Cloud Access Control Server for Risk-Based Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in implementing effective access control for cloud-based services due to the lack of tailored security policies and the dependence on third-party firewalls or proxies, which are not well-suited for cloud service providers, leading to increased risk exposure.
Innovation Solution
A cloud access control server and method that operates within an enterprise's existing network infrastructure, using a policy engine to enforce access control policies specific to cloud service providers and categories, based on risk assessments, and communicates with firewalls or proxies to allow or deny access, control traffic direction, and provide encryption or warning messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party firewall or proxy is used to implement network access control, then network access control is achieved, but the security policies are not specifically tailored for cloud service providers and risk exposure increases
Solution Approach 1:
The patent introduces a cloud access control server as an intermediary component between the enterprise network and cloud service providers. This server specifically evaluates cloud service requests against tailored security policies, bridging the gap between general network access control and cloud-specific security requirements. The intermediary enables policies to be specifically adapted for cloud services while maintaining integration with existing infrastructure.
2Reliability
If traditional access control schemes are implemented, then general security is maintained, but they do not work well for cloud based services and risk exposure increases
Solution Approach 1:
The patent applies local quality by implementing access control policies that are specific to cloud service contexts rather than uniform general policies. The cloud access control server evaluates requests based on cloud-specific criteria such as service provider identity, service category, and risk assessment, enabling differentiated security treatment for cloud services versus traditional services.
3Reliability
If third-party firewall or proxy is used, then network access control is achieved, but enterprises are dependent on third party to implement security policies leading to increased risk exposure
Solution Approach 1:
The cloud access control server acts as a specialized intermediary that enterprises control directly, reducing dependence on third-party firewalls for cloud-specific security. This intermediary enables enterprises to implement and enforce their own security policies tailored to cloud services, thereby reducing risk exposure associated with relying on generic third-party solutions.
4Reliability
If content driven network access control is implemented, then file sharing and sensitive data scanning are achieved, but existing security policies are not well adapted for cloud based services
Solution Approach 1:
The patent implements local quality by creating cloud-specific access control policies that go beyond content-driven approaches. The cloud access control server evaluates requests based on cloud service attributes (provider identity, service category, risk level) in addition to content analysis, enabling security policies to be both content-aware and cloud-service-adapted simultaneously.
Data Source
AI summary
A cloud access control server and method provides a cloud service access control database to implement cloud services access control policy. The cloud service access control database stores thereon cloud service identifiers associated with cloud service providers having high risk scores. In some embodiments, the cloud service identifiers form a block list of cloud services which is provided to network device of the enterprise data network to implement cloud service access control. In other embodiments, a cloud access control server and method implements cloud services access control policy for an enterprise. The cloud access control server and method receives network traffic data from the installed firewall or proxy at the enterprise and process the network traffic data with respect to cloud service access. The cloud access control server provides instructions to the firewall or proxy to allow or deny the network access at the enterprise.


