Secure cross-tenant access
By monitoring and responding to changes in cross-tenant access policies and role assignments, security concerns regarding cross-tenant access in cloud computing are addressed, ensuring access reliability and compliance, and supporting security investigations and the execution of managed services.
Patent Information
- Application Number
- CN202480018255.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-06-02
- Filing Date
- 2024-05-20
- Publication Date
- 2025-10-31
AI Technical Summary
In cloud computing environments, security concerns arise from cross-tenant access, including access exceeding authorized limits and access being interrupted or hindered. This is especially true in multi-tenant cloud architectures, where it is crucial to ensure the reliability of secure cross-tenant access and prevent accidental or malicious policy changes.
By monitoring the non-obstruction access policies of focus tenants and cross-tenant role assignments, potential obstruction changes can be detected and responded to, alerts can be issued and modifications can be made, and combined with audit correlation functions, access security and compliance can be ensured.
It effectively mitigates unexpected or malicious policy and role changes during cross-tenant access, improves the security of cloud computing tenants, ensures the reliability and compliance of access, and supports security investigations and the execution of managed services.
Smart Images

Figure CN120883573A_ABST
Abstract
Description
Related applications
[0001] This application claims priority to U.S. Provisional Patent Application No. 63469935, filed May 31, 2023, the entire contents of which are incorporated herein by reference. Background Technology
[0002] Attacks on computing systems can take many different forms, including some that are difficult to predict and that vary depending on the circumstances. Therefore, one of the guiding principles of cybersecurity is "defense in depth." In practice, defense in depth typically works by forcing attackers to encounter multiple different types of security mechanisms at various locations around or within the computing system. No single security mechanism can detect all types of cyberattacks, determine the scope of an attack or vulnerability, or stop all detected cyberattacks. However, sometimes, combining and layering a sufficient number and variety of defense and investigation tools can prevent attacks, deter attackers, or at least help limit the scope of damage caused by an attack or vulnerability.
[0003] To achieve defense in depth, cybersecurity professionals consider the various attacks that might target computing systems and the vulnerabilities they may contain. They select defensive measures based on criteria such as: which attacks are most likely to occur, which attacks are most likely to succeed, which attacks, if successful, would cause the most damage, what defenses are currently deployed, what defenses can be deployed, and the costs, process changes, and training required to deploy specific defenses or eliminate vulnerabilities. They investigate the scope of attacks and attempt to detect vulnerabilities before they are exploited to launch attacks. For a particular computing system, some defenses or investigation measures may be impractical or cost-effective. However, improvements in cybersecurity are always possible and worth pursuing. Summary of the Invention
[0004] Some embodiments are designed to address the technical challenges arising from authorizing a user in one cloud tenant to command another cloud tenant to perform actions. For example, secure cross-tenant access presents challenges such as how to technically constrain access to the authorized scope and how to technically prevent or mitigate attempts to obstruct authorized access. Sometimes, the actions performed are related to cybersecurity, such as narrowing the attack surface, eliminating security vulnerabilities, or investigating security incidents. However, the teachings herein are not limited to cross-tenant cybersecurity operations.
[0005] In some embodiments, a computing system is configured for secure cross-tenant access. The system includes a set of processors in operative communication with a digital memory. The set of processors is configured to perform a secure cross-tenant access method comprising at least one of the following: detecting a conditional access policy blocking change and issuing an alert in response to the detected conditional access policy blocking change; detecting the addition of a blocking conditional access policy and issuing an alert in response to the detected addition of a blocking conditional access policy; or detecting a cross-tenant role assignment blocking change and issuing an alert in response to the detected cross-tenant role assignment blocking change. Some embodiment variations omit one of the detection steps. The terms "cross-tenant" and "cross-tenant" are used interchangeably herein.
[0006] Unless otherwise stated, in all examples, a conditional access policy blocking change is a change that blocks authorized access to the focus tenant by a user from a secondary tenant, a blocking conditional access policy addition is the addition of a conditional access policy that blocks authorized access to the focus tenant by a user from a secondary tenant, and a cross-tenant role assignment blocking change is a change that blocks authorized access to the focus tenant by a user from a secondary tenant. Throughout this document, "by user" refers to access by a user's device, user account, software acting on behalf of the user, or hardware acting on behalf of the user. Similarly, as elsewhere in this document, authorized access to the focus tenant by a user from a secondary tenant is more concisely described as "authorized access from the secondary tenant to the focus tenant."
[0007] In all examples, unless otherwise stated, “hinder” means to block, slow down, hinder, impede, or obstruct.
[0008] In this document, user access or any other activity refers to activity on a user device, or activity on a user account, or activity on behalf of the user's software, or activity on behalf of the user's hardware. In a computing system, activity is represented by digital data, machine operation, or both. The term "user activity" as used within the scope of any claim based on this disclosure does not include human action itself, and therefore, human behavior itself is not included within the scope of any embodiment or any claim.
[0009] In some embodiments, a network security method for secure cross-tenant access includes monitoring a focus tenant's non-obstructive access policy. The monitoring includes checking for obstructive changes in the non-obstructive access policy and checking for the addition of obstructive access policies. The network security method also includes tracking the focus tenant's cross-tenant role assignments. The tracking includes examining cross-tenant role assignments in response to changes in cross-tenant role assignments.
[0010] This example network security method also includes detecting at least one of the following: a blocking change in a non-blocking conditional access policy, the addition of a blocking conditional access policy, or a change in cross-tenant role assignment.
[0011] Some network security method implementations also include modifying at least one of the following in response to the detection results: a non-obstructive access policy, an obstructive access policy, a cross-tenant role assignment, or the scope of authorized access from a secondary tenant to the focus tenant.
[0012] In some embodiments, a computer-readable storage device is configured with data and instructions that, when executed by a processor, cause a computing system to perform a secure cross-tenant access method. The method includes at least one of the following: alerting in response to detection of a conditional access policy blocking a change, alerting in response to detection of a conditional access policy blocking the addition of a conditional access policy, or alerting in response to detection of a cross-tenant role assignment blocking a change. Some embodiment variations omit one of the alerting steps.
[0013] Other technical activities and features related to the teachings of this document will be equally apparent to those skilled in the art. The examples given are merely illustrative. This summary is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed subject matter. Rather, this summary is provided to introduce some technical concepts in a simplified form, which will be further elaborated in the detailed embodiments described below. The scope of the claimed subject matter is defined by the claims as correctly understood, and in the event of any conflict between this summary and the claims, the claims shall prevail. Attached Figure Description
[0014] A more detailed description will be given with reference to the accompanying drawings. These drawings only show selected aspects and therefore cannot fully define the scope or extent of this disclosure.
[0015] Figure 1 It is a schematic diagram illustrating various aspects of a computer system and configured storage media, including some aspects typically applicable to systems providing secure cross-tenant access (SCTA) functionality;
[0016] Figure 2 This is a block diagram showing an enhanced system configured with SCTA functionality;
[0017] Figure 3 This is a block diagram showing various aspects of an enhanced system with SCTA functionality;
[0018] Figure 4 This is a block diagram showing some of the added aspects of the tenant;
[0019] Figure 5This is a data flow diagram showing various aspects of some SCTA functions;
[0020] Figure 6 This is a flowchart illustrating the steps in a secure cross-tenant access method; and
[0021] Figure 7 This is a flowchart further illustrating some steps in a secure cross-tenant access method, and includes... Figure 6 and Figure 5 . Detailed Implementation
[0022] Overview
[0023] Some of the lessons described in this article stem from the technical challenges faced in improving technologies that allow cybersecurity experts to perform secure operations on computing systems. Specifically, the challenges during the effort included: securely improving access for managed service personnel (such as technicians, security operators, and IT operators) to enable them to log in to customer tenants to resolve and fix issues within those tenants, while ensuring that the customer environment remains secure and reliable.
[0024] Multitenant cloud architectures allow multiple tenants to share computing resources in public, hybrid, or private clouds. A tenant is an architectural layer in cloud computing that lies between the user and the cloud as a whole. A given tenant typically has multiple user accounts. In many cloud computing environments, cross-tenant access raises security concerns; therefore, users within one tenant do not automatically or easily receive access to user data, settings, hardware, applications, logs, and other resources in different tenants. One security concern is that access may exceed authorized limits, and another is that access may be interrupted or impeded even when authorized. These and other concerns are the motivations behind parts of this disclosure, but the technical teachings herein are not limited in scope or applicability to these specific motivational challenges.
[0025] Some embodiments described herein utilize or provide a network security method for secure cross-tenant access, including: monitoring a non-blocking conditional access policy of a focus tenant, the monitoring including examining blocking changes in the non-blocking conditional access policy, the monitoring also including examining the addition of a blocking conditional access policy, wherein the blocking change is a change that blocks authorized access to the focus tenant by a user from a secondary tenant, and the blocking conditional access policy is a conditional access policy that blocks authorized access to the focus tenant by a user from a secondary tenant.
[0026] In these embodiments, the policy monitoring capability offers the technical benefit of mitigating unintended or covert policy changes that could disrupt or impede authorized cross-tenant access. In some scenarios, the user activity of assisting tenants is controlled by security experts within the cloud service provider, the focus tenant is the cloud service provider's customer tenant, and cross-tenant access is authorized by the customer administrator to improve customer tenant security, investigate security incidents within customer tenants, or achieve both. The policy monitoring capability makes it more difficult for attackers to use access policy changes to prevent customer tenants from receiving professional security assistance.
[0027] Some embodiments described herein utilize or provide a cybersecurity method for secure cross-tenant access, including: tracking cross-tenant role assignments for a focus tenant, the tracking including examining cross-tenant role assignments for changes in cross-tenant role assignments. This role monitoring capability has the technical benefit of mitigating accidental or covert role changes that could disrupt or impede authorized cross-tenant access. Furthermore, in some embodiments, the tracking includes detecting malicious roles. Authorized cross-tenant access is not necessarily impeded by malicious roles, but an attacker could exploit this authorized access to covertly add roles not approved by the customer. If a malicious role goes undetected, an attacker could subsequently exploit that malicious role to intentionally access the customer tenant.
[0028] Some embodiments described herein utilize or provide cybersecurity methods for secure cross-tenant access, including: correlating focus tenant auditing with secondary tenant auditing to generate a correlated audit of user activity in the focus tenant and user activity in the secondary tenant. This audit correlation functionality has technical benefits: it allows detection of whether secondary tenant users deviate from the customer-authorized set of actions, while also indicating whether a secondary tenant user performed a specific action.
[0029] For example, in some scenarios, a customer tenant administrator might approve a security investigator's access with restrictions: the access is limited to incident investigation, and the investigator may not change the customer tenant's security controls during the access period. Correlation auditing can integrate the following information: the security investigator's access request, the administrator's access authorization response with the "no change" restriction, the security investigator's login to the customer tenant and activities during the access, the security investigator's logout from the customer tenant, and the subsequent revocation of access authorization. Therefore, correlation auditing can be used to answer questions such as whether the security investigator changed any security controls, how the administrator described the purpose of the access authorization, and whether the security investigator was logged in when the security control change was made, if it was not recorded in the logs.
[0030] Some embodiments described herein utilize or provide a cybersecurity method for secure cross-tenant access, including: receiving a command from a user in a focus tenant, wherein the command belongs to at least one of the following categories: security investigation command, security modification command, or managed service command. This command functionality has the technical benefit of enabling secure cross-tenant access to include any managed service command in addition to security commands, or only managed service commands without security commands. For example, secure access can be authorized to government regulators, court-appointed experts, SaaS vendors, or vetted consultants to install specific services or optimize the performance of specific services.
[0031] Some embodiments described herein utilize or provide a network security method for secure cross-tenant access, including: receiving authorized access from a secondary tenant to a focus tenant that restricts access to that user only via login from an authorized managed device. Additionally or alternatively, some embodiments restrict authorized access from a secondary tenant to a focus tenant that restricts access to that user only via login from a specific range of IP addresses. This access restriction feature has the technical benefit of making authorized cross-tenant access more secure. In some embodiments, this feature is an optional complement to, rather than a replacement for, the monitoring, tracking, detection, alerting, and other functions described herein.
