Cloud Service Gateway for Unauthorized Account Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face security risks due to unauthorized and unmanaged accounts accessing cloud computing services, which are not monitored or managed by the enterprise, posing a challenge in maintaining compliance and security policies.
Innovation Solution
A cloud service account management method that identifies unauthorized accounts and triggers a workflow to bring them under management, allowing for monitoring and compliance with enterprise security policies by redirecting access through a secure web gateway and utilizing a registration portal to obtain credentials for unmanaged accounts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If administrators use authorized accounts to access cloud service providers, then security control and monitoring are maintained, but ease of operation is reduced due to strict access controls
Solution Approach 1:
The patent introduces a cloud service gateway as an intermediary component that sits between administrators and cloud service providers. The gateway intercepts authentication requests, validates credentials against enterprise policies, and manages session tokens. This mediator enables strict security control while maintaining ease of operation by handling authentication complexity transparently, allowing administrators to access cloud services through a simplified interface without directly managing complex credential validation.
2Ease of operation
If shadow accounts are created for cloud service access, then ease of operation is improved by bypassing strict controls, but security risks increase due to lack of monitoring
Solution Approach 1:
The patent implements a feedback mechanism where the cloud service gateway continuously monitors authentication requests and account activities. When a shadow account is detected (an account not registered in the enterprise's account management system), the gateway generates alerts and blocks further access. The system provides real-time feedback to administrators about unauthorized accounts and their activities, enabling rapid response to security threats while preventing shadow account usage.
Solution Approach 2:
The patent applies preliminary anti-action by proactively preventing shadow account creation and usage before security incidents can occur. The cloud service gateway intercepts authentication requests and checks them against the enterprise's authorized account database beforehand. If an account is not recognized or violates policy, access is blocked in advance, preventing potential security breaches rather than reacting to them after the fact.
3Reliability
If all cloud service access is monitored and controlled, then security compliance is improved, but device complexity increases due to additional control mechanisms
Solution Approach 1:
The patent implements a universal cloud service gateway that consolidates multiple security functions into a single platform. The gateway simultaneously performs authentication, authorization, account management, activity monitoring, policy enforcement, and alerting functions. By providing multi-functionality in one system, the patent achieves comprehensive security compliance without proportionally increasing device complexity, as the single gateway replaces what would otherwise require multiple separate security tools and systems.
Data Source
AI summary
A cloud service account management method identifies unauthorized or unmanaged accounts making administration console access or API access at a cloud computing service and triggers a work flow to place the accounts under management. In one embodiment, the user device is directed to a registration portal to provide credentials of the unauthorized account. Once the accounts are made managed, the cloud service account management method can monitor the activities of the accounts and can apply compliance or security policies to the managed accounts.


