SYSTEM AND METHOD FOR DUAL ENDPOINT ACCESS CONTROL OF REMOTE CLOUD STORED RESOURCES - Patent application
The dual-endpoint access control system addresses the challenge of managing complex cloud storage security by enforcing local host policies and encrypting data, enhancing security and preventing leaks while maintaining user control and efficiency.
Patent Information
- Application Number
- JP2024537790
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-08-27
- Filing Date
- 2022-08-24
- Publication Date
- 2025-09-25
- Estimated Expiration
- 2042-08-24
AI Technical Summary
Current cloud storage systems lack effective mechanisms for granular access control and data security, leading to misconfiguration risks and potential data leaks, as users struggle to manage complex security policies across various cloud service providers.
A dual-endpoint access control system that enforces local host management of cloud storage security, using a local host interface to intercept and enforce access policies, encrypt data, and authenticate user accounts, thereby offloading access control from the cloud end to the local host end.
This system enhances data privacy and security by preventing unauthorized access and data leaks, while maintaining user familiarity and control over local applications and objects, ensuring secure and efficient access control across multiple cloud service providers.
Smart Images

Figure 0007744522000001 
Figure 0007744522000002
Abstract
Description
[Technical Field]
[0001] The present invention relates to the technical field of access control to remote cloud-storage resources, and in particular to dual-endpoint (and concurrent) access control. In particular, the present invention allows for externalizing policy management and access control of cloud-storage resources or objects. [Background technology]
[0002] Cloud computing is changing the way corporations, government agencies, and small businesses manage their internal data. Because cloud servers enable an agile and cost-effective way to run business-critical applications and store information, businesses are migrating from traditional on-premise data centers to cloud servers for storing and managing their digital assets.
[0003] Cloud computing, or simply "the cloud," is the on-demand availability of computer system resources, particularly data storage and computing power, without direct, active management by the client or end user.
[0004] The increasing demand for cloud services has led to the emergence of various cloud service providers, such as Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure (Azure), OVHclod, or Alibaba Cloud, etc. Each of these service providers offers its own security policies, mechanisms, and configuration processes that can flexibly restrict access to cloud-stored assets, resulting in a lack of capabilities for users.
[0005] Furthermore, while it provides the possibility to restrict access as needed, the actual responsibility for protecting the confidentiality, integrity, and availability of data in cloud storage is pushed to the user. The need to select role policies and other technicalities among various buckets / specific objects can pose a tedious and extremely difficult task for the average user, leading to mistakes in misconfiguring bucket access policies and potential leak risks.
[0006] Regular data breaches in the news demonstrate that cloud storage is easy to deploy and use, but difficult to secure.
[0007] Thus, while easily configurable cloud service security policies can introduce simple and ineffective functional, organizational, or hierarchical barriers (ultimately making it difficult to use the cloud service on a day-to-day basis because users who need access to certain resources lack the necessary permissions), complex ones are still vulnerable to misconfiguration.
[0008] In conclusion, there is a need in the cloud-related industry to facilitate the configuration of access control policies while further protecting assets from data leakage. Summary of the Invention
[0009] The present invention provides a solution to the aforementioned problems by a system and method for dual-endpoint access control of remote cloud-storage resources as set out in claims 1 and 13, respectively, and a local host interface as set out in claim 15. The dependent claims define preferred embodiments of the invention.
[0010] In a first inventive aspect, the present invention provides a system for dual-endpoint access control of remote cloud-storage resources, comprising: at least one end-user entity operating at least one application adapted to perform at least one operation on at least one cloud-stored resource; a local host interface configured to control access to a remote cloud-storage resource over a communications network by at least one end-user entity operating at least one application, a first access policy associating a set of permitted operations including at least one access permission to one or more of the cloud stored resources; a local host interface configured to transmit, when an authorized user requests to perform at least one permitted operation on at least one authorized cloud storage resource that satisfies the access permissions set in the first access policy, an individual access request via the communication network to at least one remote server storing the cloud storage resource; At least one remote server that stores cloud storage resources; and a cloud interface associated with at least one remote server, At least one role policy that allows or denies the execution of at least one operation on at least one cloud-storage resource; and an authenticatable user account that is configured to assume at least one of the roles and that is capable of being authenticated through a received individual access request sent by the local host interface; A cloud interface that includes a second access policy consisting of To provide a system comprising:
[0011] In other words, dual-endpoint access control locally enforces access control of remote cloud-stored resources. Additional mapping of local users, local applications, and cloud-stored resources (e.g., individual object specifiers) to remote cloud access controls then enables locally enforced access control of remote cloud objects. Note that AWS defines a resource as an object, while Microsoft Azure uses "blob." Throughout this document, the terms resource, blob, or object are considered synonymous.
