Cloud Application Protection Enforcement via Secure Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software application protection schemes lack adequate security enforcement throughout the development lifecycle, as they are often controlled by development teams without specialized security expertise, and fail to provide necessary feedback loops for build and runtime environments, leading to potential security issues going unnoticed.

Innovation Solution

A cloud-based application protection enforcement service that collects and monitors security data at build-time and runtime, enforces predefined protection policies, and provides detailed security audit reports with real-time metrics, preventing non-compliant builds and alerting relevant parties to security issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If development teams control the protection process, then the process is easier to operate, but security expertise and enforcement capability deteriorate

Engineering Contradiction:
Improveprotection process controlVSAvoidsecurity enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cloud-based protection service as an intermediary between development teams and security enforcement. The service receives build artifacts from developers, applies security protections according to predefined policies, and returns protected binaries. This mediator approach allows developers to maintain operational simplicity while ensuring expert-level security enforcement through automated policy compliance checking and protection application.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If protection parameters are tuned for initial builds, then initial security coverage is improved, but security issues in later builds go unnoticed

Engineering Contradiction:
Improveinitial security coverageVSAvoidongoing security monitoring
Core Design Contradiction:
Manufacturing precisionVSReliability

Solution Approach 1:

The system implements feedback loops that continuously monitor build artifacts against security policies. Each build is analyzed to detect security issues, and results are fed back to developers through notifications and audit reports. The system maintains a history of security findings across builds, enabling continuous improvement of security posture rather than one-time protection application.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Security policies are predefined and configured in advance before the build process begins. The cloud service automatically applies these pre-configured protection measures to each build artifact, ensuring consistent security enforcement without requiring developers to manually adjust parameters for each build type.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If security audit data is generated locally, then data generation is faster, but data accessibility and usability for security reviews deteriorate

Engineering Contradiction:
Improveaudit data generationVSAvoidaudit data accessibility
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The cloud-based protection service provides multiple functions through a single platform: it applies security protections, generates audit data, stores results centrally, and provides various access methods including web interfaces and API integrations. This multi-functional approach eliminates the need for separate local audit systems while improving data accessibility and usability for security reviews.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20210349970A1Application protection enforcement in the cloud
Publication Date: 2021.11.11 ARRIS ENTERPRISES LLC
  • US20210349970A1 patent drawing
  • US20210349970A1 patent drawing
  • US20210349970A1 patent drawing

AI summary

A method and system provide the ability to enforce application protection in the cloud. A request to register an application is received in a registration tool executing within a cloud computing environment. The registration tool collects application information data and protection policy settings, and registers the application by returning, to a build-time environment, a secure protection authorization (SPA) certificate that authorizes the application to be built. A build registration tool executing in the cloud computing environment receives, from a cloud protection toolchain executing in the build-time environment, signed build-data that includes the SPA and build information for a build of the application. After determining, in the cloud, that the SPA is authenticate, developer credentials are authorized, and the build information is valid, the build registration tool responds to the cloud protection toolchain that the build for the application is authorized.