[0032] These and other benefits are not limited to the method embodiments, and those skilled in the art will clearly understand these benefits from the technical teachings provided herein.
[0033] Operating environment
[0034] refer to Figure 1 The operating environment 100 used in this embodiment includes at least one computer system 102. The computer system 102 may or may not be a multiprocessor computer system. The operating environment may include one or more machines within the given computer system, which may be clustered within the cloud 136, networked via client-server, and / or peer-to-peer. A single machine is a computer system, and a network or other collaborative group of machines is also a computer system. The given computer system 102 may be configured for end users (e.g., with applications), for administrators, or may be configured as a server, a distributed processing node, and / or otherwise.
[0035] Human user 104 may sometimes interact with user interface 328 of computer system 102 through input text, touch, voice, motion, computer vision, gestures, and / or other forms of input / output (I / O) using display 126, keyboard 106, and other peripheral devices 106. In some embodiments, virtual reality or augmented reality, or both, are provided by system 102. In some embodiments, screen 126 is a detachable peripheral device 106, while in some embodiments, screen 126 is an integral part of system 102. The user interface supports interaction between the embodiment and one or more human users. In some embodiments, the user interface includes one or more of the following: command-line interface, graphical user interface (GUI), natural user interface (NUI), voice command interface, or other user interface (UI) presentation forms, which may be presented as standalone options or integrated into the interface.
[0036] System administrators, network administrators, cloud administrators, security analysts and other security personnel, operators, developers, testers, engineers, auditors, and end users are all classified as specific types of human users 104. In some embodiments, automated agents, scripts, playback software, devices, etc., that run or otherwise serve on behalf of one or more persons may also have user accounts (e.g., service accounts). Sometimes, user accounts are created or configured as human user accounts but are actually used primarily or solely by one or more services; such accounts are service accounts in the true sense. Although a distinction can be made, "service account" and "machine-driven account" are used interchangeably herein and are not limited to any particular vendor.
[0037] Storage devices or networking devices, or both, are considered peripheral devices in some embodiments, while in other embodiments they are considered part of system 102, depending on their separability from processor 110. In some embodiments, Figure 1 Other computer systems, not shown, may interact technically with computer system 102 or with another system embodiment via, for example, a network interface device, using one or more connections to cloud 136 and / or other networks 108.
[0038] Each computer system 102 includes at least one processor 110. Similar to other suitable systems, computer system 102 also includes one or more computer-readable storage media 112, also referred to as computer-readable storage devices 112. In some embodiments, for example, tools 122 include security tools or software applications (deployed on mobile device 102, or workstation 102, or server 102), editors, compilers, debuggers, and other software development tools, as well as APIs, browsers, or web pages, and corresponding software for protocols such as HTTPS. Files, APIs, endpoints, and other resources can be accessed by accounts or sets of accounts, users 104 or user groups 104, IP addresses or groups of IP addresses, or other entities. Access attempts may present passwords, digital certificates, tokens, or other types of authentication credentials.
[0039] Storage medium 112 can be of different physical types. Some examples of storage medium 112 are volatile memory, non-volatile memory, fixed media, removable media, magnetic media, optical media, solid-state media, and other types of physically persistent storage media (distinguished from merely propagating signals or energy). Specifically, in some embodiments, a configured storage medium 114 (such as a portable (i.e., external) hard disk drive, CD, DVD, memory stick, or other removable non-volatile storage medium) becomes a functional technical component of the computer system after being inserted or otherwise installed, such that its contents are accessible to interact with and be used by the processor 110. A removable configured storage medium 114 is an example of a computer-readable storage medium 112. Some other examples of computer-readable storage media 112 include built-in RAM, ROM, hard disks, and other memory storage devices that are not easily removed by the user 104. To comply with the present U.S. Patent requirements, in any pending or granted U.S. claim, a computer-readable medium, computer-readable storage medium, computer-readable memory, and computer-readable storage device are not signals themselves or simply energy.
[0040] Storage device 114 is configured with binary instructions 116 executable by processor 110. In this document, "executable" is used broadly to include, for example, machine code, interpreted code, bytecode, and / or code running on a virtual machine. Storage medium 114 is also configured with data 118, which is created, modified, referenced, and / or otherwise used for technical effects by executing instructions 116. Instructions 116 and data 118 configure the memory or other storage medium 114 in which they reside; when the memory or other computer-readable storage medium is a functional part of a given computer system, instructions 116 and data 118 also configure the computer system. In some embodiments, a portion of data 118 represents real-world items such as events, product characteristics, inventory, physical measurements, settings, images, readings, volumes, etc., embodied in the hardware of system 102. This data is also transformed through backup, recovery, commit, abort, reformatting, and / or other technical operations.
[0041] Although the embodiments are described as being implemented by software instructions executed by one or more processors in a computing device (e.g., a general-purpose computer, server, or cluster), such a description is not intended to exhaustively describe all possible embodiments. Those skilled in the art will understand that the same or similar functionality can often be implemented, in whole or in part, directly by hardware logic to provide the same or similar technical effects. Alternatively, or in addition to software implementation, the technical functions described herein may be performed at least in part by one or more hardware logic components. For example, without excluding other implementations, some embodiments include one or more of the following: chiplets, hardware logic components 110, 128 (such as field-programmable gate arrays (FPGAs)), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SOCs), complex programmable logic devices (CPLDs), and similar components. In some embodiments, for example, components are grouped into interactive functional modules based on their inputs, outputs, or their technical effects.
[0042] In addition to processor 110 (e.g., CPU, ALU, FPU, TPU, GPU, and / or quantum processor), memory / storage medium 112, peripheral devices 106, and display 126, some operating environments also include other hardware 128, such as batteries, buses, power supplies, wired and wireless network interface cards. Throughout this document, the terms "screen" and "display" are used interchangeably. In some embodiments, display 126 includes one or more touchscreens, a screen responsive to pen or tablet input, or a screen solely for output. In some embodiments, peripheral devices 106, such as human user I / O devices (screen, keyboard, mouse, tablet, microphone, speaker, motion sensor, etc.), will operatively communicate with one or more processors 110 and memory 112.
[0043] In some embodiments, the system includes multiple computers connected via wired and / or wireless network 108. Networking interface device 128 may provide access to network 108 using, for example, network components present in some computer systems (such as packet-switched network interface cards, wireless transceivers, or telephone network interfaces). In some embodiments, virtualized forms of network interface devices and other network components (such as switches, routers, or firewalls) are also present, for example in software-defined networking or sandboxes or other secure cloud computing environments. In some embodiments, one or more computers are partially or completely "physically isolated" due to disconnection from other networked devices or remote clouds, or only intermittent connection. Specifically, secure cross-tenant access functionality 204 may be installed on the physically isolated network and then updated periodically or occasionally using removable media 114, or not updated at all. Some embodiments also transmit technical data or technical instructions, or both, via direct memory access, removable or non-removable volatile or non-volatile storage media, or other information storage retrieval and / or transmission methods.
[0044] Those skilled in the art will understand that the foregoing aspects, as well as other aspects presented in the “Operating Environment” section herein, constitute part of some embodiments. The headings herein are not intended to strictly divide features into “exemplary feature sets” and “non-exemplary feature sets.”
[0045] One or more items in the accompanying drawings are shown in outline or listed in brackets to emphasize that they are not necessarily part of the illustrated operating environment or all embodiments, but rather interoperable with items in the operating environment or some embodiments discussed herein. This does not mean that all items not shown in outline or brackets in any drawing or any embodiment are necessary. Specifically, Figure 1 Provided for convenience; something included Figure 1 This does not mean that the project itself or its described uses were known prior to this disclosure.
[0046] In any subsequent application claiming priority to the current application, reference numerals may be added to designate items disclosed in the current application. Such items may include, for example, software, hardware, steps, processes, systems, functions, mechanisms, data structures, computing resources, programming languages, tools, workflows or algorithm implementations, or other items in the computing environment that are disclosed herein but are not associated with any specific reference numerals herein. Corresponding figures may also be added.
[0047] More information about the system
[0048] Figure 2A computing system 102 is illustrated, configured with one or more secure cross-tenant access enhancement mechanisms taught herein to form an enhanced system 202. In some embodiments, the enhanced system 202 includes a single machine, a local network of machines, machines in a specific building, machines used by a specific entity, machines in a specific data center, machines in a specific cloud, or another computing environment 100 appropriately enhanced. This document will refer to [the following text is incomplete and likely refers to a different document] in various locations. Figure 2 The various aspects of this document will be discussed, and further details regarding these aspects will be provided in the “List of Reference Numerals” section following this disclosure.
[0049] Figure 3 This diagram illustrates some aspects of the enhanced system 202. It is not a comprehensive overview of all aspects of the enhanced system 202 or all aspects of the secure cross-tenant access function 204. Nor is it a comprehensive overview of all aspects of environment 100, system 202, or other contexts of the enhanced system 202, nor is it a comprehensive overview of any aspect of function 204 used in or in conjunction with system 102. Further details will be provided in different locations. Figure 3 The various aspects of this document will be discussed, and further details regarding these aspects will be provided in the “List of Reference Numerals” section following this disclosure.
[0050] Figure 4 This diagram illustrates some additional aspects of cloud tenant 124. This diagram is not a comprehensive overview of all additional aspects of tenant 124 or cloud 136. Further details will be discussed in different sections of this document. Figure 4 The various aspects of this document will be discussed, and further details regarding these aspects will be provided in the “List of Reference Numerals” section following this disclosure.
[0051] Figure 5 This diagram illustrates some aspects of data inflow, outflow, or inter-item data flow for items including Directory Service 506, Permissions Service 514, and AOBO (Representative Operations, also known as Representative Management) Service 508. This diagram is not a comprehensive overview of all additional aspects for Auxiliary Tenants 214, 124, or Focus Tenants 212, 124, or Cloud 136. Further details will be provided in different sections of this document. Figure 5 The various aspects of this document will be discussed, and further details regarding these aspects will be provided in the “List of Reference Numerals” section following this disclosure.
[0052] Other accompanying figures are also related to system 202. Figure 6 , Figure 7 and Figure 5 The operation method of function 204 in system 202 is also shown.
[0053] In some embodiments, the enhanced system 202 is networked via interface 328. In some, interface 328 includes hardware (such as a network interface card), software (such as a network stack, API, or socket), combinations (such as a network connection), or combinations thereof.
[0054] Some embodiments include a computing system 202 configured for secure cross-tenant access. The computing system includes a digital memory 112 and a processor set 110 including at least one processor, the processor set being operatively communicative with the digital memory. The processor set is configured to perform a secure cross-tenant access method 700, the secure cross-tenant access method 700 including at least one of: detecting a conditional access policy 402 blocking change 444 and issuing an alarm 306 in response to detecting a conditional access policy blocking change; detecting a conditional access policy blocking addition 446 and issuing an alarm 306 in response to detecting a conditional access policy blocking addition; or detecting a cross-tenant role assignment 408 blocking change 444 and issuing an alarm 306 in response to detecting a cross-tenant role assignment blocking change. A conditional access policy blocking change is a change 310 that blocks authorized access 308 from a user of a secondary tenant 214 to a focus tenant 212. A conditional access policy blocking addition is the addition of a conditional access policy that blocks authorized access 310 from a user of a secondary tenant to a focus tenant. Cross-tenant role assignment blocking changes is a change that prevents a user from a secondary tenant from having authorized access to the focus tenant.
[0055] Some embodiments include a case management subsystem 312, which exists in a secondary tenant and includes an interface 328 configured to receive a request 432 for authorized access for a focus tenant.