[0012] The present invention protects remote data on cloud storage by enabling local (host-end) management of the security of cloud-stored resources while maintaining familiarity and control over local users, application processes, and objects.
[0013] The present invention also provides a unified platform for configuring data policies across various cloud service providers to enable offloading of access policies from the cloud end to the local host end.
[0014] Current solutions based on intermediate architectures between an organization's on-premise infrastructure and the cloud provider's infrastructure, such as cloud access security brokers (so-called CASBs), are unable to perform granular access control functions at the local host end, i.e., they lack the ability to protect application operations or processes and target resources.
[0015] Apart from this process context awareness, which can be achieved by locally implementing the local host interface, because it occurs within the security boundary of the CSP's customer, there is no need to send requests outward, which run the risk of being intercepted and analyzed and ultimately fail if the requesting end user account is not authorized to access the cloud-stored resource. Thus, the present invention also improves data privacy. In this invention, an operation or process is an executing instance of a computer program launched by a computer user account that performs computations and input / output operations such as reading data from or writing data to a disk.
[0016] In accordance with the present invention, the term "user" may be understood as "user account" since different people may use the same "end user entity" or computer system and therefore each person would have associated a user account on the end user entity operating system, application, or both according to the present invention.
[0017] An end-user entity, e.g., a computer, runs an application adapted to perform at least one process or operation on at least one cloud-storage resource. Examples of this application may be a web-based portal, an open-source application, or a specific application for downloading cloud-storage resources to a backup database. Examples of operations, on the other hand, may be read, write, delete, list, update, and aggregation processes.
[0018] In fact, these operations may be supported or executable on a single (or a group of) cloud storage resources. Throughout this document, a group of cloud storage resources will be referred to as a "bucket." Furthermore, buckets that have been assigned to specific roles to restrict access to their contents will be referred to as "protected buckets."
[0019] Thus, an end user entity is a user who is logged into an operating system (and / or application) and initiates a particular operation using their user account through the application.
[0020] The system also provides a local host interface on the host side configured to control access to the remote cloud storage resource over the communication network by at least one end user entity running at least one application. This local host interface may be embodied as an access control processing engine that intercepts requests for access to the cloud bucket. In a preferred embodiment, the local host interface is a secure, hardened (i.e., single-function) Transport Layer Security (TLS) proxy configured to intercept Hypertext Transfer Protocol Secure (HTTPS) traffic originating from the end user entity and addressed to at least the cloud server, and vice versa.
[0021] The local host interface further includes a first access policy that associates a set of permitted operations, including at least one access permission, to one or more of the cloud storage resources, the first access policy being a set of user- or client-established rules to be followed to enable selective access to the cloud storage resources.
[0022] Non-exhaustive examples of these permissions include: - an end user entity identifier that refers to an end user entity that runs at least one application; a user session identifier that refers to a session-related group of one or more user identification numbers that log on to an application or end-user entity and perform an operation on at least one application; - an identification number of the operation of at least one application executed on the end user entity; - an identification number of at least one cloud-stored resource to which access is requested; and - a predetermined time window or date within which the access request is received is.
[0023] In a preferred embodiment, access permissions for an operation are not based on an ID (such as a number identifier given by the end user entity operating system), but rather are defined by its file path (e.g., location such as / usr / bin / myapp) and, optionally, the application's code signature (e.g., a hash value such as the output of a SHA-256 algorithm), since the local host interface may be embodied as software that is preferably installed in the operating file system or device layer (e.g., the end user entity layer, virtual machine layer, or token layer), so that its operations are transparent to all applications running on it.
[0024] The local host interface extracts relevant information from the intercepted operation request, such as a local user identification number and / or a file path identifying an application, and compares it with the access permissions of the first access policy to grant or deny access to a single or collective cloud storage resource.
[0025] Note that when requesting an operation on a resource or set of resources stored in an unprotected bucket (i.e., not listed in the first or second access policy), access is always granted by the localhost interface, which simply passes the request through.
