Cloud Tenant Access Restriction via Identity Platform
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations in highly regulated sectors, such as banking and defense, face challenges in preventing data exfiltration and rogue trading scenarios when using public cloud services like Office 365, as existing solutions fail to restrict access to only authorized tenants, leading to potential unauthorized access and data breaches.
Innovation Solution
Implementing a method that allows an entity-managed device to access its associated tenant on a public cloud service while preventing access to other tenants by obtaining and enforcing access policies through an identity platform, which restricts token issuance to the device's home tenant only, using device registration, network edge proxies, or firewall policies to filter HTTP traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If public cloud services are made accessible to multiple tenants, then service versatility and accessibility are improved, but security risk and data exfiltration potential increase
Solution Approach 1:
The patent introduces an intermediary authentication mechanism between the user's device and the cloud service. The device must present valid authentication information to the cloud service's authentication system before accessing any tenant data. This intermediary layer verifies the device's authorization status and enforces tenant isolation policies, preventing direct access to other tenants while maintaining service versatility.
2Reliability
If access control policies are enforced at the cloud service level, then security and tenant isolation are improved, but system complexity increases
Solution Approach 1:
The patent extracts the complex access control logic from the device level and concentrates it at the cloud service's authentication system. Instead of requiring complex local policy enforcement on diverse devices, the system uses a centralized authentication mechanism that handles tenant isolation and access control policies. This extraction simplifies device complexity while maintaining reliable tenant access control through the cloud-based authentication system.
3Object-affected harmful factors
If device registration and authentication are required, then unauthorized access prevention is improved, but user convenience and access speed decrease
Solution Approach 1:
The patent implements preliminary device registration and authentication before actual tenant access. During the preliminary action phase, devices are registered with the cloud service and authentication information is established. Once registered, devices can access authorized tenants without repeated authentication, providing convenience while maintaining security. The preliminary action ensures unauthorized access is prevented before it can occur.
4Reliability
If tenant access is restricted to home tenant only, then data security and compliance are improved, but service functionality and versatility are reduced
Solution Approach 1:
The patent implements dynamic tenant access control that adapts to organizational policies. The system can dynamically determine which tenants a registered device is authorized to access based on configured policies. This dynamic approach allows strict home-tenant-only restriction for compliance-critical scenarios while enabling multi-tenant access when organizational policies permit, thus maintaining both security and versatility.
Data Source
AI summary
Allowing an entity managed device to access a tenant associated with the e on a public cloud service while preventing the device from accessing one or more other tenants on the cloud service. A method includes, at the cloud service, obtaining policy from the entity with respect to tenant access. The method further includes, at the cloud service, receiving a request from the entity managed device to access a tenant at the cloud service. The method further includes granting or denying the access request based on the policy obtained from the entity.


