Zero Trust Architecture with Local Agent Self-Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing zero trust security technologies, such as multi-factor authentication (MFA), are vulnerable to phishing attacks, as token or push-based possession-based factors can be easily compromised by attackers who social engineer users to supply secret codes or approve authentication attempts.
Innovation Solution
A cloud-based zero trust architecture (ZTA) that establishes a reliable communication channel between a device and a service during web and SaaS authentication, using a phishing-resistant possession-based factor within an existing MFA flow. This involves a client device with a browser and a local agent, where the agent encodes device information into an image that is then processed by the browser to output a blob to the cloud-based application, confirming device identity and security posture.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If token or push-based possession-based factors are used in MFA, then authentication convenience is improved, but security against phishing attacks deteriorates
Solution Approach 1:
The patent replaces traditional token-based or push-based possession factors with a phishing-resistant cryptographic mechanism. The device trust architecture substitutes the vulnerable mechanical interaction (user entering tokens or approving pushes) with a cryptographic challenge-response system where the device proves its identity through cryptographic signatures, making phishing attacks ineffective while maintaining authentication convenience.
Solution Approach 2:
The patent changes the fundamental parameter of possession-based authentication from vulnerable formats (tokens, push notifications) to a phishing-resistant cryptographic format. By transforming the authentication mechanism into a cryptographic challenge-response system with device attestation, the solution maintains ease of operation while dramatically improving security against phishing attacks.
2Reliability
If device trust verification is implemented, then security posture is improved, but authentication complexity increases
Solution Approach 1:
The patent implements preliminary device registration and trust establishment before the authentication flow. The device is pre-registered with the service, and trust relationships are established in advance through device attestation. This preliminary action allows the actual authentication to proceed smoothly without adding significant complexity, as the cryptographic credentials are already in place.
Solution Approach 2:
The patent introduces a service-mediated authentication flow where the service acts as an intermediary between the user and the authentication process. The service handles the cryptographic challenge-response verification and device trust validation, abstracting away the complexity from the user while maintaining strong security posture through comprehensive device verification.
3Reliability
If comprehensive device verification is performed, then access control reliability is improved, but authentication time increases
Solution Approach 1:
The patent performs comprehensive device verification through pre-registration and pre-established trust relationships. By setting up cryptographic credentials and device attestation in advance, the actual authentication process during login is accelerated, as the system only needs to verify pre-computed cryptographic signatures rather than performing comprehensive checks in real-time.
Solution Approach 2:
The patent enables the authentication flow to skip time-consuming verification steps by using pre-established device trust relationships. The cryptographic challenge-response mechanism allows the system to rapidly verify device identity without performing lengthy security checks, thus maintaining access control reliability while significantly reducing authentication time.
Data Source
AI summary
A zero trust application enables access to a protected resource from a client device associated with a user. The client device has a browser, and an agent running locally and accessible via a local loopback interface. During an authentication flow, a browser-based script executes in the browser to deliver a challenge to the agent, and to collect a response to that challenge from the agent using a graphics file-based encoding scheme, and to deliver that information to the application for verifying the client device and its security posture. Depending on that security posture, the authentication flow may be permitted to complete. If a failure of the security posture is identified, the user may be permitted during the on-going authentication flow to address that failure and request a re-check of the posture.