[0056] Some embodiments include an audit association subsystem 316, which is configured to associate, at execution, a secondary tenant request 432 for authorized access to a focus tenant with a focus tenant login event 132 and a focus tenant resource 438 access event 132 314.
[0057] In some embodiments, a list 320 of authorized roles 318, 134 exists in a digital memory, and the detection 602 of cross-tenant role assignment obstruction change includes the detection of anomalous roles 413, 134 that are not in the access control list of authorized roles.
[0058] Some embodiments include security group 326, which exists in secondary tenants and corresponds to non-obstructive cross-tenant role assignment 408 in focus tenant 714.
[0059] Some embodiments include a scenario analysis subsystem 324, which is configured to perform scenario analysis 322 at execution, based at least on conditional access policy scope 404 and authorized access scope 436 of authorized access 308 to focus tenant 212.
[0060] This document also describes other system embodiments, which are derived directly or as system versions of the described processes or configured media, taking into full account the detailed discussion of computing hardware herein.
[0061] Although specific examples of secure cross-tenant access architectures are shown in the accompanying figures, embodiments may differ from these examples. For example, in embodiments, items shown in different figures may be included together, items shown in figures may be omitted, functionality shown in different items may be combined into fewer items or a single item, items may be renamed, or items may be connected differently from each other.
[0062] Examples are provided in this disclosure to help illustrate various aspects of the technology, but the examples given herein do not cover all possible embodiments. For example, a given embodiment may include additional or different types of cross-tenant access functionality, and may also include different technical features, aspects, mechanisms, software, expressions, sequences of operations, commands, data structures, programming environments, execution environments, environmental or system characteristics or other functions consistent with the teachings provided herein, and may differ from the specific examples provided in other respects.
[0063] Process (also known as method)
[0064] The process (also referred to as “method” in a legal sense) is illustrated in various ways in the text and figures herein. Figure 5 , Figure 6 and Figure 7 A series of methods 500, 600, and 700 are illustrated, which are performed or assisted by some enhanced system (such as some system 202 or another enhanced system with secure cross-tenant access functionality as taught herein). Method families 500 and 600 are both proper subsets of method family 700.
[0065] Figure 5 The three phases are shown: the onboarding phase 524, the on-demand access phase 526, and the exit phase 528. Figure 5 Some variations include at most one of the stages, but do not necessarily exclude it. Figure 5 Other steps not shown in the diagram. Figure 5 Some variants include at most two of these stages, but do not necessarily exclude them. Figure 5Other steps not shown. The term "excluded" here does not mean that the stage is not performed; for example, excluded stages are sometimes performed by different parties and are therefore not included in a given embodiment. This document will refer to [these steps] in different locations. Figure 5 The various aspects of this document will be discussed, and further details regarding these aspects will be provided in the “List of Reference Numerals” section following this disclosure.
[0066] Figure 6 Some variations exclude monitoring step 302 or tracing step 304. Some variations include alarm 306 instead of modification, and some variations include both alarm 306 and modification 604. These are merely examples of variations; as described elsewhere, any operable combination of the steps disclosed herein may be part of a given embodiment.
[0067] Figures 1 to 5 An architecture for a secure cross-tenant access system 202 with implicit or explicit actions is shown, such as obtaining administrator permission, creating or providing or using or invalidating access tokens, reading and enforcing access policies, comparing role assignments, or otherwise processing data 118, wherein data 118 includes, for example, security tokens, access policies 138, roles 134, security groups 326, access requests 423 and responses 516, and directory service data 506, as well as other examples disclosed herein.
[0068] Unless otherwise stated, the technical processes shown in the figures or otherwise disclosed will be executed automatically, for example, by enhanced system 202. Related unclaimed processes, if involving human operation, may also be executed partially automatically and partially manually; for example, in some cases, human 104 may input data in response to execution by tool 122 or kernel 120. However, none of the embodiment processes contemplated herein are entirely manual or purely mental; none of the claimed processes can be accomplished solely in the human mind or solely on paper. Any interpretation of the claims to the contrary is entirely contrary to this disclosure.
[0069] In a given embodiment, zero or more of the illustrated steps of a process may be repeated, and may be operated using different parameters or data. The steps in the embodiment may also be performed in accordance with... Figure 7 Execute in different orders as shown from top to bottom. Figure 7 This is a supplement to the textual examples and textual descriptions of the embodiments provided herein. If due to… Figure 7 If any aspect or interpretation leads to inconsistencies, ambiguities, or overly broad scope, the text of this disclosure shall prevail. Figure 7 That aspect or explanation.
[0070] Arrows in a process or data flow diagram indicate permitted flows; arrows pointing in more than one direction indicate flows can occur in more than one direction. Within a given flow, steps can be performed sequentially, partially overlapping, or completely in parallel. Specifically, action items in flowchart 700 are traversed to indicate the order in which steps are performed in a process, which may differ between this execution instance and the next. The traversal order of the flowchart can also vary depending on the process embodiment. Steps can also be omitted, combined, renamed, regrouped, executed on one or more machines, or otherwise deviated from the illustrated flow, provided that the executed process is operable and conforms to at least one claim of an application or patent that includes this disclosure or claims priority to it. If those skilled in the art consider this to be related to… Figure 7 If a given sequence S of consistent steps is inoperable, then that sequence S is not within the scope of any claim. Any claim to the contrary is contrary to this disclosure.
[0071] Some embodiments provide or utilize a network security method 700 for secure cross-tenant access methods; the method is performed by a computing system 202. The method includes at least one of the following: monitoring 302 a non-obstruction conditional access policy of the focus tenant, the monitoring including examining 702 an obstruction change 444 in the non-obstruction conditional access policy, the monitoring also including examining 702 an addition 446 of an obstruction conditional access policy. An obstruction change is a change that obstructs 310 authorized access to the focus tenant by a user from a secondary tenant. An obstruction conditional access policy is a conditional access policy that obstructs 310 authorized access to the focus tenant by a user from a secondary tenant. In this example, the method also includes tracking 304 cross-tenant role assignments of the focus tenant, the tracking including examining 704 cross-tenant role assignments for changes in cross-tenant role assignments. In this example, the method also includes detecting 602 at least one of the following: an obstruction change in a non-obstruction conditional access policy, an addition of an obstruction conditional access policy, or a change in cross-tenant role assignments. In this example, the method further includes: in response to the result of the detection, modifying at least one of the following: a non-obstructive access policy, an obstructive access policy, a cross-tenant role assignment, or the scope of authorized access from a secondary tenant to the focus tenant 436.
[0072] In some embodiments, the method includes associating a focus tenant audit with a secondary tenant audit 314, thereby generating an association audit 130 of user activity 406 in the focus tenant and user activity 406 in the secondary tenant 314.
[0073] In some embodiments, the method includes receiving 708 a command 412 from a user in the focus tenant, wherein the command belongs to at least one of the following command categories: security investigation command 410, security modification command 410, or managed service command 418.
[0074] In some embodiments, monitoring 302 non-obstructive access policies includes performing 322 scenario analysis. In some embodiments, scenario analysis includes "what-if" analysis based on tool 122 adaptation to identify the potential impact of policy changes, without considering the scope 436 of cross-tenant access 308.
[0075] In some embodiments, tracking 304 cross-tenant role assignments includes detecting 706 malicious roles.
[0076] In some embodiments, the method includes setting the authorized access constraint 712 of a user from a secondary tenant to the focus tenant for zero persistence 420 and limited time 422 for access 424. In some variations, access 424 is constrained to zero persistence but not limited time, or vice versa. Not being constrained to limited time 422 does not mean "permanently valid"; non-limited time access can be terminated on demand by a command from an administrator.
[0077] In some embodiments, the method includes imposing an authorized access constraint 712 on a user-to-focus tenant from a secondary tenant to allow access only via login from an authorized managed device 426. In some embodiments, the method includes imposing an authorized access constraint 712 on a user-to-focus tenant from a secondary tenant to allow access only via login from a specific IP address range 442. In embodiments, the following constraints 712 may be implemented zero, one, two, or more: zero duration, limited time, managed device, or IP address range.
[0078] In some embodiments, the method includes defining 716 cross-tenant role assignments in the focus tenant using at least 716-granularity delegated management authority group 430.
[0079] Configured storage media
[0080] Some embodiments include a configured computer-readable storage medium 112. Examples of storage medium 112 include disks (magnetic, optical, or other), RAM, EEPROM or other ROMs, and other configurable memories, specifically including computer-readable storage media (not just for transmitting signals). In some embodiments, the storage medium is specifically configured as a removable storage medium 114, such as a CD, DVD, or flash memory. According to embodiments, various elements (such as security groups 430, 326, directory service data 506, services 508, 514, access requests 432 and responses 516, role assignments 408, access policies 138, audit events 132, subsystems 312, 316, 324, and SCTA software 216) can be used in embodiments to configure removable or non-removable, volatile or non-volatile general-purpose memory in the form of data 118 and instructions 116 to form a configured storage medium, which data 118 and instructions 116 are read from the removable storage medium 114 and / or another source (such as a network connection). The configured storage medium 112 enables the computer system 202 to perform the technical process steps disclosed herein for providing or utilizing SCTA functionality 204. Therefore, the accompanying drawings help to illustrate embodiments of the configured storage medium and process (also referred to as method) as well as system and process embodiments. Specifically, Figure 5 , Figure 6 or Figure 7 Any method steps shown or otherwise taught herein may be used to help configure the storage medium to form a configured storage medium embodiment.
[0081] Some embodiments use or provide computer-readable storage devices 112, 114 configured with data 118 and instructions 116, which, when executed by processor 110, cause computing system 202 to perform a secure cross-tenant access method 700. The method 700 includes: issuing an alert 306 in response to detection 602 of a conditional access policy blocking change, issuing an alert 306 in response to detection 602 of a conditional access policy blocking addition, or issuing an alert 306 in response to detection 602 of a cross-tenant role assignment blocking change, wherein a conditional access policy blocking change is a change that blocks authorized access to the focus tenant by a user from a secondary tenant, blocking a conditional access policy addition is the addition of a conditional access policy that blocks authorized access to the focus tenant by a user from a secondary tenant, and a cross-tenant role assignment blocking change is a change that blocks authorized access to the focus tenant by a user from a secondary tenant.
[0082] In some embodiments, the method further includes associating the focus tenant audit with the secondary tenant audit 314, thereby generating 314 an association audit of user activity in the focus tenant and user activity in the secondary tenant.
[0083] In some embodiments, the method further includes imposing an authorized access constraint 712 on the user-focused tenant from the secondary tenant for zero-duration, time-limited access via login from an authorized managed device.
[0084] In some embodiments, the method further includes restricting authorized access 712 from a user of a secondary tenant to a focused tenant to zero-duration, time-limited access via login from a specific IP address range.
[0085] In some embodiments, the method further includes restricting authorized access 712 from users of a secondary tenant to the focus tenant to access only via logins from authorized managed devices and from a specific range of IP addresses.
[0086] Supplementary Explanation
[0087] The following discussion of SCTA function 204 under different headings provides additional support. However, all of it should be considered as an integrated and integral part of this disclosure’s discussion of the contemplated embodiments.
[0088] Those skilled in the art will recognize that not every part of this disclosure, or any particular detail thereof, necessarily meets statutory standards such as implementability, written description, best mode, novelty, non-obviousness, step of inventiveness, or industrial suitability. Any apparent conflict arising from any other patent disclosure by the owner of this subject matter should not be taken into consideration in interpreting the claims set forth in this patent disclosure. Based on this understanding (which applies to the entirety of this disclosure), examples and illustrations are provided below.
[0089] In this disclosure, a customer tenant is an example of focus tenant 212. This teaching also applies to other focus tenants. For example, in some scenarios, there are also cases where a focus tenant is not a customer tenant because there is no customer-vendor business relationship between the focus tenant entity that manages, operates, controls, or owns the focus tenant and the auxiliary tenant entity that manages, operates, controls, or owns the auxiliary tenant.
