Cloud Tenant Access Restriction via Identity Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations in highly regulated sectors, such as banking and defense, face challenges in preventing data exfiltration and rogue trading scenarios when using public cloud services like Office 365, as existing solutions fail to restrict access to only authorized tenants, leading to potential unauthorized access and data breaches.

Innovation Solution

Implementing a method that allows an entity-managed device to access its associated tenant on a public cloud service while preventing access to other tenants by obtaining and enforcing access policies through an identity platform, which restricts token issuance to the device's home tenant only, using device registration, network edge proxies, or firewall policies to filter HTTP traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If public cloud services are made accessible to multiple tenants, then service versatility and accessibility are improved, but security risk and data exfiltration potential increase

Engineering Contradiction:
Improvemulti-tenant accessibilityVSAvoiddata exfiltration risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism between the user's device and the cloud service. The device must present valid authentication information to the cloud service's authentication system before accessing any tenant data. This intermediary layer verifies the device's authorization status and enforces tenant isolation policies, preventing direct access to other tenants while maintaining service versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control policies are enforced at the cloud service level, then security and tenant isolation are improved, but system complexity increases

Engineering Contradiction:
Improvetenant access controlVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex access control logic from the device level and concentrates it at the cloud service's authentication system. Instead of requiring complex local policy enforcement on diverse devices, the system uses a centralized authentication mechanism that handles tenant isolation and access control policies. This extraction simplifies device complexity while maintaining reliable tenant access control through the cloud-based authentication system.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If device registration and authentication are required, then unauthorized access prevention is improved, but user convenience and access speed decrease

Engineering Contradiction:
Improveunauthorized accessVSAvoiddevice access convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements preliminary device registration and authentication before actual tenant access. During the preliminary action phase, devices are registered with the cloud service and authentication information is established. Once registered, devices can access authorized tenants without repeated authentication, providing convenience while maintaining security. The preliminary action ensures unauthorized access is prevented before it can occur.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If tenant access is restricted to home tenant only, then data security and compliance are improved, but service functionality and versatility are reduced

Engineering Contradiction:
Improvedata security complianceVSAvoidtenant access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic tenant access control that adapts to organizational policies. The system can dynamically determine which tenants a registered device is authorized to access based on configured policies. This dynamic approach allows strict home-tenant-only restriction for compliance-critical scenarios while enabling multi-tenant access when organizational policies permit, thus maintaining both security and versatility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10320844B2Restricting access to public cloud SaaS applications to a single organization
Publication Date: 2019.06.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10320844B2 patent drawing
  • US10320844B2 patent drawing
  • US10320844B2 patent drawing

AI summary

Allowing an entity managed device to access a tenant associated with the e on a public cloud service while preventing the device from accessing one or more other tenants on the cloud service. A method includes, at the cloud service, obtaining policy from the entity with respect to tenant access. The method further includes, at the cloud service, receiving a request from the entity managed device to access a tenant at the cloud service. The method further includes granting or denying the access request based on the policy obtained from the entity.