Distributed CASB Worker Pool for Cloud File Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Cloud Access Security Broker (CASB) systems face inefficiencies and scalability issues when handling large-scale deployments in cloud environments, leading to latency and poor user experience due to the inability to properly scan all files.

Innovation Solution

A distributed CASB system employing a 'assembly line' approach with multiple workers operating in parallel through various queues, utilizing a message broker and controller to efficiently crawl and process files across cloud applications, perform actions based on policies, and integrate with cloud-based security systems, without permanent data storage or confidential credential storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional CASB systems are used to scan files in cloud applications, then security policy compliance is enforced, but the systems experience latency and inability to properly scan all files due to tremendous loads

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidfile scanning capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the monolithic CASB system into multiple worker processes that operate independently. Each worker handles specific file scanning tasks, allowing parallel processing of files across cloud applications. This segmentation enables the system to scan billions of files by distributing the load across multiple workers rather than overwhelming a single system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional approach by implementing a distributed architecture that adds spatial distribution across multiple workers and temporal distribution through asynchronous processing. This dimensional expansion allows the system to handle massive file volumes by processing files across multiple dimensions simultaneously rather than sequentially in a single system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If traditional CASB systems handle large-scale cloud deployments, then security monitoring is provided, but user experience deteriorates due to latency

Engineering Contradiction:
Improvesecurity monitoringVSAvoiduser experience latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous file scanning through an event-driven architecture that processes files as they are created, modified, or accessed in cloud applications. The system maintains continuous security monitoring without interrupting user workflows, as workers asynchronously process files and enforce policies in real-time rather than requiring batch processing or system pauses.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The distributed worker architecture enables self-service file scanning where each worker independently manages its own task queue and processing节奏. Workers automatically pick up new files from cloud applications and process them without central coordination overhead, reducing latency and improving user experience while maintaining continuous security monitoring.

Inventive Principle:
Principle #25Self-service

3Reliability

If CASB systems scan billions of files, then comprehensive security coverage is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal worker processes that can handle multiple cloud applications (Office 365, Dropbox, Box, Google Drive, Salesforce) through a common interface. Each worker is multi-functional, capable of scanning files across different cloud platforms and enforcing various security policies, which reduces overall system complexity by avoiding separate specialized systems for each cloud application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity through parameterized worker configurations that can be adjusted based on workload requirements. Workers can be dynamically instantiated, scaled, and configured with different policy sets and cloud application connections, allowing the system to adapt to billions of files without hardcoding complex logic for each scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11582261B2Cloud access security broker systems and methods via a distributed worker pool
Publication Date: 2023.02.14 ZSCALER INC
  • US11582261B2 patent drawing
  • US11582261B2 patent drawing
  • US11582261B2 patent drawing

AI summary

A Cloud Access Security Broker (CASB) system includes a controller; a message broker connected to the controller; and a plurality of workers connected to the message broker and connected to one or more cloud providers having a plurality of files contained therein for one or more tenants, wherein the plurality of workers are configured to crawl through the plurality of files for the one or more tenants, based on policy and configuration for the one or more tenants provided via the controller, and based on assignments from the message broker. The plurality of workers can be further configured to cause an action in the one or more cloud providers based on the crawl and based on the policy and the configuration. The action can include any of allowing a file, deleting a file, quarantining a file, and providing a notification.