[0090] Some implementations provide or enhance the capabilities of managed service technicians to act as administrators on behalf of customers, mitigating incidents involving customer tenants in a secure, compliant, auditable, and timely manner. This capability helps maintain the security of customer tenants and their assets.
[0091] Some implementations provide or utilize the following capabilities: monitoring and alerting on CA policy changes that are intended to target customer tenants and prevent authorized technical personnel from logging into the customer product portal.
[0092] Some implementations provide or utilize the following capabilities: monitoring and alerting when cross-tenant role assignments expand beyond their intended purpose.
[0093] Some embodiments provide or utilize the capability to provide correlated auditing of all operations performed by a technician across different systems. Some embodiments include case management audit events, login logs from AAD or other directory services 506, and product audit events.
[0094] Some embodiments provide or utilize the capability of allowing a security technician to request limited-time, non-persistent access within a case management system framework. Some embodiments provide or utilize the capability of allowing a security technician to request limited-time, persistent access within a case management system framework.
[0095] Some implementations provide or utilize the following capability: providing limited-time cross-tenant role assignment in a focus tenant.
[0096] Some implementations provide or utilize the capability to allow only technical personnel to access the focus tenant from secure and restricted devices registered in the secondary tenant's MEM, thereby reducing the attack surface.
[0097] Some embodiments provide or utilize the following capabilities: allowing technicians to log in to a customer's product portal and perform operations that can improve the security, reliability, performance, or usability of the customer's products.
[0098] Some implementations provide or utilize the capability to provide correlated auditing of all operations performed by technical personnel across different systems. In some instances, these audits include case management audit events, directory service login events, and product audit events.
[0099] Some implementations provide or utilize the following capabilities: monitoring and alerting on CA policy changes that are intended to target customer tenants and prevent authorized technical personnel from logging into the customer product portal.
[0100] Some implementations provide or utilize the following capabilities: establishing a trust model that allows customers to authorize the creation of cross-tenant access policies and conditional access policies on their tenants.
[0101] Some embodiments provide or utilize the ability to extend the scope of approvers for limited, non-continuous access to technical personnel beyond the MSE tenant.
[0102] Some implementations provide or utilize the following capabilities: monitoring and alerting when cross-tenant role assignments expand beyond their intended purpose.
[0103] Some embodiments provide or utilize a case management subsystem (e.g., an enhanced Dynamics 365 integrated case management system) to obtain non-persistent access via access management (e.g., cross-tenant access management in AAD) to remediate security incidents and perform mitigation actions. Many examples of remediation or mitigation include isolating devices, running antivirus scans, and deactivating devices. In some embodiments, authorized access includes operations on a security portal (such as the MEM or MSE portal). Some embodiments use security-restricted Windows registered in the Microsoft Endpoint Manager (MEM) of a Microsoft Expert (MSE) tenant. Device (a trademark of Microsoft Corporation). Some embodiments also provide the ability to perform correlated audits of all operations performed by a technician in the aforementioned systems. Some embodiments also provide monitoring of conditional access (CA) policies in customer tenants to prevent customers or intruders from blocking access to authorized technicians.
[0104] Some embodiments utilize or modify AD login security features, such as X-TAP policy trust settings (where customer tenant 212 trusts compliant device 101 from secondary tenant 214), inbound conditional access for customer tenants, with granular targeting (external user type and tenant scope), and constraints (technicians via Windows registered in secondary tenant 214's MEM). Device access to customer tenants). Some embodiments utilize or modify... AD cross-tenant role assignment is used for authorization. Some implementations utilize or modify... Active Directory Access Management (ELM) is used for Just-In-Time (JIT) access configurations for technical personnel (a trademark of Microsoft Corporation).
[0105] In some embodiments, a customer global administrator participates in a one-time process of setting up AOBO components (such as X-TAP and inbound conditional access) for secondary tenants. In some embodiments, an AOBO component specific to managed service 416 is enabled whenever an administrator authorizes a managed service involving SCTA.
[0106] Some embodiments provide or utilize enhancements around security, auditing, and integration with the case management system to make the solution robust and secure, and improve availability. Some embodiments fill gaps by providing one or more of the following: a one-stop solution for technical personnel that allows them to request JIT access from the case management system; an audit trail that correlates JIT requests and approvals, technical personnel login logs in customer tenants, and audit logs showing changes to customer tenants; a tracking system that notifies technical personnel if an attacker or customer administrator modifies an existing CA policy or creates a stricter CA policy (potentially blocking technical personnel logins); and a tracking system that notifies the customer administrator if a service operated by a technical personnel creates a cross-tenant role assignment that exceeds the scope agreed upon between the auxiliary tenant oversight administrator or the technical personnel and the managed service customer.
[0107] Figure 5 This involves two tenants (secondary tenant and focus tenant) shown vertically and three phases of AOBO shown horizontally, but the steps can also be divided differently. Another way to divide the phases is to divide AOBO into four phases: Onboarding 524, Access 526, Access Expiration (...). Figure 5 (Not shown in the image) and Exit 528. Onboarding 524 and Exit 528 involve one-time settings triggered by a customer or other focused tenant's global administrator.
[0108] In some embodiments, during onboarding phase 524, the customer's global administrator onboards to the managed services 502 and creates X-TAP and inbound conditional access in their tenant 212. Subsequently, AOBO service 508 creates a security group 504 in the secondary tenant and establishes a cross-tenant role assignment 512 in the customer tenant. In some cases, the security group is defined by customer role; for example, the group contoso_securityadmin is created for the roles of security administrator and customer Contoso. In some cases, establishment 512 includes configuring XTAP settings to allow the service provider. In some embodiments, to allow JIT access to these security groups, ELM package 510 is configured in the secondary tenant. The ELM package provides a policy that grants limited-time access to the group and requires an approver (role-based) to approve the request.
[0109] In some embodiments, during the on-demand access phase 526, the technician navigates to the auxiliary tenant's myaccess portal or similar portal and selects the package to access. The access request 432 undergoes an approval process, generating a response 516 that approves or disapproves the request. Upon approval, the technician is granted access to the customer tenant.
[0110] In some embodiments, during the access expiration phase, the technical staff member's membership in the security group is removed based on ELM policy configuration. Figure 5 This is part of the exit phase.
[0111] In some embodiments, during exit phase 528, the customer's global administrator may choose to unsubscribe from the managed service. X-TAP is then deactivated, and the cross-tenant role assignment is removed. The customer administrator is also advised to remove X-TAP and the inbound CA from their tenant 212. In some embodiments, exit 520 includes removing the access package and security group. In some embodiments, exit 522 includes configuring XTAP settings to disallow service provider access and removing the cross-tenant role assignment.
[0112] Some implementations provide policy monitoring. Conditional access policies are monitored so that if a modified or stricter policy is detected in a customer tenant, a notification is sent to the tenant's technical staff, who can then collaborate with the customer administrator to resolve the issue.
[0113] Some implementations provide role tracking. Cross-tenant role assignments are tracked so that the system does not violate the contract by creating more role assignments than agreed upon between the secondary tenant vendor and the customer.
[0114] Some embodiments provide reporting to track AOBO activity using associated audit logs. Some embodiments provide associated sets of audit logs to track AOBO request and approval audit logs in managed services, as well as to track activity in customer tenants.
[0115] Some embodiments provide or utilize a network security method including: receiving approval for a limited-time zero-continuous access by an external user to a cloud tenant's controlled resources (the external user was not previously a user of the cloud tenant); providing a limited-time cross-tenant role assignment for the external user within the cloud tenant; restricting the approved access to access from a security-restricted registered device; auditing the external user's actions within the cloud tenant during the duration of the approved access; and monitoring the cloud tenant's conditional access policy during the duration of the approved access, and issuing an alert if an attempt to change the policy is detected that would impede the approved access.
[0116] Some implementations include monitoring a cloud tenant’s conditional access policy during the duration of an approved access, and issuing an alert if an attempt to change the policy is detected that would prevent the approved access.
[0117] Some implementations include: monitoring cross-tenant role assignments for cloud tenants during the duration of an approved access, and issuing an alert if an attempt to change the role assignments is detected that would prevent the approved access.
[0118] Some implementations include: associating the audit of external user operations within a cloud tenant with operations such as JIT requests, approvals, and activities during approved access periods.
[0119] Some environments include processes for AOBO access within customer tenants of managed services. In some embodiments, AOBO customer onboarding includes these computing system steps or states in the listed sequence: executing software to initiate onboarding by a customer administrator, obtaining an authorized AAD role for the managed service, obtaining customer administrator consent for the role, creating an XTAP within the customer tenant using an administrator token, creating CA Policy 1 within the customer tenant using an administrator token (Policy 1 blocks devices outside the cloud PC virtual network IP range), and creating CA Policy 2 within the customer tenant using an administrator token (Policy 2 allows compliant managed devices (e.g., Windows 32000) from a certain IP range (a Microsoft trademark). (Managed) device. After the customer onboarding with AOBO, there is a back-end onboarding process, which includes the following steps or states in the listed sequence: onboarding API call, XTAP lock, creating security groups in the secondary tenant for each customer, each role, and each managed service, configuring cross-tenant role assignments in the customer tenant, and creating AAD permission packages in the secondary tenant for each security group.
[0120] Some environments include a background CA consistency checker that runs at intervals such as hourly or other specified intervals. In some embodiments, CA policy consistency check 702 includes these computational system steps or states in the listed sequence: obtaining the baseline CA policy, obtaining cross-tenant access policies in customer tenants, comparing the CA policy with the hypothesis analysis, marking the payload as "verified" if the conditional access policy change verification result is "passed"; if the verification result is "failed", invoking the ICM connector API, creating an ICM, and, for example, initiating an investigation using a customer administrator. ICM stands for Intelligent Communication Manager, which in some environments is used as an incident management service and internal tracing tool.
[0121] Some environments include a background role assignment consistency checker that runs at intervals such as hourly or other specified intervals. In some embodiments, the cross-tenant role assignment consistency check 704 includes these computational system steps or states in the listed sequence: obtaining role assignments approved by the customer administrator, obtaining cross-tenant role assignments from the customer tenant, comparing the role assignments, and marking the payload as "verified" if the role assignment verification result is "passed"; if the verification result is "failed", invoking the ICM connector API, creating an ICM, and starting an investigation.
[0122] Some environments include AOBO customer exit, which includes these compute system steps or states in the listed sequence: locate all AOBO-related artifacts in the customer tenant, locate all AOBO-related artifacts in the secondary tenant, mark XTAPs as soft delete, mark cross-tenant role assignments as soft delete, mark CA policies as soft delete, mark SCTA security groups in the secondary tenant as soft delete, and mark SCTA permission access packages in the secondary tenant as soft delete. Various variations may change the marking order or include marking simultaneously, or both.
[0123] Some environments include a background exit phase following a customer exit from AOBO. This background exit includes these compute system steps or states in the listed sequence: disabling XTAP in the customer tenant, removing cross-tenant role assignments in the customer tenant, removing SCTA security groups in the secondary tenant, removing SCTA permission access packages in the secondary tenant, and notifying the customer administrator to remove CA policies via email or otherwise.
[0124] Some environments include a process for automating access using reader roles, which includes these computational system steps or states in the listed sequence: assigning a case to the SOC (Security Operations Center), finding an AAD reader role with customer consent for the managed service, finding the correct access permission package for the AAD role in the secondary tenant, requesting access on behalf of the SOC, automatically approving the request, and polling the access management API to obtain the remaining time for access.
[0125] Some environments include a process for requesting access to a higher privileged role, which includes these computational system steps or states in the listed sequence: a SOC request for a specific role in a customer tenant, the process ending if the request is denied, otherwise a case is assigned to the SOC user, finding the correct access permission package for the AAD role in the auxiliary tenant, requesting access on behalf of the SOC and executing the audit process described below, transferring control to the AAD access management logic application, sending notifications to the approval group and case management system, and transferring control to the approval process.
