Cloud Security System Application-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The growth of mobile devices and cloud services in enterprises poses security risks due to uncontrolled access to corporate resources through various applications, as traditional role-based access controls fail to account for the application used to access these resources, leading to potential data breaches.

Innovation Solution

A cloud-based security system that enforces application-based control by evaluating requests from user devices and limiting access based on the nature of the application, allowing only authorized applications to access network resources, and redirecting or blocking unauthorized ones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If role-based access controls are implemented through on-premise Virtual Private Networks, then users with appropriate rights can access corporate resources using any application, but security risks increase as users may use malicious applications to access sensitive corporate information

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from role-based access control (controlling who can access) to application-based access control (controlling what can access). This parameter change in the control mechanism allows the system to evaluate and restrict access based on application identity and security posture, thereby maintaining ease of operation while mitigating security risks from malicious applications

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary component (application gateway or security broker) that sits between users and corporate resources. This intermediary evaluates application requests, verifies security credentials, and enforces access policies, thereby blocking malicious applications while allowing legitimate ones to access corporate resources through the controlled intermediary

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional antivirus software is used to black/white list applications, then malicious software can be removed from the system, but the correspondence between the nature of resource and the application requesting the resource is not captured

Engineering Contradiction:
Improvemalware removalVSAvoidapplication-resource matching
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent moves from generic antivirus-based black/white listing to application-based access control that incorporates resource type information. This parameter change enables the system to make precise decisions by matching application characteristics with resource requirements, thereby improving both reliability and measurement precision simultaneously

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the access control decision-making process into multiple evaluation criteria: application identity, resource type, security policies, and user context. This segmentation allows the system to evaluate each aspect separately and combine them for precise access decisions, improving both malware detection reliability and application-resource matching precision

Inventive Principle:
Principle #1Segmentation

3Reliability

If IT admins implement full control over lockdown systems, then installation of illegitimate software can be prevented, but users have limited privileges to install or remove software

Engineering Contradiction:
Improvesoftware controlVSAvoidsoftware installation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an application gateway as an intermediary that mediates between user software installation requests and system security policies. This intermediary allows users to install software with appropriate approvals and monitoring, maintaining security control while improving ease of operation compared to strict lockdown systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic access control policies that can adapt to different users, contexts, and risk levels. Instead of static lockdown, the system dynamically evaluates installation requests based on user role, application security posture, and organizational policies, thereby maintaining reliability while improving ease of operation through flexible, context-aware approvals

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If users access corporate resources from any application, device, network, or geography with a VPN application, then access flexibility increases, but security risks arise from unauthorized applications

Engineering Contradiction:
Improveaccess flexibilityVSAvoidunauthorized application access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the access control parameter from location/device-based (VPN connectivity) to application-based security evaluation. This allows users to access corporate resources from any location or device while the system evaluates each application request against security policies, maintaining adaptability while blocking unauthorized applications

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements feedback mechanisms where the application gateway continuously monitors application behavior, security credentials, and access patterns. This feedback loop allows the system to dynamically adjust access decisions, providing real-time security responses that maintain flexibility while preventing unauthorized application access through continuous evaluation

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10728252B2Client application based access control in cloud security systems for mobile devices
Publication Date: 2020.07.28 ZSCALER INC
  • US10728252B2 patent drawing
  • US10728252B2 patent drawing
  • US10728252B2 patent drawing

AI summary

A cloud-based security system enforcing application-based control of network resources includes a plurality of nodes communicatively coupled to the Internet; and one or more authority nodes communicatively coupled to the plurality of nodes; wherein a node of the plurality of nodes is communicatively coupled to a user device via the Internet, and wherein the node is configured to receive a request from a user device for network resources on the Internet or in an external network, to evaluate the request to determine an application on the user device associated with the request, and to provide application-based control of the request based on the determined application and the network resources.