[0026] Only when an authorized user requests to perform a whitelisted operation on at least one authorized cloud storage resource and meets the permissions set in the first access policy will the local host interface send an individual access request via one or more application program interfaces (APIs) using HTTPS over TLS.
[0027] Finally, the local host interface may also encrypt data before sending it to the server side and / or decrypt data received from the server side. In other words, in a preferred embodiment, the local host interface may perform encryption of data at rest.
[0028] On the server side, the system provides a remote server storing cloud-stored resources further associated with a cloud interface that includes a second access policy, which was previously implemented on the server side by the cloud service provider, and which now includes at least one role policy and a user account.
[0029] A role policy is a set of permissions assigned to a particular entity, such as a user, application, or service, to grant access to system resources. Thus, the role policy of the second access policy allows or denies execution of a requested operation on at least one cloud-storage resource. Meanwhile, the second access policy includes a user account that can be authenticated through a received individual access request sent by a local host interface.
[0030] In certain embodiments, the application (via the end user entity) is configured to receive login credentials that authenticate the user account for the second access policy along with a selection or indication of the cloud-based resource to which access is requested. Accordingly, the application (or the end user entity itself) is configured to forward the login credentials and the target resource to a local host interface that is further configured to derive one or more user identifiers to enforce the first access policy.
[0031] In particular embodiments, the individual access request may be formed according to the specific login credentials received by the application from the user. Alternatively, the user account may be a "generic user account" that is not specific to a particular user, but rather to a group of users, in which case the generic user account can be authenticated solely by the details of the individual access request.
[0032] Once authenticated, the user account assumes at least one of the roles, and each access request will therefore transmit the access key / private key pair of the user account that has the trust relationship associated with the role.
[0033] In a preferred embodiment, at least one role policy is a wide open access policy configured to permit execution of all permissible operations on a single or group of cloud-storage resources.
[0034] Advantageously, access control and management applied to cloud stores (e.g., AWS S3 buckets) is now completely offloaded onto the local host. With this embodiment, all access control to protected buckets is determined entirely via security policies based on local host users, application processes, resources, etc., with permissible actions such as read, write, and list now mapping perfectly to protected bucket operations.
[0035] In this preferred embodiment, the local host interface already has (e.g., stores) the credentials to authenticate the user account (e.g., a generic user account) of the second access policy and the keys necessary to assume the role.
[0036] Advantageously, accidental or intentional dumping of cloud-stored objects into the protected bucket by an unauthorized local user who knows the authentication credentials of the second access policy is completely prevented.
[0037] Also, even if a user knows the specific credentials to authenticate the end-user account of the second access policy and also knows the key to assume the role, if the localhost interface has already encrypted the credentials stored in the cloud in the protected bucket (i.e., performed the encryption of data at rest), then the object will remain encrypted and will be leaked, since the decryption key is managed by the localhost interface, thus avoiding unauthorized access to this stored information.
[0038] In a second aspect of the present invention, the present invention provides a method for dual-endpoint access control of a remote cloud-storage resource, comprising: receiving, by at least one application running on an end user entity, a request to perform at least one operation on at least one cloud-stored resource; at least one application sending an operation request that is intercepted by a local host interface; the local host interface deriving one or more identifiers that reference the context of the operation request; the local host interface enforcing access control by a first access policy that associates a set of permitted operations, including at least one access permission to one or more of the cloud-stored resources; - when the local host interface requests that an authorized user perform at least one permitted operation on at least one authorized cloud storage resource that satisfies the permissions set in the first access policy, sending an individual access request via the communication network to at least one remote server storing the cloud storage resource; receiving a cloud interface associated with at least one remote server storing cloud-stored resources from the cloud; authenticating the user account of the second access policy using a separate access request; and The authenticated user account assumes at least one role of at least one role policy that allows or denies execution of an operation on the cloud-storage resource according to the second access policy. The present invention provides a method comprising:
[0039] In certain embodiments, the method further comprises: The application receives, together with a request to perform at least one operation on at least one cloud-storage resource, login credentials that authenticate a pre-registered user account of the second access policy; or The local host interface obtains login credentials for authenticating a pre-registered user account of the second access policy and / or a key for the user account to assume a role. Includes:
[0040] In a third aspect of the present invention, the present invention provides a local host interface for controlling access to a remote cloud storage resource over a communications network by at least one end user entity operating at least one application adapted to perform at least one operation on at least one cloud storage resource, the local host interface comprising: the local host interface includes a first access policy that associates a set of allowed operations including at least one access permission to one or more of the cloud stored resources; a local host interface configured to intercept operation requests sent by the at least one application; The local host interface is configured to transmit, via the communication network to at least one remote server storing the cloud storage resource, an individual access request configured to authenticate the user account of the second access policy at the cloud end when the authorized user requests to perform at least one permitted operation on at least one authorized cloud storage resource that satisfies the access permissions set in the first access policy. Provides a local host interface.
