Cloud Policy Enforcement via Organizational Credential Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges with 'shadow IT' where employees bypass IT departments to use unmanaged cloud services, leading to financial costs and security risks due to lack of compliance with organizational policies.

Innovation Solution

A method for cloud service providers to detect and verify organizational associations through credentials and characteristics, apply organizational policies, and manage subscriptions to ensure compliance, allowing IT to control and monitor cloud services used by entities within the organization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employees are allowed to use cloud services directly without IT intervention, then ease of operation and user satisfaction improve, but security and policy compliance deteriorate due to shadow IT

Engineering Contradiction:
Improveease of cloud service accessVSAvoidpolicy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary system that sits between employees and cloud service providers. This intermediary automatically detects shadow IT usage, verifies organizational credentials, and enforces policies without requiring employees to directly interact with IT departments. The intermediary translates user actions into policy-compliant operations, resolving the contradiction between ease of access and policy compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing employees to directly access cloud services through automated credential verification and policy enforcement. IT departments configure policies once, and the system automatically applies them to all users and services, eliminating the need for manual IT intervention in each service request while maintaining compliance.

Inventive Principle:
Principle #25Self-service

2Reliability

If IT departments manually manage and approve each cloud service request, then policy compliance improves, but productivity and response time deteriorate due to IT bottleneck

Engineering Contradiction:
Improvepolicy complianceVSAvoidservice provisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-configuring organizational credentials, service permissions, and policy rules before users need them. IT departments set up the framework in advance, and the automated system handles real-time verification and enforcement, eliminating the need for manual approval of each service request while maintaining compliance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs automated detection and verification mechanisms that rapidly process credential validation and policy checks. The system accelerates the service provisioning process through automated workflows, real-time monitoring, and instant policy enforcement, dramatically increasing productivity compared to manual IT review processes.

Inventive Principle:
Principle #38Strong oxidants (Accelerated oxidation)

3Reliability

If IT departments maintain a centralized portal for cloud service requests, then policy control improves, but adaptability to new cloud features deteriorates as IT cannot keep up with constant provider updates

Engineering Contradiction:
Improvepolicy controlVSAvoidcloud service update responsiveness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the policy enforcement function from the cloud service provider interfaces. The centralized policy management system remains stable and secure, while automated intermediaries handle interactions with various cloud providers. This segmentation allows the policy control system to remain unchanged while adapting to new cloud features through automated credential verification and service detection mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal credential verification and policy enforcement mechanism that works across multiple cloud service providers simultaneously. The standardized approach to credential validation and policy application remains consistent while supporting diverse cloud services and their evolving features, maintaining both control and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If companies block direct cloud service access and route all requests through IT, then security improves, but ease of operation and user satisfaction deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcloud service accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an automated intermediary that provides security functions without requiring manual IT intervention. The intermediary transparently verifies credentials, detects shadow IT, and enforces policies in the background, allowing users to access cloud services directly while maintaining security. This resolves the contradiction by providing security automation that is invisible to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops through automated monitoring of cloud service usage, credential verification outcomes, and policy compliance status. This real-time feedback enables the system to dynamically adjust enforcement actions while maintaining security, without requiring users to change their access patterns or experience manual IT approvals.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3186745B1Multi cloud policy enactment via organizations to cloud-provider partnerships
Publication Date: 2020.04.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3186745B1 patent drawingFigure 1
  • EP3186745B1 patent drawingFigure 2
  • EP3186745B1 patent drawingFigure 3

AI summary

A method includes acts for establishing a subscription for an entity. The method includes receiving, at a cloud service provider, a request from an entity to establish a subscription. The request includes credentials for the entity that are not proper credentials for an organization associated with the entity that the entity should use to access services for the organization. The method further includes performing a corrective action based on detecting one or more factors to determine that the entity is associated with the organization. The method further includes providing services based on the corrective action.