Cloud Service Gateway for Unauthorized Account Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face security risks due to unauthorized and unmanaged accounts accessing cloud computing services, which are not monitored or managed by the enterprise, posing a challenge in maintaining compliance and security policies.

Innovation Solution

A cloud service account management method that identifies unauthorized accounts and triggers a workflow to bring them under management, allowing for monitoring and compliance with enterprise security policies by redirecting access through a secure web gateway and utilizing a registration portal to obtain credentials for unmanaged accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators use authorized accounts to access cloud service providers, then security control and monitoring are maintained, but ease of operation is reduced due to strict access controls

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud service gateway as an intermediary component that sits between administrators and cloud service providers. The gateway intercepts authentication requests, validates credentials against enterprise policies, and manages session tokens. This mediator enables strict security control while maintaining ease of operation by handling authentication complexity transparently, allowing administrators to access cloud services through a simplified interface without directly managing complex credential validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If shadow accounts are created for cloud service access, then ease of operation is improved by bypassing strict controls, but security risks increase due to lack of monitoring

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the cloud service gateway continuously monitors authentication requests and account activities. When a shadow account is detected (an account not registered in the enterprise's account management system), the gateway generates alerts and blocks further access. The system provides real-time feedback to administrators about unauthorized accounts and their activities, enabling rapid response to security threats while preventing shadow account usage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by proactively preventing shadow account creation and usage before security incidents can occur. The cloud service gateway intercepts authentication requests and checks them against the enterprise's authorized account database beforehand. If an account is not recognized or violates policy, access is blocked in advance, preventing potential security breaches rather than reacting to them after the fact.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If all cloud service access is monitored and controlled, then security compliance is improved, but device complexity increases due to additional control mechanisms

Engineering Contradiction:
ImprovecomplianceVSAvoidcontrol mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cloud service gateway that consolidates multiple security functions into a single platform. The gateway simultaneously performs authentication, authorization, account management, activity monitoring, policy enforcement, and alerting functions. By providing multi-functionality in one system, the patent achieves comprehensive security compliance without proportionally increasing device complexity, as the single gateway replaces what would otherwise require multiple separate security tools and systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10771469B1Cloud service account management
Publication Date: 2020.09.08 SKYHIGH SECURITY LLC
  • US10771469B1 patent drawing
  • US10771469B1 patent drawing
  • US10771469B1 patent drawing

AI summary

A cloud service account management method identifies unauthorized or unmanaged accounts making administration console access or API access at a cloud computing service and triggers a work flow to place the accounts under management. In one embodiment, the user device is directed to a registration portal to provide credentials of the unauthorized account. Once the accounts are made managed, the cloud service account management method can monitor the activities of the accounts and can apply compliance or security policies to the managed accounts.