[0041] All features described in this specification (including the claims, description and drawings) and / or all steps of the methods described may be combined in any combination, except for such mutually exclusive combinations of features and / or steps. [Brief explanation of the drawings]
[0042] These and other features and advantages of the present invention will be clearly understood from a consideration of the following detailed description of the invention, which refers to the drawings and is made clear from preferred embodiments of the invention, given by way of example only and not by way of limitation.
[0043] [Figure 1]1 illustrates an embodiment of a system according to the present invention. [Figure 2] FIG. 2 illustrates a detailed embodiment of the local host end of the system according to the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0044] As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as either methods or systems.
[0045] In the following, we consider the case where the system for dual-endpoint access control of remote cloud-stored resources is implemented by a PC, which is a standalone end-user entity interfacing with a local host interface on the user or client side, and a remote server interfacing with a cloud interface on the remote server side. In a further embodiment, the end-user entity interfacing with the local host interface is embodied as a virtual machine.
[0046] According to another embodiment (not shown), either the end user entity or the remote server may be implemented by a PC that is a Secure Element (SE) host device in conjunction with a Trusted Execution Environment (TEE) that is adapted to perform the functions performed by the end user entity and described below by adding a secure execution environment to the TEE.
[0047] According to another embodiment (not shown), either the end user entity or the remote server may be implemented by a (mobile) phone that is an SE host device in conjunction with an SE chip that is adapted to perform the functions performed by the end user entity or the remote server and described below by adding secure data storage and secure data processing to the SE chip. This SE chip may comprise an embedded chip, such as an embedded universal integrated circuit card (i.e., eUlCC) or an integrated universal integrated circuit card (i.e., iUICC), within the terminal that is the SE host device, or a chip included in a smart card (or other medium) communicatively connected to the terminal that is the SE host device. This SE chip may also be fixed to its host device or removable from the host device. A removable SE may be a subscriber identity module (i.e., SIM) type card, a secure removable module (i.e., SRM), a USB (an acronym for "universal serial bus") type smart dongle, a (micro)secure digital (i.e., SD) type card, a multimedia type card (i.e., MMC), or any format card that connects to the host device.
[0048] The present invention does not impose any restrictions on the type of end-user entity or remote server type.
[0049] Figure 1 shows a schematic diagram of a system for dual-endpoint access control of remote cloud-storage resources. In its basic configuration, the system includes one or more end-user entities, namely, one or more PCs 1, a local host interface 2, and a cloud-storage resource 3. A , 3 B , 3 C and a cloud interface 4.
[0050] For illustrative purposes, the end user entity 1 and the local host interface 2 are shown together within the same execution platform 10. However, the remaining execution platforms 10', 10", 10'" are understood to include only the elements described below for the end user entity 1, and not the elements of the local host interface 2 described in FIG. 2. Thus, the execution platform 10 is also a PC with a software-type local host interface 2, since the local host interface 2 may be any software running within the end user entity 1 (e.g., a PC). In certain embodiments, this software-type local host interface 2 is deployed or installed during a setup process that may include configuring permissions for a first access policy.
[0051] According to the present invention, the local host interface 2 is installed within the security boundary of the end user entity, ie deployed at the local end.
[0052] PC1 is configured to receive at least login credentials for at least one of the end user accounts from user 100, validate them, and allow the user to run applications and / or initiate various processes described below. The user may also introduce login credentials (authentication credentials) via PC1 to authenticate the user account for a second access policy of the cloud service provider.
[0053] Because the same user 100 may have one or more accounts (i.e., end-user accounts) each containing their own credentials, FIG. 1 illustrates different end-user accounts 100, each associated with a user account either on an end-user entity operating system, on an application, or both, in accordance with the present invention. A ~100 F This shows:
[0054] The PC 1 comprises one or more (micro)processors (and / or (micro)controllers) 1.1 which are data processing means, which in turn comprise and / or are connected to one or more memories 1.2 which are data storage means, which comprise or are connected to means for interfacing with a user 100, such as a man-machine interface (or MMI), and which comprise or are connected to input / output (or I / O) interfaces 1.3, all interconnected via an internal bidirectional data bus.