[0126] In the approval process, the approver communicates through a communication platform (e.g., Microsoft). The platform (a trademark of Microsoft Corporation) or case management system receives the notification and then approves or denies the access request in a response notification via the platform or case management system, or both. The request and response are logged by the system for auditing purposes.
[0127] In the requester-client-tenant access flow, the requester (e.g., SOC) receives a notification. If access is approved, the requester logs into the client-tenant account, the computation system performs an operation on a different resource within the client-tenant account (e.g., via Cross-Domain Identity Management (SCIM)), and then the client-tenant access flow ends. This operation is logged by the system for auditing purposes.
[0128] Some environments include audit log access processes that encompass these computational system steps or states in the listed sequence. In one path where a customer views the Corresponding 314 audit logs: software acting on behalf of the customer administrator performs role-based access control (RBAC) checks; filters the logs by customer ID and date; and feeds the results back to the Corresponding Query Engine. In another path, software acting on behalf of the managed service administrator performs managed service RBAC checks, filters the logs by managed service and date, and feeds the results back to the Corresponding Query Engine. The Corresponding Query Engine feeds back to the centralized audit store, which also optionally receives audit-rich log data from activity in the focus tenant and secondary tenants.
[0129] In some embodiments, system 202 is an embedded system, such as an Internet of Things (IoT) system. "IoT" or "Internet of Things" means any networked collection of addressable embedded computing or data generating or executing nodes. A single node is referred to as IoT device 101, IoT 101, IoT system 102, or IoT system 102. Such a node is an example of computer system 102 as defined herein and may include or be referred to as, for example, a "smart" device, "endpoint," "chip," "tag," or "marker," and IoT may be referred to as a "network-physical system." In the term "embedded system," the embedding involved refers to embedding a processor and memory in a device, rather than embedding debugging scripts in source code.
[0130] IoT nodes and systems typically have at least two of the following characteristics: (a) no local human-readable display; (b) no local keyboard; (c) the primary input source is a sensor tracking a non-verbal data source to be uploaded from the IoT device; (d) no local spinning disk storage, with only RAM or ROM chips providing the sole local memory; (e) no CD or DVD drive; (f) embedded in a home appliance or household fixture; (g) embedded in an implantable or wearable medical device; (h) embedded in a vehicle; (i) embedded in a process automation control system; or (j) designed for use in one of the following areas: environmental monitoring, urban infrastructure monitoring, agriculture, industrial equipment monitoring, energy use monitoring, human or animal health or fitness monitoring, physical security, physical transportation system monitoring, object tracking, inventory control, supply chain control, fleet management, or manufacturing. IoT communication can use protocols such as TCP / IP, CoAP (Co-Restricted Application Protocol), Message Queuing Telemetry Transport (MQTT), Advanced Message Queuing Protocol (AMQP), HTTP, HTTPS, Transport Layer Security (TLS), UDP, or Simple Object Access Protocol (SOAP), for example, for wired or wireless (cellular or other) communication. IoT storage or actuators, data outputs, or controls can be targets of unauthorized access attempts via the cloud, another network, or direct local access.
[0131] Technical features
[0132] The technical features of the embodiments described herein will be readily apparent to those skilled in the art and will also be readily recognized by a careful reader in various ways. Some embodiments involve various technical activities deeply rooted in computing technology, such as creating a security group data structure 326 (504), creating an access permission packet data structure 530 (510), establishing a cross-tenant role assignment 408 (512), and access based on IP address 440 or managed device 426 state constraints 712. Some of the technical mechanisms discussed include, for example, software 216 for monitoring access policies 138 and tracking roles 134, an auditing subsystem 316, a case management subsystem 312, and a scenario analysis subsystem 324. Some of the technical effects discussed include, for example, detection 602 of cross-tenant access restriction changes or additions in conditional access policies 402, detection of cross-tenant access restriction changes in role assignment 408, detection 706 of malicious roles 414 and 134, and association 314 of activities in the focus tenant 212 with activities in the secondary tenant 214. Therefore, purely thought processes and activities relying solely on pen and paper are explicitly excluded. Based on the provided description, other advantages of the teaching-based technical characteristics will also be apparent to those skilled in the art.
[0133] Those skilled in the art will understand that cross-tenant access activities in a cloud computing environment are technical activities that cannot be accomplished through mere thought, as they require computing system activities in the focus tenant 212 or activities in the auxiliary tenant 214, or both. For example, this includes creating, reading, modifying, or deleting data structures 402, 408, and 326 in the computer system memory. Furthermore, a computing system cannot be configured to perform secure cross-tenant access as described herein solely through thought or pen-and-paper manipulation. Those skilled in the art will also understand that attempting to implement secure cross-tenant access manually would result in unacceptable delays in program execution and introduce a serious risk of human error. For example, human error could cause program crashes or expose the system to serious security risks. Clearly, humans do not possess the speed, accuracy, memory capacity, and specific processing capabilities required to perform secure cross-tenant access as described herein.
[0134] Specifically, the secure cross-tenant access described herein is part of computing technology. Therefore, improvements to secure cross-tenant access, such as feature 204 described herein, are improvements to computing technology.
[0135] Different embodiments offer different technical benefits or other advantages in different situations, but those skilled in the art will recognize, upon understanding the teachings herein, that, as described in many places, particular technical advantages often stem from specific embodiment features or combinations of features. Any general or abstract aspect integrated into a practical application, such as access control identification service 506 within a set of network security controls, security or managed service case management tool 312, or auditing tool 316.
[0136] Some of the embodiments described herein can be viewed in a broader context. For example, concepts such as efficiency, reliability, user satisfaction, or consumption may be considered relevant to a particular embodiment. However, the breadth of the context does not imply that this document seeks proprietary rights to abstract concepts; in fact, it does not.
[0137] Instead, this disclosure focuses on providing suitable specific embodiments that fully or partially solve specific technical problems, such as how to improve the security of cross-tenant access, how to detect unauthorized activity during cross-tenant access, and how to detect unauthorized roles during cross-tenant access. Other configured storage media, systems, and processes involving efficiency, reliability, user satisfaction, or waste are not within the scope of this document. Therefore, with a proper understanding of this disclosure, vague descriptions, mere abstractions, lack of technical features, and the resulting problems of proof can be avoided.
[0138] Additional combinations and variations
[0139] Any combination of these combinations of software code, data structures, logic, components, communications, and / or their functional equivalents may also be combined with any of the systems described above and their variations. A process may include any step described herein in any operable subset or combination or sequence. Each variation may occur alone or in combination with any one or more other variations. Each variation may occur with any process, and each process may be combined with any one or more other processes. Each process or combination of processes (including variations) may be combined with any of the configured storage media described above and with variations.
[0140] More generally, those skilled in the art will recognize that not every part or any particular detail of this disclosure is required to meet legal standards such as implementability, written description, or best mode. Furthermore, embodiments are not limited to the specific scenarios, heuristic examples, operating environments, tools, peripherals, software process flows, identifiers, data structures, data selections, naming conventions, symbols, control flow, or other implementation choices described herein. Any apparent conflict arising from any other patent disclosures by the owner of this subject matter should not be taken into consideration in interpreting the claims set forth in this patent disclosure.
[0141] Abbreviations, abbreviations, names and symbols
[0142] The following defines some abbreviations, acronyms, names, and symbols. Other terms are defined elsewhere in this document or will be understood by those skilled in the art without further definition.
[0143] AAD: Active Directory (a trademark of Microsoft Corporation)
[0144] ALU: Arithmetic Logic Unit
[0145] AOBO: Represents Action, also known as Represents Management
[0146] API: Application Programming Interface
[0147] BIOS: Basic Input / Output System
[0148] CA: Conditional Access
[0149] CD: CD-ROM
[0150] CPU: Central Processing Unit
[0151] DVD: Digital Multifunction Disc or Digital Video Disc
[0152] ELM: AAD Access Management
[0153] FPGA: Field Programmable Gate Array
[0154] FPU: Floating-point processing unit
[0155] GDPR: General Data Protection Regulation
[0156] GPU: Graphics Processing Unit
[0157] GUI: Graphical User Interface
[0158] HTTPS: Hypertext Transfer Protocol, secure
[0159] IaaS or IaaS: Infrastructure as a Service
[0160] JIT: Just-in-Time
[0161] LAN: Local Area Network
[0162] MEM: Microsoft Endpoint Manager
[0163] MSE: Microsoft Expert
[0164] OS: Operating System
[0165] PaaS or PaaS: Platform as a Service
[0166] RAM: Random Access Memory
[0167] ROM: Read-Only Memory
[0168] TPU: Tensor Processing Unit
[0169] UEFI: Unified and Extensible Firmware Interface
[0170] UI: User Interface
[0171] WAN: Wide Area Network
[0172] XTAP: Cross-tenant access policy
[0173] Some additional terms
[0174] This document refers to exemplary embodiments such as those shown in the accompanying drawings and describes them using specific language. However, those skilled in the art, upon understanding this disclosure, may make alterations and further modifications to the features shown herein, as well as additional technical applications to the abstract principles embodied in the specific embodiments. Such alterations, modifications, and applications should be considered within the scope of protection of the claims.
[0175] The meanings of the terms are clarified in this disclosure, and therefore these clarifications should be carefully considered when interpreting the claims. Specific examples are given, but those skilled in the art will understand that other examples may also fall within the meaning of the terms used and within the scope of one or more claims. Terms herein may not necessarily have the same meaning as in their general usage (especially non-technical usage), or in a particular industry usage, or in a particular dictionary or dictionary set. Reference numerals may be used with various terms to help indicate the scope of the terms. The common use of reference numerals does not mean that the objects referred to by those reference numerals necessarily share every aspect, feature, or limitation. The omission of reference numerals from the given text does not mean that the content of the figures is not discussed in that text. This disclosure claims and exercises the right to use specific and optional terminology for interpretation. Referenced terms are explicitly defined, but terms may also be implicitly defined without quotation marks. Terms may be explicitly or implicitly defined in the detailed description and / or other parts of the application.
[0176] A “computer system” (also referred to as a “computing system”) may include, for example, one or more servers, motherboards, processing nodes, laptop computers, tablets, personal computers (portable or non-portable), personal digital assistants, smartphones, smartwatches, smart bracelets, mobile phones, other mobile devices having at least a processor and memory, video game systems, augmented reality systems, holographic projection systems, televisions, wearable computing systems, and / or other devices that provide one or more processors at least partially controlled by instructions. Instructions may be in the form of firmware or other software in memory and / or dedicated circuitry.
[0177] A "multithreaded" computer system is a computer system that supports multiple threads of execution. The term "thread" should be understood to include code that is capable of or subject to scheduling and may be synchronized. Outside of this disclosure, threads may also be referred to by other names, such as "task," "process," or "coroutine." However, this document distinguishes between threads and processes: a thread defines an execution path within a process. Furthermore, threads within a process share a given address space, while different processes have their own distinct address spaces. Threads within a process can run in parallel, sequentially, or in a combination of parallel and sequential execution (e.g., time-sharing scheduling).
[0178] A "processor" is a unit of thread processing, such as a core in a multithreaded implementation. Processors comprise hardware. A given chip can contain one or more processors. Processors can be general-purpose, or they can be customized for specific purposes, such as vector processing, graphics processing, signal processing, floating-point arithmetic, encryption, I / O processing, machine learning, etc.
[0179] The "kernel" includes the operating system, hypervisor, virtual machine, BIOS or UEFI code, and similar hardware interface software.
[0180] "Code" refers to processor instructions, data (including constants, variables, and data structures), or both. "Code" and "software" are used interchangeably in this document. Executable code, interpreted code, and firmware are some examples of code.
[0181] The term "program" in this article is used broadly to refer to applications, kernels, drivers, interrupt handlers, firmware, state machines, libraries, and other code written and / or automatically generated by programmers (also known as developers).
