Cloud Application Isolation Portal for Secure Session Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing cloud applications are inadequate in protecting unmanaged devices from data loss and security threats, as they often require extensive resources and have limitations on the number of supported applications, leading to blind spots in monitoring and potential data leakage.

Innovation Solution

The implementation of a cloud application isolation portal and a cloud access security broker that establish a connection based on user credentials, manage sessions, and isolate traffic to prevent client-side processing, providing a seamless user experience while securing data sessions across multiple unmanaged devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If reverse proxy models are used to secure cloud applications, then security monitoring is improved, but device resources are consumed and the number of supported applications is limited

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddevice resources
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud application isolation portal as an intermediary component that sits between the cloud application and the computing device. This portal handles security monitoring, traffic isolation, and session management remotely, eliminating the need for resource-intensive reverse proxy models on the device side while maintaining comprehensive security monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If reverse proxy models are used to secure cloud applications, then security monitoring is improved, but the number of supported applications is limited

Engineering Contradiction:
Improvesecurity monitoringVSAvoidnumber of supported applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cloud application isolation portal is designed as a universal platform that can securely host and manage multiple cloud applications simultaneously. It provides a standardized interface and isolation mechanism that works across different applications without requiring application-specific reverse proxy configurations, thereby increasing the number of supported applications while maintaining security monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If cloud applications are accessed directly on unmanaged devices, then ease of access is improved, but data loss and security threats increase

Engineering Contradiction:
Improveease of accessVSAvoiddata loss and security threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cloud application into isolated instances that run within the cloud application isolation portal on the computing device. This segmentation prevents direct access to the underlying device resources and isolates potential security threats within contained environments. Users can access multiple isolated instances simultaneously, maintaining ease of access while preventing data loss and security threats through architectural isolation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11558383B1Securing cloud applications via isolation
Publication Date: 2023.01.17 CA TECH INC
  • US11558383B1 patent drawing
  • US11558383B1 patent drawing
  • US11558383B1 patent drawing

AI summary

A method for securing cloud applications is described. The method may include establishing a connection between a cloud application isolation portal, a cloud access security broker, and a cloud application based on an indication of the cloud application and a set of credentials associated with an end user of the cloud application, and managing, via the cloud application isolation portal and the cloud access security broker, a session between the cloud application and a computing device associated with the end user based on the connection between the cloud application isolation portal with the cloud access security broker and the cloud application.