[0055] The I / O interface 1.3 may include wired and / or wireless interfaces for interacting with the user 100 via contact and / or contactless (i.e., CTL) links. In this description, the adjective "CTL" indicates, among other things, that the communication means communicates via one or more short-range (i.e., SR) type radio frequency (i.e., RF) links.
[0056] The SR type RF link may relate to any CTL technology that enables the PC 1 to locally exchange data with the user 100 over a CTL type link. The CTL link, if present, may include a Bluetooth (i.e., BTH), Bluetooth Low Energy (i.e., BLE), Wi-Fi, ZigBee, Near Field Communication (i.e., NFC) type link, and / or other SR type RF communication technology link.
[0057] Alternatively, or in addition to the CTL link, PC1 is connected via a wire or cable (not shown) to another end-user terminal or device (not shown) that is also operated by user 100.
[0058] The PC MMI may include a display screen, a keyboard, a speaker, and / or a camera (not shown). The PC MMI allows the user 100 to interact with the PC 1. The PC MMI may be used to obtain data entered and / or provided by the user 100, such as user authentication data and PC operating system login credentials, such as a username, password, PIN, and / or the user's biometric data (e.g., fingerprint, face print, and / or iris print). The user may also enter user account credentials for a second access policy via the PC MMI.
[0059] PC Memory 1.2 may include one or more volatile memories and / or one or more non-volatile memories. PC Memory 1.2 may store, for example, user identities such as first name and / or last name for User 100, and identities associated with each authenticated user such as International Mobile Equipment Identity (i.e., IMEI), Mobile Subscriber Integrated Services Digital Network Number (i.e., MSISDN), Internet Protocol (i.e., IP) address, International Mobile Subscriber Identity (i.e., IMSI), Medium Access Control (i.e., MAC) address, email address, etc.
[0060] The PC memory 1.2 may store data such as an ID associated with the PC that allows the PC to be uniquely identified and addressed. The PC ID may include a unique ID such as a UUID, a uniform resource locator (i.e., URL), a uniform resource identifier (i.e., URI), and / or other data that allows the PC to be uniquely identified and addressed.
[0061] The PC memory 1.2 stores an operating system (OS) and an application adapted to perform at least one process or operation on at least one cloud-storage resource, such as a web-based portal (e.g., the Amazon Web Services (AWS) Management Console), an open-source application (e.g., the AWS Command Line Interface), or an application for downloading cloud-storage resources to a backup database.
[0062] The PC1, alone or together with the execution platform 10, is further configured to transmit information to the cloud end via a communication network (eg, Transport Layer Security, TLS).
[0063] The local host interface 2 is configured to intercept information transmitted by the PC1 and control access to the remote cloud storage resources by enforcing a first access policy that associates a set of permitted operations including at least one access permission to one or more of the cloud storage resources.
[0064] If the requested operation is whitelisted, i.e., an authorized user requests to perform at least one permitted operation on at least one authorized cloud storage resource and satisfies the access permissions set in the first access policy, the local host interface creates and sends an individual access request to the cloud end, i.e., a remote server storing the cloud storage resource.
[0065] The local host interface 2 may also receive credentials from the end user entity 1 (and thus from the user) for authenticating the user account of the second access policy. In a preferred example further described in connection with Figure 2, the local host interface indeed contains the credentials for authenticating the user account of the second access policy and the keys necessary to assume the role. However, before forwarding the operation request to the cloud end by a separate access request, the application may require the user to input credentials for authenticating the user account of the second access policy, which will be compared (and therefore verified) with those stored in the local host interface.
[0066] In an alternative embodiment, the local host interface stores only the access key and secret key pair for the user account to assume the role. Therefore, the user may introduce credentials to authenticate the second access policy user account that will be used to create the individual access request. Therefore, if these credentials are entered incorrectly, the second access policy will reject the operation request.
[0067] As mentioned above, at the cloud end, the system creates multiple buckets. A ~3 C The bucket 3 includes a remote server (not shown) that stores the buckets 3 and a cloud interface 4. A ~3 C Each of the buckets may contain a single or a group of cloud-stored resources (e.g., objects) on which supported operations or processes may be performed by applications according to the present invention. A is shown as a "protected bucket" because it has been assigned to a specific role in the local host interface's first access policy to restrict access to its contents. B , 3 C is an unprotected bucket.