[0182] A "routine" is a callable segment of code that typically returns control to the instruction immediately following the point in the program execution that called the routine. Depending on the terminology used, in other contexts, "function" and "procedure" are sometimes distinguished: functions typically return a value, while procedures do not. As used in this article, "routine" includes both functions and procedures. A routine may have code that returns a value (e.g., sin(x)), or it may simply return without providing a value (e.g., an empty function).
[0183] A "service" refers to a callable program service in a cloud computing environment or other network or computing system environment that provides resources to multiple programs, provides access to resources to multiple programs, or both. The service implementation itself may include multiple applications or other programs.
[0184] "Cloud" refers to pooled resources used for computing, storage, and networking, elastically available for on-demand services measured by usage. A cloud can be a private cloud, public cloud, community cloud, or hybrid cloud, and cloud services can be provided in the form of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), or other services. Unless otherwise stated, any discussion of reading from or writing to a file includes reading / writing to a local file, reading / writing over a network (which can be a cloud network or other networks), or both (local and networked reading / writing). The cloud may also be referred to as a "cloud environment" or a "cloud computing environment."
[0185] "Access" to computing resources includes the use of permissions or other capabilities to read, modify, write, execute, move, delete, create, or otherwise utilize the resource. An attempted access can be clearly distinguished from an actual access, but "access" without the qualifier "attempt" includes both attempted access and access that is actually executed or provided.
[0186] In this document, user activity refers to activity of a user device, or activity of a user account, or activity of software representing the user, or activity of hardware representing the user. In a computing system, activity is represented by digital data, machine operation, or both. No human action itself is included as mentioned within the scope of any claim based on this disclosure. Therefore, software or hardware activity “representing the user” means software or hardware activity representing a user device, a user account, or another computer mechanism or computing component, and thus human behavior itself is not included within the scope of any embodiment or claim.
[0187] For example, "digital data" refers to data in a computing system, as opposed to data recorded on paper or thoughts in the human brain. Similarly, "digital storage" refers to non-biological devices, such as computing storage hardware, rather than the memories of humans or other organisms.
[0188] As used herein, unless otherwise stated, “include” allows the addition of elements (i.e., include means contain).
[0189] "Optimization" refers to improvement, not perfection. For example, it may involve further improving an already optimized program or algorithm.
[0190] In this article, "process" is sometimes used as a term in the field of computer science and, in this technical sense, encompasses users of computing resources. "Process" can also include, for example, coroutines, threads, tasks, interrupt handlers, application processes, kernel processes, procedures, or object methods. In fact, a "process" is a system tool (such as...) task manager, The term "process" refers to a computational entity identified by tools in Photoshop or similar operating system environments (trademarks of Microsoft Corporation and Linus Torvalds, respectively). It can also be used as a term in the field of patent law, for example, in describing a "method claim" to distinguish it from a "system claim" or a "manufacture claim (configuration of storage medium)." Similarly, "method" is primarily used herein as a technical term in the field of computer science (a "routine"), but it is also a term in the field of patent law (similar to "process"). The terms "process" and "method" in the patent law sense are used interchangeably herein. Those skilled in the art will understand the meaning referred to in the particular instances, and will also understand that sometimes a given claimed process or method (in the sense of computer science) can be implemented using one or more processes or methods (in the sense of computer science).
[0191] "Automatically" means through the use of automation (e.g., general-purpose computing hardware configured by software for the specific operations and technical effects discussed herein), rather than without automation. Specifically, steps performed "automatically" are not accomplished through manual paper-based operations or solely in the human brain, although the steps may be initiated or interactively guided by humans. Automated steps must be executed by machines to achieve one or more technical effects that are impossible without the provided technical interaction. Automated steps are presumed to include at least one actively performed operation.
[0192] Those skilled in the art will understand that the technical effect is a speculative purpose of the technical embodiments. For example, embodiments involve computation, and some computations can be performed without technical components (e.g., by paper and pen, or even as thought steps), but this fact does not eliminate the existence of the technical effect or change the specific technical nature of the embodiment, especially in real-world implementations. SCTA operations, such as reading or modifying identity provider 506 entries, analyzing strategy 138 for access blocking 310 effects, and many other operations discussed herein (whether or not illustrated in the figures), are understood to be inherently digital. Even in hypothetical prototype scenarios, human thought cannot directly interact with a CPU or other processor or with RAM or other digital storage to read and write the necessary data to perform the SCTA steps 700 taught herein, let alone in the real-world, large-scale computing environment of the embodiments. This will be fully understood by those skilled in the art in light of this disclosure.
[0193] "Through computation" also means using computing devices (at least a processor and memory), and excludes obtaining results solely through human thought or action. For example, performing arithmetic with pen and paper does not fall under the definition of "through computation" in this context. Computational results are faster, broader, deeper, more accurate, more consistent, more comprehensive, and / or otherwise provide technological effects that exceed the limits of human performance. "Computational steps" are steps performed computationally. Neither "automatically" nor "through computation" necessarily means "immediately." "Through computation" and "automatically" are used interchangeably in this context.
[0194] "Actively" means without a direct request from the user. In fact, the user may not even be aware that the active steps of the embodiments are possible until the results of the steps have been presented to the user. Unless otherwise stated, any calculations and / or automated steps described herein may also be performed actively.
[0195] "Based on" means at least based on, but not exclusively based on. Therefore, computation based on X depends at least on X, and may also depend on Y.
[0196] Throughout this document, the optional plural forms “(s),” “(es),” or “(ies)” are used to indicate the presence of one or more of the indicated features. For example, “processor(s)” means “one or more processors” or equivalently, “at least one processor.”
[0197] The term "at least one" in the list of items means one item in a project, or two items in a project, or three items in a project, etc., up to and including all N items, where the list is a list of N items. The presence of an item in the list does not necessarily mean that the embodiment must include that item (or check that item). For example, if an embodiment of a system is described herein as including at least one of A, B, C, or D, then a system that includes A but does not check B, C, or D is an embodiment, and a system that includes A and also includes B but does not include or check C or D is also an embodiment. A similar understanding should be applied to items in steps, step portions, or options of a method implementation. The above examples are not exhaustive and are only intended to help understand the scope of "at least one" herein.
[0198] For the purposes of U.S. law and practice, the word “step” as used herein, in the claims, or elsewhere is not intended to trigger the interpretation of “means-plus-function,” “step-plus-function,” or the claims interpretation under Title 35, Section 112(6) / 112(f) of the United States Code. Any presumption having such effect is hereby expressly refuted.
[0199] For the purposes of U.S. law and practice, claims are not intended to trigger a "means-plus-function" interpretation unless they use the phrase "for a component." Claim language intended to be interpreted as component-plus-function language (if any) will explicitly state this intention by using the phrase "for a component." When a component-plus-function interpretation is applied, whether by using the term "component" in the claim language and / or the legal constructs of the court, the component referred to in the specification for a given noun or given verb shall be understood to be linked to the claim language and, herein, linked together by any of the following: appearing within the same box in the accompanying drawings, being indicated by the same or similar names, being indicated by the same reference numerals, the functional relationship depicted in any of the drawings, or the functional relationship indicated in the text of this disclosure. For example, if a claim defines "zac widget" and the claim is to be interpreted as "means plus function", then at least any reference to "zac widget" in any drawing module, paragraph, or example in the specification, or any structure associated with any drawing reference assigned to the zac widget, or any structure disclosed as having a functional relationship with the structure or operation of the zac widget, should be considered as part of the structure related to the "zac widget" as determined in the application, and help to define the equivalent scope of the structure of the "zac widget".
[0200] Those skilled in the art will recognize that this disclosure discusses various data values and data structures, and recognizes that these items reside in memory (RAM, disk, etc.), thereby configuring the memory. Those skilled in the art will also recognize that this disclosure discusses various algorithmic steps to be implemented in executable code in a given implementation, and that such code also resides in memory, and that it effectively configures any general-purpose processor that executes it, thereby transforming it from a general-purpose processor into a dedicated processor of functionally dedicated hardware.
[0201] Therefore, even if the claims do not explicitly describe the existence of each data structure or data value or the mentioned code segment, a person skilled in the art would not consider the following to be non-overlapping: (a) the memory described in the claims, and (b) the data structures, data values, or code described in the claims. Data structures and data values, as well as code, are understood to reside in memory. Therefore, it is not necessary to explicitly state such storage relationships, but it is not prohibited to do so; for emphasis, one or two may be selectively explicitly stated, but this does not mean that all other data values, data structures, and code are not stored in memory. Similarly, the function of code described in the claims is understood to configure the processor, regardless of whether such configuration quality is explicitly described in the claims.
[0202] Throughout this document, unless otherwise expressly stated, any reference to a step in the process assumes that the step can be performed directly by the interested party and / or indirectly by the party through an intervention mechanism and / or intervention entity, and remains within the scope of that step. That is, unless direct execution is explicitly required, the interested party is not required to directly execute the step. For example, computational steps on behalf of the interested party, such as accessing, adding, alerting, analyzing, auditing, checking, comparing, constraining, associating, creating, deleting, detecting, executing, improving, inspecting, investigating, mitigating, modifying, monitoring, unloading, loading, executing, receiving, requesting, responding, establishing, tracking, using (as well as accessing, accessed, adding, added, etc.) regarding a destination or other entity, may involve intervention actions, such as those described above or such as forwarding, copying, uploading, downloading, encoding, decoding, compressing, decompressing, encrypting, decrypting, authenticating, invoking, etc., including any actions described in this document, and are still understood to be performed directly by or on behalf of the interested party. The example verbs listed here may overlap in meaning or even be synonyms; individual verb names do not specify a separate function in each case.
[0203] For example, whenever reference is made to data or instructions, it should be understood that these items are configured in a computer-readable memory and / or computer-readable storage medium to convert them into specific entries, rather than simply existing on paper, in a person's mind, or, for example, merely as a signal propagating on a wire. For the purposes of U.S. patent protection, memory or other storage devices or other computer-readable storage media are not propagating signals, or carrier waves, or merely energy outside the scope of patentable technology under the interpretation of the U.S. Patent and Trademark Office (USPTO) in the case of In reNuijten. In the United States, no claim covers signals themselves or merely energy, and any claim interpreted in light of the additional statements in this disclosure is unreasonable. Unless otherwise expressly stated in claims granted outside the United States, claims do not cover signals themselves or merely energy.
[0204] Furthermore, although the opposite is apparent elsewhere herein, it should be understood that there is a clear distinction between (a) a computer-readable storage medium and a computer-readable memory, and (b) a transmission medium (also referred to as a signal medium). A transmission medium is a computer-readable medium that propagates a signal or carrier wave. In contrast, a computer-readable storage medium and a computer-readable memory and a computer-readable storage device are computer-readable media that do not propagate a signal or carrier wave. Unless otherwise expressly stated in the claims, “computer-readable medium” means a computer-readable storage medium and not the propagation of a signal itself or energy alone.
[0205] The term "example" in this document is illustrative. The term "example" is not interchangeable with "invention." Examples may be freely shared or borrowed to create other examples (assuming the result is workable), even if the resulting combination of aspects is not explicitly described herein. Requiring an explicit and separate description of every permissible combination is unnecessary for someone skilled in the art and violates the policy of acknowledging that patent specifications are written for those skilled in the art. Even based on a small number of composable features, it is apparent through formal combinatorial calculations or informal common-sense intuition that a large number of possible combinations exist for the aspects described herein. Therefore, requiring an explicit listing of each combination violates the policy of patent specifications being concise and readers possessing relevant technical knowledge.
[0206] List of reference numerals in the attached figures
[0207] The following list is provided for convenience and support of the accompanying drawings and as part of the specification text, which describes various aspects of the embodiments by referring to multiple items. Items not listed herein may still be part of a given embodiment. For better readability, some, but not all, of the references to items in the text are accompanied by the given reference numerals. The same reference numerals may be used in different examples or instances of a given item. The list of reference numerals is:
[0208] 100. Operating environment, also known as computing environment; includes one or more systems. 102.
