Cloud Authentication via Protected Space Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud service systems rely on weak authentication mechanisms, such as account and password inputs, which are inadequate for secure control and are vulnerable to ransomware attacks when linked to cloud services, lacking technology to prevent ransomware from being downloaded to data processing apparatuses.
Innovation Solution
A managing system and method that includes a data processing apparatus with a divided storage unit into unprotected and protected spaces, a safety gateway device, and an authentication server, which verifies user authentication by confirming operation within a protected space before allowing access to the cloud service system, using multiple authentication data types and ensuring secure login procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If weak authentication mechanisms (account and password input) are used for cloud service login, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The authentication process is segmented into multiple independent verification stages: (1) checking whether the user is located in a protected space, (2) verifying device authentication data, and (3) confirming cloud service authentication data. Each stage operates independently and must all pass for successful login, creating a layered security architecture that maintains ease of use while significantly improving security reliability.
Solution Approach 2:
The system performs preliminary verification before allowing cloud service access. Specifically, it first checks whether the user's data processing apparatus is located in a protected space and verifies device authentication data before proceeding to cloud service authentication. This preliminary action prevents unauthorized access attempts before they reach the main authentication mechanism.
2Adaptability or versatility
If data processing apparatus is linked to cloud service system, then adaptability is improved, but vulnerability to ransomware attacks increases
Solution Approach 1:
The patent introduces an intermediary authentication verification mechanism between the data processing apparatus and the cloud service system. This intermediary layer checks whether the user is located in a protected space and verifies authentication data before allowing communication with the cloud service system. This intermediary acts as a buffer that prevents ransomware attacks from directly accessing cloud services while maintaining normal cloud service accessibility.
3Reliability
If protected space is created at user terminal, then file protection against ransomware is improved, but inability to prevent ransomware download increases vulnerability
Solution Approach 1:
The system performs preliminary verification before allowing cloud service access. Specifically, it first checks whether the user's data processing apparatus is located in a protected space and verifies device authentication data before proceeding to cloud service authentication. This preliminary action prevents unauthorized access attempts before they reach the main authentication mechanism.
Data Source
AI summary
The invention discloses a managing system and managing method for managing authentication for a cloud service system. When a user operates a data processing apparatus to execute an unprotected start-up procedure to start up a browser application to access from an unprotected space of a data storage unit and transmits an authentication data including no characteristic data associated with a protected space of the data storage unit to the cloud service system through the browser application, the cloud service system redirects the authentication data to an authentication server. The authentication server judges if the authentication data has the characteristic data associated with the protected space, and if NO, the authentication server transmits an alert message representative of refusal of login to the cloud service system. The cloud service system redirects the alert message to the browser application.