[0068] In a preferred embodiment, the cloud storage resource is a Simple Storage Service (S3) bucket object, and a collection of resources references some or all of the bucket object.
[0069] In one embodiment, the cloud interface 4 is a bucket 3 A ~3 C The cloud interface may channelize all requests received at the cloud end to enforce the second access policy. The cloud interface 4 then: At least one role policy that allows or denies execution of at least one operation on at least one cloud-storage resource; and -An authenticatable user account configured to assume at least one of the roles and a database 4.1 storing a second access policy consisting of:
[0070] And in a preferred embodiment, the role policy is an AWS Identity and Access Management (IAM) role policy that includes an attached AWS IAM role. Finally, the user account is preferably an AWS IAM user. In any event, those skilled in the art should recognize that role policies and user accounts may be named differently depending on the particular cloud service provider.
[0071] Therefore, the cloud interface 4 receives the individual access request sent by the local host interface 2 and assigns the access to the specific bucket 3 based on the second access policy rule. A ~3 C Even if the cloud interface 4 is depicted,
[0072] In use, a user uses his PC1 to access bucket 3.A ~3 C Invokes a specific process or operation, such as read, write, delete, list, update, or aggregate, on a single or group of cloud-stored resources.
[0073] User 100 D ~100 F However, the execution platform 10'-10''' does not have a local host interface 2, and the target bucket 3 B , 3 C Alternatively, if a particular cloud storage resource is not protected, bucket operations shall be permitted.
[0074] Instead, the target cloud storage resource or bucket 3 A An access request sent from one of the execution platforms 10'-10''' shall be denied if the second access policy is protected by the first access policy. This may happen because the local host interface 2 stores the user account credentials and / or keys required to assume the role of the second access policy. Therefore, if the requested operation is not first channeled through the local host interface, there is no option to obtain the authentication credentials for the second access policy.
[0075] Alternatively, the user account credentials and / or keys required to assume the role of the second access policy may be stored in the user 100's D ~100 F It may also be entered by the end user entity 1. However, as encryption of data at rest is common, it may be entered by the protected bucket 3. A Cloud-stored resources retrieved from may not be decrypted unless they pass through the original local host interface 2 that stores and manages the keys.
[0076] Another use case is when an operation request is sent from the execution platform 10, i.e. an operation request initially sent by the end user entity 1, -Does the user have permission to invoke the operation? -Is the target cloud storage resource or bucket protected? -Does the user have permission to invoke such an operation in the context of a date, time window, file path, etc.? This is the case when the ipsec_ip_address is trapped by the local host interface where various access checks such as
[0077] If all are "yes," access is granted; otherwise, access to the cloud-stored resource is denied.
[0078] Granting access to a cloud storage resource, or bucket, means that a user can read objects from the bucket, write objects to the bucket, enumerate bucket objects, create directories, and delete directories from the bucket through a process.
[0079] In one embodiment, when a user attempts to write data to a bucket, the data is first encrypted by the local host interface and then written to the protected bucket. Conversely, when a user attempts to read from the bucket, the data is retrieved and first decrypted by the local host interface before being provided to the user (perhaps through an application). Advantageously, no cleartext data is transferred over the wire at any time.
[0080] FIG. 2 shows a detailed, separated view of the execution platform 10 of FIG. 1, which is formed by an end-user entity 1 (eg, a computer or PC) and a local host interface 2 .
[0081] The end user entity 1 is preferably configured to send operation requests using HTTPS over a TLS two-way communication network, with the local host interface 2 being a secure, hardened TLS proxy configured to intercept this HTTPS traffic originating from the end user entity and destined for at least the cloud server, and vice versa.
[0082] Finally, the local host interface 2 may send individual access requests to the cloud server via one or more application program interfaces (APIs) using HTTPS over TLS. Additionally or alternatively, individual access requests may be sent to an enterprise HTTPS proxy.
[0083] The local host interface 2 comprises a proxy application gateway 2.1 configured to intercept operation requests from the end user entity 1, a first access policy enforcement module 2.2 configured to enforce a first access policy on the intercepted operation requests, an individual access request creation module 2.3, a cryptographic module 2.4 for encrypting / decrypting data that provides at least the data-at-rest function of the cloud storage resource, and an external network interface 2.5 configured to send and receive information to and from cloud servers of one or more cloud service providers.
