CSP Proxy Authentication for On-Premises Cloud Object Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in providing effective data protection services for limited access cloud data, as they lack the ability to authenticate and discover objects within on-premises cloud service providers, leading to inadequate backup and restoration capabilities.
Innovation Solution
A method and system that involve creating an authentication account in a CSP directory, instantiating a CSP proxy using authentication information, and associating users with the proxy to access and manage limited access cloud data, enabling data protection services through backup and restoration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then existing systems can maintain simple access control, but they cannot access limited access cloud data in on-premises CSP environments
Solution Approach 1:
The patent introduces a CSP proxy as an intermediary component that mediates between the data manager and the on-premises CSP. This proxy establishes authentication accounts in the CSP directory and manages authorized access to limited access cloud data, enabling the data protection system to operate within restricted on-premises environments without requiring changes to the core authentication infrastructure.
2Loss of information
If no CSP proxy is instantiated, then the system structure remains simple, but the data manager cannot discover or access cloud objects for backup
Solution Approach 1:
The system performs preliminary authentication setup by instantiating a CSP proxy and creating authentication accounts in the CSP directory before any data protection operations begin. This advance configuration enables the data manager to subsequently discover and access cloud objects without requiring complex real-time authentication mechanisms during backup operations.
3Reliability
If authentication information is not stored, then security risks are reduced, but the CSP proxy cannot access cloud data for protection services
Solution Approach 1:
The patent implements localized security by storing authentication information specifically within the on-premises CSP environment where it is needed, rather than centralizing it externally. The CSP proxy holds and manages this authentication information locally, enabling secure access to cloud data while minimizing security exposure by keeping credentials within the controlled on-premises boundary rather than transmitting them externally.
Data Source
AI summary
Techniques described herein relate to a method for performing data protection services for limited access cloud data. The method includes obtaining, by a data manager, an initial cloud service provider (CSP) proxy generation request from a user; in response to obtaining the initial (CSP) proxy generation request: creating an authentication account in a CSP directory based on the initial CSP proxy generation request; instantiating a CSP proxy in an on-premises CSP using authentication information associated with the authentication account; storing the authentication information; and associating the user with the authentication information and the CSP proxy, wherein after the associating the CSP proxy can access limited access cloud data and cloud resources of the on-premises CSP.


