Cloud Access Control Server for Risk-Based Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in implementing effective access control for cloud-based services due to the lack of tailored security policies and the dependence on third-party firewalls or proxies, which are not well-suited for cloud service providers, leading to increased risk exposure.

Innovation Solution

A cloud access control server and method that operates within an enterprise's existing network infrastructure, using a policy engine to enforce access control policies specific to cloud service providers and categories, based on risk assessments, and communicates with firewalls or proxies to allow or deny access, control traffic direction, and provide encryption or warning messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If third-party firewall or proxy is used to implement network access control, then network access control is achieved, but the security policies are not specifically tailored for cloud service providers and risk exposure increases

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidcloud service provider specificity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a cloud access control server as an intermediary component between the enterprise network and cloud service providers. This server specifically evaluates cloud service requests against tailored security policies, bridging the gap between general network access control and cloud-specific security requirements. The intermediary enables policies to be specifically adapted for cloud services while maintaining integration with existing infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional access control schemes are implemented, then general security is maintained, but they do not work well for cloud based services and risk exposure increases

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidcloud service adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing access control policies that are specific to cloud service contexts rather than uniform general policies. The cloud access control server evaluates requests based on cloud-specific criteria such as service provider identity, service category, and risk assessment, enabling differentiated security treatment for cloud services versus traditional services.

Inventive Principle:
Principle #3Local quality

3Reliability

If third-party firewall or proxy is used, then network access control is achieved, but enterprises are dependent on third party to implement security policies leading to increased risk exposure

Engineering Contradiction:
Improvesecurity policy implementationVSAvoidrisk exposure
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The cloud access control server acts as a specialized intermediary that enterprises control directly, reducing dependence on third-party firewalls for cloud-specific security. This intermediary enables enterprises to implement and enforce their own security policies tailored to cloud services, thereby reducing risk exposure associated with relying on generic third-party solutions.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If content driven network access control is implemented, then file sharing and sensitive data scanning are achieved, but existing security policies are not well adapted for cloud based services

Engineering Contradiction:
Improvecontent securityVSAvoidcloud service compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by creating cloud-specific access control policies that go beyond content-driven approaches. The cloud access control server evaluates requests based on cloud service attributes (provider identity, service category, risk level) in addition to content analysis, enabling security policies to be both content-aware and cloud-service-adapted simultaneously.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10154007B1Enterprise cloud access control and network access control policy using risk based blocking
Publication Date: 2018.12.11 SKYHIGH SECURITY LLC
  • US10154007B1 patent drawing
  • US10154007B1 patent drawing
  • US10154007B1 patent drawing

AI summary

A cloud access control server and method provides a cloud service access control database to implement cloud services access control policy. The cloud service access control database stores thereon cloud service identifiers associated with cloud service providers having high risk scores. In some embodiments, the cloud service identifiers form a block list of cloud services which is provided to network device of the enterprise data network to implement cloud service access control. In other embodiments, a cloud access control server and method implements cloud services access control policy for an enterprise. The cloud access control server and method receives network traffic data from the installed firewall or proxy at the enterprise and process the network traffic data with respect to cloud service access. The cloud access control server provides instructions to the firewall or proxy to allow or deny the network access at the enterprise.