[0209] The machine in system 101 102, for example, any device having at least a processor 110 and memory 112 and also having different identifiers (such as IP addresses or Media Access Control (MAC) addresses); can be a physical machine or a virtual machine implemented on physical hardware.
[0210] 102. A computer system, also known as a "computing system" or "computer network," and when in a network, it can be called a "node."
[0211] 104 users, such as users of Enhanced System 202
[0212] 106 peripheral devices
[0213] 108 networks, such as LANs, WANs, software-defined networks, cloud, and other wired or wireless networks, typically include LANs, WANs, software-defined networks, cloud, and other wired or wireless networks.
[0214] 110 processors or processor sets; including hardware
[0215] 112 Computer-readable storage media, such as RAM, hard disk
[0216] 114 Configured removable computer-readable storage media
[0217] 116 Instructions executable by the processor; can be on a removable storage medium or in other memory (volatile or non-volatile or both).
[0218] Numerical data in system 102; data structures, values, source code, and other examples discussed herein.
[0219] 120 (or more) kernels, such as (multiple) operating systems, BIOS, UEFI, device drivers; also refers to the execution engine, such as the language runtime.
[0220] 122 Software tools, software applications, security controls; computing
[0221] 124 Tenants in a multi-tenant cloud computing environment; a collection of computing resources at a hierarchical level between an individual user and the cloud as a whole.
[0222] A 126-inch display, also known as a "monitor".
[0223] 128 Unless otherwise specified, computing hardware associated with reference numerals 106, 108, 110, 112, and 114 in the accompanying drawings.
[0224] 130 auditing, as it is understood in a computing system; 130 refers to the log that stores audit events 132, and also to computing activities that create, maintain, or analyze such log events.
[0225] 132 Computational events, as indicated in the computational system log.
[0226] 134 User roles, as represented in a computing system
[0227] 136 Cloud, also known as cloud environment or cloud computing environment
[0228] 138. Access policies, as represented in a computing system.
[0229] 202 Enhanced computing system, namely, the enhanced system 102 implemented through the function 204 taught in this paper.
[0230] 204 Secure Cross-Tenant Access Functionality (also known as “SCTA Functionality”), for example, software or dedicated hardware that performs or is configured to perform steps 302 and 602, or steps 304 and 602, or steps 302, 304 and 602, or steps 602 and 604, or steps 602 and 306, or any software or hardware that performs or is configured to perform the novel method 700 disclosed herein for the first time or a computational cross-tenant access security activity, or a computational cross-tenant access activity disclosed herein for the first time.
[0231] 206 refers to ensuring secure access, as well as the security of the characteristics of a computing system and security measures.
[0232] 208 Cross-tenant (also known as "cross-tenant"), which means moving from one tenant (or on behalf of one tenant) to another tenant (or on behalf of another tenant).
[0233] 210. Access to or within a computing system; depending on the context, refers to a computing activity, an instance of a computing activity, or both.
[0234] 212 Focus Tenant 124 in a Cloud Computing Environment
[0235] 214 Secondary tenants in a cloud computing environment 124; In some cases, a given tenant may be a focal tenant in one scenario and a secondary tenant in another.
[0236] 216 The SCTA components in the computing system, such as services 506 and 508, and other software that provides function 204 at runtime, support or implement the data structures (such as 134, 138, 326, 402, 408, 430, 506, and 530) of function 204, and support or implement the processes 524, 526, and 528 of function 204.
[0237] 302 refers to monitoring policy 138, such as through polling, through callbacks or hooks configured on routines to access policy 138, by scanning logs to find events corresponding to policy access, or via the policy management API.
[0238] A 304 error can be calculated by tracking role 134, for example, through polling, through callbacks or hooks configured on routines that access role 134, by scanning logs to find events corresponding to role access, or via the role management API.
[0239] 306 indicates an alert, for example, by sending an email or text message, by modifying the GUI, or by both.
[0240] 308 Authorized computing system access in a given scenario
[0241] 310 refers to obstructing authorized access in a computational sense; identified threats to the scope of authorized access constitute obstruction, as do situations where the scope of authorized access is highly likely to be reduced.
[0242] 312 The case management subsystem of the computing system; also known as the case management system or tool
[0243] In computational terms, 314 refers to correlating events from logs of different tenants, also known as generating correlation audits.
[0244] The 316 computing system's audit correlation subsystem; also known as the audit correlation system or tool.
[0245] 318 Authorized computing system roles in a given scenario 134
[0246] 320 List of authorized roles (not necessarily ordered); numeric
[0247] 322 computationally refers to analyzing role changes or strategy changes, or both, to determine whether hindrance 310 is involved; 322 also refers to the numerical results of such computational activities; in some embodiments, it includes adaptations of hypothesis analysis.
[0248] The 324 computing system's scene analysis subsystem; also known as the scene analysis system or tool.
[0249] The security group data structure in the 326 computing system, also known as a security group.
[0250] 328 typically refers to an interface in a computing system; computational or digital.
[0251] Conditional access policies in 402 computing systems
[0252] The scope of policies in a 404 computing system, such as which activities are allowed or prohibited.
[0253] 406 typically refers to user computational activity; excluding human behavior itself.
[0254] Cross-tenant role assignment in the 408 computing system
[0255] 410 Security Commands in the Computing System
[0256] 412 Commands in the computing system
[0257] 414 Malicious (Unauthorized) Roles 134
[0258] Managed services in 416 computing systems
[0259] Managed service commands in the 418 computing system
[0260] The zero persistence feature of 420 access sessions, compared to persistent access which does not require re-requesting the session on each access.
[0261] 422 Access sessions have a time-limited characteristic, as opposed to permanent or unlimited access sessions that do not automatically terminate after a specified time.
[0262] 424 Zero-duration, or limited-time, or both, access sessions (also known as access).
[0263] 426 Managed device 101, as opposed to unmanaged device; managed device is managed, for example, its contained software, the security controls it is subject to, and its auditing.
[0264] 428 Security Group Granular Delegation of Management Authority Groups (GDAP) Feature
[0265] GDAP or DAP group in the 430 computing system
[0266] 432 Access request; computation activity or data structure
[0267] 436 Access range, as represented in the computing system
[0268] 438. Resources in a computing system, such as hardware, software, and data; excluding biological or conceptual aspects.
[0269] 440 IP address, as represented in a computing system
[0270] 442 A range or other set of one or more IP addresses, as represented in a computing system.
[0271] Changes to strategy 138 or role 134, as represented in the computing system; content modification, priority modification, and content deletion are all examples of changes.
[0272] The addition of strategy 138 or role 134, as represented in the computing system.
[0273] 500 data flow diagram; and Figure 5 Data Flow Figure 1 System architecture
[0274] 502 Calculation error indicates loading of managed services
[0275] 504 error message indicates the creation of a security group.
[0276] 506 directory service, also known as identification service, for example, Active Service (a trademark of Microsoft Corporation) or LDAP (Lightweight Directory Access Protocol) service
[0277] 508AOBO service (i.e., representative action, also known as representative management).
[0278] 510 refers to creating access permission packages or other access permissions, or enabling data structures.
[0279] 512 refers to the establishment of cross-tenant role assignment.
[0280] 514 Access permissions or enable service
[0281] 516 Access request response data structure or computation activity
[0282] 518 refers to adding users to security groups.
[0283] 520 refers to cross-tenant access in the context of exiting a secondary tenant.
[0284] 522 refers to cross-tenant access in the context of exiting the focus tenant.
[0285] 524 Cross-tenant access onboarding phase
[0286] 526 Cross-tenant access focus tenant resource access phase
[0287] 528 Cross-tenant access exit phase
[0288] 530 Access Permission Package or other access permissions or enable data structures
[0289] 600 flowchart; 600 also refers to the cross-tenant access method, which is... Figure 6 Flowchart or the description in this article Figure 6 Any variation of the flowchart shown or consistent with it
[0290] 602 refers to the detection of obstacles 310, or other effects or potential effects of changes or additions to access policies 138 or role assignments 408 in the computing system, such as by detecting the removal or reduction of access tokens, access durations, or access permissions, or by detecting roles 414 that are not in the list of authorized roles 320.
[0291] 604 refers to modifications to access policies (138), role assignments (408), or cross-tenant access scopes (436) and other aspects, such as access duration.
[0292] 700 flowchart; 700 also refers to... Figure 7 The flowchart shows or is related to Figure 7 process Figure 1 A comprehensive cross-tenant access method that combines Figure 5 Data flow diagrams and Figure 6 The flowchart and other steps taught in this article, or by Figure 7 Any variations of the flowchart shown or described herein Figure 7 Consistent approach for any variation of the flowchart
[0293] 702 refers to checking changes or additions to (multiple) access policies 138, such as based on access timestamps, comparisons of historical and current policy hashes, or other mechanisms.
[0294] 704 error code indicates a problem with role assignment, and 408 error code indicates a problem with API.
[0295] 706 calculates the detection of malicious roles not belonging to the list of authorized roles 320 414
[0296] 708 indicates that the command 412 is received, for example via a user interface API or other API.
[0297] 710 refers to the execution of command 412, for example via kernel 120, tool 122, or other software.
[0298] 712 refers to constraints on authorized access, such as denying or terminating access when constraints are not met (e.g., IP address, managed device, or access duration constraints).
[0299] 714 refers to the use of security groups, such as restricting access.
[0300] 716 refers to the use of GDAP groups in computation, such as for constrained access.
[0301] 718 refers to mitigating security vulnerabilities, for example, by reducing the attack surface, repairing damage caused by attacks, adding additional layers of defense against attacks, or closing security gaps.
[0302] 720 in computing refers to investigating security vulnerabilities, such as by analyzing logs or examining vulnerability markers in computing systems.
[0303] 722 refers to receiving access requests, such as via a user interface API or other APIs.
[0304] 724 refers to the activities performed within a tenant's premises.
[0305] 726 refers to improving tenant security, for example, by mitigating the 718 security vulnerability, reducing the attack surface without relying on specific known vulnerabilities, or by increasing authentication requirements for access to tenant resources.
[0306] 728 Any steps or items discussed in this disclosure that are not assigned other reference numerals; therefore, 728 can be clearly shown as reference numerals for various steps or items or both, and reference numerals for various steps or items or both can be added without adding new content (in this disclosure or any subsequent patent application claiming priority to this disclosure).
[0307] in conclusion
[0308] Some embodiments in the cloud computing environment 100 include monitoring changes 444 or additions 446 to conditional access policies 402, which prevent or risk preventing authorized access 308 from secondary tenant 214 users to resources of the focus tenant 212. In some embodiments, cross-tenant access security 700 includes tracking a role assignment list 320 to detect 706 malicious roles 414, or to detect 602 preventing role changes 444 (such as role deletion), or both. In some embodiments, focus tenant events 132 and secondary tenant events 132 are correlated in an audit 130. In some embodiments, authorized access 308 is zero-duration, time-limited access 424. In some embodiments, authorized access 308 is constrained 712 to an IP address range 442, or constrained 712 to login from a managed device 426, or both. In short, security measures 206, 216, 500, and 700 are described that mitigate the risk of unintended or covert role or policy changes that could disrupt or impede authorized cross-tenant access to 308.
[0309] The embodiments are understood to include or benefit from testing and appropriate security and privacy controls, such as the General Data Protection Regulation (GDPR). The use of the tools and techniques taught herein is compatible with the use of such controls.
[0310] While some of the heuristic examples use Microsoft technologies, the teachings herein are not limited to use in technologies provided or managed by Microsoft. For example, with appropriate licensing, these teachings may be implemented in software or services provided by other cloud service providers.
[0311] While specific embodiments are explicitly shown and described herein as processes, configured storage media, or systems, it should be understood that the discussion of one type of embodiment generally extends to other types of embodiments. For example, the description of a process in conjunction with the accompanying drawings also helps to describe a configured storage medium, and helps to describe the technical effects and operation of systems and manufacturers as discussed in conjunction with other drawings. No limitation from one embodiment must be followed when reading into another embodiment. Specifically, processes are not necessarily limited to the data structures and arrangements presented when discussing systems or manufacturers such as configured memory.
