data Source
AI summary
Systems and methods support collection of validated telemetry by an Information Handling System (IHS). A policy decision point (PDP) of a zero-trust computing environment controls access to protected resources The PDP identifies a telemetry stream of the IHS to be validated and identifies a telemetry definition specifying telemetry being collected by the IHS. The PDP updates the telemetry definition to specify adjustments to telemetry streams of the IHS to be authenticated and transmits the updated telemetry definition to the IHS. The IHS identifies telemetry that is ready for transmission and, based on the updated telemetry definition received from the policy decision point, generates a digital signature that authenticates the telemetry that is ready for transmission. The authenticated telemetry is transmitted to one or more destinations specified in the updated telemetry definition.


