Cloud Security Middleware for Data-Deficient Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud service solutions lack comprehensive visibility and control over data sharing, leading to risks of sensitive data leakage and compliance issues due to data-deficient transactions and the proliferation of unmanaged devices and cloud applications.

Innovation Solution

Implementing an inspective analyzer to discover all cloud applications in use, enforce real-time policies through an active analyzer, and utilize a Cloud Confidence Index (CCI) to assess and manage cloud services, ensuring granular control and encryption of sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud services are adopted to enable easy content sharing and access, then productivity and ease of operation are improved, but data security and control are worsened due to lack of visibility over data sharing

Engineering Contradiction:
Improveease of content sharingVSAvoiddata security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security gateway as an intermediary component positioned between client devices and cloud services. This gateway inspects, analyzes, and controls data transactions before they reach the cloud, enabling organizations to maintain visibility and control over data sharing while still allowing easy access to cloud services. The gateway acts as a mediator that prevents data leakage without blocking legitimate usage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If comprehensive monitoring and control of cloud transactions is implemented, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata leakage preventionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the security function into distinct components within the security gateway, including a policy server for managing access control rules, a content inspection engine for analyzing data, and a transaction monitoring module for tracking cloud operations. This segmentation allows each component to handle specific security tasks independently, making the overall complex security system more manageable and maintainable while providing comprehensive monitoring capabilities.

Inventive Principle:
Principle #1Segmentation

3Reliability

If policy enforcement for data protection is applied, then compliance is improved, but ease of operation deteriorates due to additional control layers

Engineering Contradiction:
Improvecompliance assuranceVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the security gateway automatically enforces compliance policies without requiring manual intervention for each transaction. The system autonomously inspects data, applies access control policies, and monitors transactions in real-time, ensuring compliance while maintaining smooth user operation. Users experience minimal friction as the security controls operate transparently in the background.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4002176B1Middle ware security layer for cloud computing services
Publication Date: 2026.02.18 NETSKOPE INC
  • EP4002176B1 patent drawingFigure 1A
  • EP4002176B1 patent drawingFigure 1B
  • EP4002176B1 patent drawingFigure 1C

AI summary

The technology disclosed relates to enforcing multi-part policies on data-deficient transactions of independent data stores. In particular, it relates to combining active analysis of access requests for the independent object stores with inspection of objects in the independent object stores, each of the analysis and inspection generating and persisting object metadata in a supplemental data store, actively processing data-deficient transactions that apply to the objects by accessing the supplemental data store to retrieve object metadata not available in transaction streams of the data-deficient transactions, and actively enforcing the multi-part policies using the retrieved object metadata.