Hybrid-Cloud Authorization Validation for Multi-Tenant Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hybrid-cloud systems face security risks in multi-tenant environments where client devices can access data they are not permitted to access due to the inability of third-party authorization servers to validate requests accurately, leading to potential data breaches.

Innovation Solution

Implementing a trusted authorization server that checks the validity of requests from client devices before forwarding them to the third-party authorization server, ensuring access tokens are issued only to authorized devices by including tenant and organizational unit identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a third-party authorization server is used to issue access tokens in a multi-tenant environment, then the system can support multiple tenants and scale capacity, but client devices can access data they are not permitted to access due to inability to validate requests accurately

Engineering Contradiction:
Improvemulti-tenant supportVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted authorization server as an intermediary between client devices and the third-party authorization server. This mediator validates requests from client devices before forwarding them to the third-party server, ensuring that only authorized requests receive access tokens. The intermediary resolves the contradiction by maintaining multi-tenant support while adding a layer of security validation that prevents unauthorized data access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access tokens are issued without validating client device requests, then the authorization process is simple and fast, but data breaches can occur when client devices access unauthorized data

Engineering Contradiction:
Improveauthorization process simplicityVSAvoiddata breach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary validation of client device requests before access tokens are issued. The trusted authorization server checks whether client devices are permitted to access requested data items before forwarding requests to the third-party authorization server. This preliminary action prevents unauthorized access attempts from proceeding, resolving the contradiction by maintaining operational simplicity while eliminating data breach risks through advance validation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a trusted authorization server validates requests before forwarding to third-party server, then data security is enhanced, but the authorization process becomes more complex

Engineering Contradiction:
Improvedata securityVSAvoidauthorization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization process into distinct stages: request validation by the trusted authorization server, token issuance by the third-party server, and data access by client devices. This segmentation isolates the complexity of validation logic to a specific component while maintaining a clear, standardized interface with the third-party server. The segmentation resolves the contradiction by concentrating complexity in a manageable location while preserving overall system security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250260690A1Method for Controlling Secure Access to Data in a Hybrid-Cloud Environment
Publication Date: 2025.08.14 VARONIS SYSTEMS INC
  • US20250260690A1 patent drawing
  • US20250260690A1 patent drawing
  • US20250260690A1 patent drawing

AI summary

A method is provided for controlling secure access to data in hybrid-cloud environments. A trusted authorisation server controls access to data served by a resource server to client devices in an untrusted environment, to ensure client devices are only able to access data that they are permitted to access. In the present techniques, the trusted authorisation server checks the validity of data access requests received from client devices prior to any such requests being received by the resource server or an authorisation server associated with the resource server. This is advantageous because in many existing hybrid-cloud systems, the resource server and authorisation server are unable to check the individual validity of requests received from client devices. This is particularly problematic for multi-tenant resource servers. The present techniques provide a more secure way of controlling access to data stored and served by cloud-based, off-premises/third party resource servers.