[0084] The local host interface 2 further includes (or has access to) a first database 2.6 containing rules of the first access policy accessible by the first access policy enforcement module 2.2, a second database 2.7 containing authentication credentials of at least one user account of the second access policy and pairs of access and private keys for this(or these) user account(s) to assume one or more roles, and a third database 2.8 storing key pairs for encrypting and decrypting information.
[0085] Thus, in use, the proxy application gateway 2.1 intercepts operation requests sent by end-user entities 1 running applications such as a web-based portal (e.g., AWS Management Console), an open-source application (e.g., AWS Command Line Interface), or an application for downloading cloud-stored resources to a backup database, which may also be an internal client application using REST.
[0086] The proxy application gateway 2.1 then sends the intercepted operation request to a first access policy enforcement module 2.2 that extracts relevant information and compares it with the access permissions of the first access policy stored in a first database 2.6. If the operation request is allowed according to the first access policy, the individual access request creation module 2.3 shall retrieve from a second database 2.7 the credentials of the user account and / or the key to assume a role that allows the user account to access the protected bucket where the target cloud storage resource resides.
[0087] In an alternative embodiment, the user himself enters the credentials of the user account for these second access policies, and the individual access request creation module 2.3 simply retrieves the key from the second database 2.7 for that user account to assume the appropriate role.
[0088] As previously mentioned, the role policy is preferably a wide open access policy configured to permit execution of all permissible operations on a single cloud-stored resource or group of cloud-stored resources.
[0089] Finally, depending on whether the requested operation is a write or a read operation, the individual access request is encrypted or decrypted respectively using a key stored in a third database 2.8.
[0090] In other words, the local host interface performs data-at-rest encryption, where resources are encrypted by the crypto module 2.4 using a first encryption key stored in the third database 2.8. The resources (e.g., objects) can then be stored (i.e., written) to the target protected cloud bucket.
[0091] In a preferred embodiment, when this encrypted cloud-stored resource is "read" upon retrieval, the cryptographic module 2.4 is configured to decrypt it only if the first access policy defines the decryption operation for the authorized user to associate the exact retrieved resource.
[0092] However, for operation requests like "listing" (resources from a protected bucket) that may not contain associated data, the first access policy may be less restrictive. This may be the case for logging / audit functionality, for example.
[0093] In a further embodiment, localhost data 2 is also configured to create and update historical logs detailing successful and attempted accesses to protected data. These logs are frequently reported to users or clients to flag anomalous or inappropriate data access and potentially warn of insider threats, hackers, and advanced persistent threats (APTs) that may bypass perimeter security.
[0094] Finally, the third database 2.8 may also contain the cloud service provider's certificates to allow individual access requests to be sent over insecure networks, thus ensuring that data is always encrypted in transit.
[0095] These cloud service provider certificates may be accessible via the cryptographic module 2.4 and / or the external network interface 2.5, which then exchanges information securely with the cloud server.
Claims
1. 1. A system for dual-endpoint access control of remote cloud-stored resources, comprising: at least one end-user entity 1 operating at least one application adapted to perform at least one operation on at least one cloud-storage resource; a local host interface 2 configured to control access to said remote cloud storage resource via a communications network by said at least one end user entity running said at least one application, a first access policy associating a set of permitted operations including at least one access permission to one or more of the cloud storage resources; a local host interface 2 configured to send an individual access request via the communication network to at least one remote server storing the cloud storage resource when an authorized user requests to perform at least one permitted operation on at least one authorized cloud storage resource that satisfies the access permissions set in the first access policy; - said at least one remote server storing said cloud storage resources; a cloud interface 4 associated with said at least one remote server, At least one role policy that allows or denies the performance of at least one operation on at least one cloud-storage resource; and an authenticatable user account that is configured to assume at least one of the roles and that is authenticatable through the received individual access request sent by the local host interface; a cloud interface 4 including a second access policy consisting of: A system with.
