Cloud Security Server Traffic Routing for Enterprise Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face difficulties in monitoring and controlling access to cloud applications, leading to challenges in protecting their networks from data leakage and computer security issues due to the complexity of managing third-party services.

Innovation Solution

A system comprising a cloud security server that receives and analyzes network traffic, directs it to application handlers for processing, and enforces application policies to control access, utilizing components like application identification, encryption, and reputation servers to manage and secure cloud application access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises allow access to cloud applications, then productivity and service accessibility are improved, but network security and data protection deteriorate

Engineering Contradiction:
Improveaccess to cloud applicationsVSAvoiddata leakage and virus infection
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud security server as an intermediary component between cloud application clients and cloud application servers. This mediator receives network traffic streams, identifies cloud applications, directs traffic to appropriate application handlers, and enforces application policies. The intermediary enables enterprises to maintain productivity by allowing cloud application access while simultaneously protecting network security through centralized monitoring and control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises implement comprehensive monitoring of cloud application access, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud security server is segmented into distinct functional components: an application identification module that identifies cloud applications in network traffic, multiple application handlers that process different cloud applications, and a policy enforcement mechanism. This segmentation allows the system to manage complexity by dividing monitoring functions into specialized modules, each handling specific aspects of cloud application traffic, thereby improving network security without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If enterprises block access to cloud applications, then network security is improved, but productivity and service accessibility deteriorate

Engineering Contradiction:
Improvecomputer security protectionVSAvoidaccess to third party services
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system applies different security policies to different cloud applications based on their specific characteristics and risk profiles. The application identification module identifies individual cloud applications, and the policy enforcement mechanism applies tailored security measures to each. This local quality approach allows enterprises to maintain high security for sensitive applications while permitting broader access to lower-risk cloud services, thereby protecting network security without unduly restricting productivity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9692759B1Control of cloud application access for enterprise customers
Publication Date: 2017.06.27 TREND MICRO INC
  • US9692759B1 patent drawing
  • US9692759B1 patent drawing
  • US9692759B1 patent drawing

AI summary

A system for controlling access to cloud applications includes a cloud security server that receives network traffic stream from cloud application clients of a private computer network. The cloud security server examines the network traffic stream to identify a cloud application that is associated with the network traffic stream and directs the network traffic stream to one of several application handlers that is configured to process network traffic stream for the cloud application. The application handler enforces on the network traffic stream an application policy that is applicable to the cloud application.