Cloud File Sharing via SECaaS Intermediary Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based file sharing systems lack effective security measures to validate and protect files shared by users located off-site from the enterprise network, risking data loss, infections, and leaks.
Innovation Solution
Implementing Security-as-a-Service (SECaaS) in a cloud-based environment that decouples security from the collaboration platform, using a cloud-based key management server to encrypt and decrypt files, and a file sharing server that forwards files to a SECaaS server for validation and scanning without requiring on-path authorization, ensuring secure file sharing without decrypting files on the sharing server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cloud-based file sharing is implemented without SECaaS integration, then ease of operation and accessibility for off-site users is improved, but security and protection against malicious files deteriorates
Solution Approach 1:
The patent introduces a cloud-based SECaaS server as an intermediary between the file sharing server and off-site users. This mediator performs security validation, malware scanning, and file inspection without requiring direct integration between the file sharing system and security infrastructure, thus maintaining ease of operation while improving security reliability
Solution Approach 2:
The system segments security functions from the file sharing platform by utilizing external SECaaS infrastructure. Security validation, encryption key management, and malware detection are separated into independent cloud-based services, allowing the file sharing system to remain simple and accessible while delegating security responsibilities to specialized external services
2Reliability
If on-path authorization and monitoring are implemented for file transfers, then security control is improved, but device complexity and infrastructure requirements worsen
Solution Approach 1:
The patent employs a cloud-based SECaaS server as an intermediary that handles security validation without requiring on-path authorization infrastructure within the enterprise network. This eliminates the need for complex on-premises security appliances, proxies, or deep packet inspection systems while maintaining security control through external cloud-based validation
Solution Approach 2:
The system implements self-service security validation where the SECaaS infrastructure autonomously performs malware scanning, file inspection, and threat detection without requiring manual intervention, on-path monitoring, or complex enterprise infrastructure. The cloud-based services automatically validate files and provide security assurances back to the file sharing system
3Reliability
If end-to-end cryptography is implemented for file protection, then security is improved, but difficulty of detecting and measuring malicious content worsens
Solution Approach 1:
The patent implements preliminary action by performing malware scanning and security validation on files before they are encrypted and shared with off-site users. The SECaaS infrastructure inspects files in their decrypted state, detects malicious content, and only allows safe files to proceed to encryption and sharing, thus maintaining both encryption security and the ability to detect malicious content
Solution Approach 2:
The cloud-based SECaaS server acts as an intermediary that temporarily holds and inspects files in their decrypted state before encryption. This mediator enables malware detection and security validation without requiring the file sharing system or end users to have the capability to decrypt and inspect encrypted files, thus maintaining encryption security while enabling malicious content detection
Data Source
AI summary
A method of leveraging security-as-a-service for cloud-based file sharing includes receiving, at a cloud-based file sharing server external to an enterprise network and having connectivity to the enterprise network, instructions from an enterprise network to validate a file uploaded by a first user associated with the enterprise network before allowing the file to be downloaded. The file sharing server may then receive the file from the first user and forward the file to a cloud-based security-as-a-service (SECaaS) server that is also external to the enterprise network and has connectivity to the enterprise network. The file sharing server receives a determination of validation from the cloud-based SECaaS server and allows a second user to download the file based on the determination. To make the determination, the SECaaS server retrieves cryptographic keying material from a cloud-based key management server, and decrypts the file.