[0312] Those skilled in the art will understand that implementation details may involve specific code, such as specific thresholds, comparisons, specific types of platforms or programming languages or architectures, specific scripts or other tasks, and specific computing environments, and therefore do not need to appear in every embodiment. Those skilled in the art will also understand that program identifiers and some other terms used in discussing details are implementation-specific and therefore do not need to be addressed in every embodiment. Nevertheless, while they are not necessarily required here, such details can assist some readers by providing context and / or illustrating some of the many possible implementations of the techniques discussed herein.
[0313] By taking due attention to the technical processes, effects, mechanisms, and details provided herein (which are illustrative and not exhaustive of all claimed or claimable embodiments), those skilled in the art will understand that this disclosure and the embodiments described herein do not relate to subjects outside the technical field, nor to any ideas of their own, such as principal or original causes or motivations, or results alone, or thought processes or steps, or business methods or general economic practices, or merely methods of organizing human activities, or laws of nature themselves, or naturally occurring things or processes, or organisms or parts thereof, or mathematical formulas themselves, or isolated software themselves, or merely conventional computers, or any completely imperceptible or abstract concept itself, or irrelevant post-solution activities, or any method implemented entirely on an unspecified device, or any method that fails to produce useful and concrete results, or any preemption of all fields of use, or any other subject matter unsuitable for patent protection under the laws of the jurisdiction where such protection is sought, licensed, or enforced.
[0314] References herein to embodiments having some feature X, and references elsewhere herein to embodiments having some feature Y, do not exclude embodiments having both feature X and feature Y, unless such exclusion is expressly stated herein. All possible negative claim limitations are within the scope of this disclosure, and in a sense, any feature stated as part of an embodiment may be explicitly removed from inclusion in another embodiment, even if no specific exclusion is given in any example herein. In this document, the term “embodiment” is used only in the more convenient form: “process, system, article of manufacture, configured computer-readable storage medium, and / or other examples of the application of the teachings herein, subject to applicable law.” Therefore, a given “embodiment” may include any combination of features disclosed herein, provided that the embodiment is consistent with at least one claim.
[0315] Not every item shown in the figures needs to be present in every embodiment. Instead, embodiments may include items not explicitly shown in the figures. While some possibilities are illustrated herein by means of specific examples in text and figures, embodiments may deviate from these examples. For example, specific technical effects or features of the examples may be omitted, renamed, grouped differently, repeated, instantiated differently in hardware and / or software, or a mixture of effects or features appearing in two or more examples. In some embodiments, functionality shown in one location may also be provided in different locations; those skilled in the art will recognize that functional modules can be defined in various ways in a given implementation without omitting desired technical effects from the set of interactive modules viewed as a whole. Different steps may be shown together in a single box in the figures due to space constraints or for convenience, but are still individually executable; for example, one may be performed in a given execution of the method without the other.
[0316] The accompanying drawings have been referenced by reference numerals. Any apparent inconsistency in wording associated with a given reference numeral in the drawings or text should be understood as simply broadening the scope referenced by that reference numeral. Even when using the same reference numeral, different instances of a given reference numeral may refer to different embodiments. Similarly, a given reference numeral may be used to refer to verbs, nouns, and / or corresponding instances of each processor 110, for example, by which processor 110 can process 110 instructions.
[0317] As used herein, terms such as “a,” “an,” and “the” include one or more of the indicated items or steps. In particular, in the claims, a reference to an item generally means that there is at least one such item, and a reference to a step means that at least one instance of performing that step. Similarly, “is” and other singular verb forms should be understood to cover the possibility of “are” and other plural forms, where the context allows, to avoid grammatical errors or misunderstandings.
[0318] The title is merely for convenience; information about a given topic can be found outside the section whose title indicates that topic.
[0319] All claims and abstracts submitted are part of the specification. The abstract is provided for convenience and compliance with patent office requirements; it is not a substitute for the claims and does not control the interpretation of the claims in the event of any apparent conflict with the rest of the specification. Similarly, the content of this invention is provided for convenience and is not subject to any conflict with the claims or the rest of the specification. The claims should be interpreted in light of the specification as understood by those skilled in the art; it is not necessary to record every minute detail within the claims themselves, just as no other disclosure is provided herein.
[0320] With regard to any terminology used herein that implies or otherwise refers to an industry standard, and with regard to applicable law requiring the identification of a particular version of such a standard, this disclosure shall be understood to refer to the latest version of that standard that has been published under applicable patent law from the earliest priority date of this disclosure in at least draft form (or, if more recent, final form).
[0321] Although exemplary embodiments have been shown in the accompanying drawings and described above, it will be apparent to those skilled in the art that many modifications can be made without departing from the principles and concepts set forth in the claims, and such modifications need not encompass the entire abstract concept. Although the subject matter has been described in language specific to structural features and / or process actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific technical features or actions described in the preceding claims. Each means or aspect or technical effect identified in a given definition or example need not be present or utilized in every embodiment. Rather, the specific features and actions and effects described are disclosed as examples to be considered in implementing the claims.
[0322] All changes that fall outside the scope of the abstract idea but fall within the meaning and scope of the equivalents of the claims should be covered to the extent permitted by law.
Claims
1. A network security method (700) for secure cross-tenant access (210), the method comprising: The monitoring (302) includes checking (702) the non-obstruction conditional access policy (402) of the focus tenant (212), the monitoring including checking (702) the obstruction change (444) in the non-obstruction conditional access policy, the monitoring also including checking (702) the addition (446) of the obstruction conditional access policy, wherein the obstruction change is a change that obstructs (310) authorized access from the secondary tenant (214) to the focus tenant, and the obstruction conditional access policy is a conditional access policy that obstructs the authorized access from the secondary tenant to the focus tenant; Track (304) the cross-tenant role assignment of the focus tenant (408), the tracking including examining (704) the cross-tenant role assignment in response to changes in the cross-tenant role assignment; Detect (602) at least one of the following: the obstruction change in the non-obstruction access policy, the addition of the obstruction access policy, or the change in the cross-tenant role assignment; as well as In response to the result of the detection, modify (604) at least one of the following: the non-obstructive access policy, the obstructive access policy, the cross-tenant role assignment, or the scope of authorized access from the secondary tenant to the focus tenant (436).
2. The method according to claim 1, further comprising: The focus tenant audit (130) is associated with the secondary tenant audit (130) (314), thereby generating (314) an association audit (130) of the user’s activities (406) in the focus tenant and the user’s activities (406) in the secondary tenant.
3. The method according to claim 1 or 2, further comprising: The user receives (708) a command (412) in the focus tenant, wherein the command belongs to at least one of the following command categories: security investigation command (410), security modification command (410), or managed service command (418).
4. The method according to claim 1, 2 or 3, wherein monitoring (302) of the non-obstructive access policy (402) includes performing scenario analysis (322).
5. The method according to any one of claims 1 to 4, wherein tracking (304) the cross-tenant role assignment includes detecting (706) malicious roles (414).
6. The method according to any one of claims 1 to 5, further comprising: Access (422) will be granted from the auxiliary tenant when the authorized access (308) constraint (712) on the focus tenant is zero for a limited period of time (420).
7. The method according to any one of claims 1 to 6, further comprising: The authorized access (308) of the auxiliary tenant to the focus tenant will be restricted (712) to access only via login from an authorized managed device (426).
8. The method according to any one of claims 1 to 7, further comprising: The authorized access (308) of the auxiliary tenant to the focus tenant will be restricted (712) to access only via login from a specific IP address range (442).
9. The method according to any one of claims 1 to 8, further comprising: At least use (716) granular delegation management authority group (430) to define (716) the cross-tenant role assignment in the focus tenant.
10. A computing system (202) configured for secure cross-tenant access, the system comprising: Digital memory (112); A processor set, including at least one processor (110), the processor set being in operative communication with the digital memory, the processor set being configured to execute a secure cross-tenant access method (700), the secure cross-tenant access method (700) including at least one of the following: Detect (602) a conditional access policy blocking change (444) and issue an alert (306) in response to the detection of the conditional access policy blocking change. Detect (602) the addition of a barrier access policy (446) and issue an alert (306) in response to the detection of the addition of the barrier access policy, or Detect (602) a cross-tenant role assignment obstruction change (444) and issue an alert (306) in response to the detection of the cross-tenant role assignment obstruction change. The conditional access policy that prevents changes is one that prevents (310) from changing authorized access (308) from the secondary tenant (214) to the focus tenant (212). The addition of the blocking conditional access policy is the addition of a conditional access policy that blocks (310) the authorized access (308) from the secondary tenant to the focus tenant, and The cross-tenant role assignment obstruction change is an obstruction (310) of the change of the authorized access (308) from the auxiliary tenant to the focus tenant.
11. The computing system according to claim 10, further comprising: A case management subsystem (312) exists in the auxiliary tenant and includes an interface (328) configured to receive (722) a request (432) for authorized access to the focus tenant.
12. The computing system according to claim 10 or 11, further comprising: An audit association subsystem (316) is configured to associate, at execution, the authorized access secondary tenant request (432) for the focus tenant with the focus tenant login event (132) and the focus tenant resource (438) access event (132) (314).
13. The computing system according to claim 10, 11 or 12, wherein a list (320) of authorized roles (318) exists in the digital memory, and wherein the detection (602) of cross-tenant role assignment blocking change (444) includes the detection (706) of abnormal roles (414) that are not part of the access control list of authorized roles.
14. The computing system according to any one of claims 10 to 13, further comprising: Security group (326), which exists in the secondary tenant and corresponds to the non-obstructive cross-tenant role assignment in the focus tenant.
15. The computing system according to any one of claims 10 to 14, further comprising: A scenario analysis subsystem (324) is configured to perform scenario analysis (322) at execution, based at least on the scope of the conditional access policy (404) and the scope of authorized access (436) of the authorized access (308) to the focus tenant.
16. A computer-readable storage device (112, 114) configured with data and instructions, which, when executed by a processor (110), cause a computing system (202) to perform a secure cross-tenant access method (700), the method comprising at least one of the following: An alert (306) is issued in response to the detection (602) of a conditional access policy (402) preventing a change (444). An alert (306) is issued in response to the detection (602) of adding (446) to the access restriction policy (402), or An alert (306) is issued in response to the detection (602) of a cross-tenant role assignment (408) hindering a change (444). The conditional access policy that prevents changes is one that prevents (310) from changing authorized access (308) from the secondary tenant (214) to the focus tenant (212). The addition of the blocking conditional access policy is the addition of a conditional access policy that blocks (310) from the secondary tenant (214) to the focus tenant (212) for the authorized access (308), and The cross-tenant role assignment obstruction change is an obstruction (310) of the authorized access (308) from the auxiliary tenant (214) to the focus tenant (212).
17. The computer-readable storage device of claim 16, wherein the method further comprises: The focus tenant audit is associated with the secondary tenant audit (314), thereby generating (314) an associated audit (130) of the user’s activities (406) in the focus tenant and the user’s activities (406) in the secondary tenant.
18. The computer-readable storage device of claim 16 or 17, wherein the method further comprises: The authorized access constraint (712) from the auxiliary tenant to the focus tenant will be a zero-duration (420) limited-time (422) access (424) via login from an authorized managed device (426).
19. The computer-readable storage device according to claim 16, 17 or 18, wherein the method further comprises: The authorized access constraint (712) from the auxiliary tenant to the focus tenant will be a zero-duration (420) limited-time (422) access (424) via login from a specific IP address range (442).
20. The computer-readable storage device according to any one of claims 16 to 19, wherein the method further comprises: The authorized access constraint (712) on the focus tenant from the auxiliary tenant will be restricted to access only via login from an authorized managed device (426) and from a specific IP address range (442).