Cloud Authentication via Protected Space Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud service systems rely on weak authentication mechanisms, such as account and password inputs, which are inadequate for secure control and are vulnerable to ransomware attacks when linked to cloud services, lacking technology to prevent ransomware from being downloaded to data processing apparatuses.

Innovation Solution

A managing system and method that includes a data processing apparatus with a divided storage unit into unprotected and protected spaces, a safety gateway device, and an authentication server, which verifies user authentication by confirming operation within a protected space before allowing access to the cloud service system, using multiple authentication data types and ensuring secure login procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If weak authentication mechanisms (account and password input) are used for cloud service login, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of loginVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent verification stages: (1) checking whether the user is located in a protected space, (2) verifying device authentication data, and (3) confirming cloud service authentication data. Each stage operates independently and must all pass for successful login, creating a layered security architecture that maintains ease of use while significantly improving security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary verification before allowing cloud service access. Specifically, it first checks whether the user's data processing apparatus is located in a protected space and verifies device authentication data before proceeding to cloud service authentication. This preliminary action prevents unauthorized access attempts before they reach the main authentication mechanism.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If data processing apparatus is linked to cloud service system, then adaptability is improved, but vulnerability to ransomware attacks increases

Engineering Contradiction:
Improvecloud service accessibilityVSAvoidransomware attack risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication verification mechanism between the data processing apparatus and the cloud service system. This intermediary layer checks whether the user is located in a protected space and verifies authentication data before allowing communication with the cloud service system. This intermediary acts as a buffer that prevents ransomware attacks from directly accessing cloud services while maintaining normal cloud service accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If protected space is created at user terminal, then file protection against ransomware is improved, but inability to prevent ransomware download increases vulnerability

Engineering Contradiction:
Improvefile protectionVSAvoidransomware download prevention
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification before allowing cloud service access. Specifically, it first checks whether the user's data processing apparatus is located in a protected space and verifies device authentication data before proceeding to cloud service authentication. This preliminary action prevents unauthorized access attempts before they reach the main authentication mechanism.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11258793B2Managing system and managing method for managing authentication for cloud service system
Publication Date: 2022.02.22 TRUSTVIEW
  • US11258793B2 patent drawing
  • US11258793B2 patent drawing
  • US11258793B2 patent drawing

AI summary

The invention discloses a managing system and managing method for managing authentication for a cloud service system. When a user operates a data processing apparatus to execute an unprotected start-up procedure to start up a browser application to access from an unprotected space of a data storage unit and transmits an authentication data including no characteristic data associated with a protected space of the data storage unit to the cloud service system through the browser application, the cloud service system redirects the authentication data to an authentication server. The authentication server judges if the authentication data has the characteristic data associated with the protected space, and if NO, the authentication server transmits an alert message representative of refusal of login to the cloud service system. The cloud service system redirects the alert message to the browser application.