2. The access permissions set in the first access policy satisfy the following criteria: an end-user entity identifier that references the end-user entity running the at least one application; a user session identifier that references a session-related group of one or more user identification numbers that are logged onto said application or said end user entity and perform operations on at least one application on said end user entity; - an identification number of the operation of at least one application executed on the end user entity; - an identification number of the at least one cloud-storage resource to which access is requested; and a predetermined time window during which said access request is received; The system of claim 1 , comprising at least one of:
3. 3. The system of claim 1 or 2, wherein the local host interface is configured to transmit the individual access requests via one or more application program interfaces (APIs) using Hypertext Transfer Protocol Secure (HTTPS) over Transport Layer Security (TLS).
4. 3. The system of claim 1 or 2, wherein the operations that can be performed by the at least one application on a single or group of cloud-storage resources are at least one of the following operations: read, write, delete, list, update, aggregate, and decrypt.
5. 3. The system of claim 1 or 2, wherein the local host interface performs encryption of data at rest, and the cloud storage resource is encrypted by the local host interface using a first encryption key and stored on the remote server.
6. 6. The system of claim 5, wherein the local host interface or the application itself is configured to decrypt the resource retrieved in response to the individual access request only if the first access policy defines a decryption operation for an authenticated user identifier with which the retrieved resource is associated.
7. 3. The system of claim 1, wherein the local host interface comprises a log database configured to record details of the individual access requests.
8. 3. The system of claim 1, wherein at least one role policy is a wide open access policy configured to permit execution of all permissible operations on a single or group of cloud-storage resources.
9. The system of claim 1 or 2, wherein the application is a web-based portal, an open source application, or an application for downloading cloud storage resources, optionally storing them in a backup database.
10. 3. The system of claim 1, wherein the application is configured to receive login credentials that authenticate a user account of the second access policy along with a cloud-based resource to which access is requested, and the application is further configured to forward the login credentials and resource to the local host interface, which is configured to derive one or more user identifiers for enforcing the first access policy.
11. The system of claim 10 , wherein the local host interface includes the login credentials for authenticating the user account to the second access policy and / or a key for the user account to assume the role.
12. 3. The system of claim 1, wherein the cloud storage resource is a Simple Storage Service (S3) bucket object, the group of resources references some or all of the bucket object, the role policy is an AWS Identity and Access Management (IAM) role policy that includes attached AWS IAM roles, and the user account is an AWS IAM user.
13. 1. A method for dual endpoint access control of a remote cloud-stored resource, comprising: at least one application running on an end user entity receiving a request to perform at least one operation on at least one cloud storage resource; - the at least one application sends operation requests that are intercepted by a local host interface; - the local host interface deriving one or more identifiers that refer to the context of the access request; the local host interface enforcing access control by a first access policy that associates a set of permitted operations, including at least one access permission, to one or more of the cloud-storage resources; - when the local host interface requests that an authorized user perform at least one permitted operation on at least one authorized cloud storage resource that satisfies the access permissions set in the first access policy, sending an individual access request via a communications network to at least one remote server storing the cloud storage resource; a cloud interface associated with at least one remote server storing the cloud-storage resource receiving the individual access request; - authenticating a user account of a second access policy using the individual access request; and The authenticated user account assumes at least one role of at least one role policy that allows or denies execution of an operation on the cloud storage resource according to a second access policy. A method comprising:
14. The method further comprises: the application receiving, together with the request to perform the at least one operation on the at least one cloud storage resource, login credentials authenticating a pre-registered user account of the second access policy; or The local host interface obtains the login credentials for authenticating the pre-registered user account of the second access policy and / or a key for the user account to assume the role.
14. The method of claim 13, comprising:
15. a local host interface for controlling access to a remote cloud storage resource over a communications network by at least one end user entity operating at least one application adapted to perform at least one operation on at least one of said cloud storage resources; the local host interface includes a first access policy that associates a set of permitted operations including at least one access permission to one or more of the cloud storage resources; the local host interface is configured to intercept operation requests sent by the at least one application; The local host interface is configured to transmit, via the communication network to at least one remote server storing the cloud storage resource, an individual access request configured to authenticate a user account of a second access policy at a cloud end when an authorized user requests to perform at least one permitted operation on at least one authorized cloud storage resource that satisfies the access permissions set in the first access policy. Local host interface.
Citation Information
Patent Citations
File management system and management method
JP2005209181A
Access control system
JP2006155074A
Method, System, and Computer Program for Implementing Permission Policy for Web Services (Method and System for Implementing Permission Policy for Web Service)
JP2008537823A
Information processor, communication relay method and program
JP2012064007A
Management system, management method, and program
JP2015158873A