Identity Intelligence in Cloud Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increased use of cloud services and remote work has expanded enterprise attack surfaces, leading to security risks due to misconfigured Identity as a Service (IDaaS) solutions, which struggle with latency in notification and low Signal-to-Noise ratio in logs, making it difficult to detect anomalous behavior and providing weak defense mechanisms, as Identity Providers lack visibility into user activities during cloud service sessions.
Innovation Solution
The system continuously monitors user activity in cloud services, gathering a baseline to detect anomalous behavior and notify Identity Providers for remediation, such as disabling accounts or requiring password changes, while users are accessing the service, using contextual connectors to enrich data and create dynamic risk-based profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IDaaS solutions are used for authentication, then user access to cloud services is enabled, but security detection capability and real-time monitoring are insufficient
Solution Approach 1:
The patent merges cloud service monitoring capabilities with IDaaS authentication systems by integrating a monitoring system that collects user activity data from cloud services and feeds it back to the IDP for continuous authentication decisions. This combination enables security monitoring to be built into the existing authentication infrastructure rather than adding separate complex systems.
Solution Approach 2:
The system implements feedback by continuously monitoring user activity in cloud services and using this information to update authentication decisions in real-time. The monitoring system collects data about user behavior patterns and feeds this back to the IDP, which then adjusts authentication requirements based on detected anomalies or changes in behavior.
2Reliability
If continuous monitoring of user activity is implemented, then real-time security detection is improved, but system latency in notification increases
Solution Approach 1:
The system performs preliminary actions by establishing baseline user behavior patterns during normal operation and pre-configuring security policies and response actions. When anomalies are detected, the system can immediately execute pre-planned responses without delay, as the detection criteria and remediation steps are already established before the incident occurs.
Solution Approach 2:
The monitoring system dynamically adjusts its monitoring intensity and notification thresholds based on current user behavior patterns and risk assessments. By continuously learning from user activity and adapting baseline expectations, the system can detect anomalies more quickly without generating excessive false positives that would cause notification delays.
3Loss of information
If Identity Providers are given access to cloud service activity data, then contextual awareness is improved, but data privacy and security risks increase
Solution Approach 1:
The system extracts only the necessary security-relevant information from cloud service activity logs and transmits minimal data to the IDP for authentication decisions. Rather than sharing complete user activity datasets, the system extracts specific anomaly indicators and behavior patterns that are sufficient for security monitoring while leaving sensitive personal information local to the cloud service providers.
Solution Approach 2:
The patent introduces a monitoring system as an intermediary between cloud services and IDPs. This intermediary layer collects, processes, and filters activity data before sharing with the IDP, enabling contextual awareness while maintaining data privacy through centralized security processing and selective data sharing.
4Device complexity
If traditional perimeter-based security is used, then network defense is simplified, but attack surface expansion due to cloud and remote work increases
Solution Approach 1:
The system transitions from static perimeter-based security to dynamic identity-based security that adapts to user location, device, and behavior context. Authentication and access controls dynamically adjust based on real-time monitoring of user activity, enabling the security system to respond to changing threat conditions without requiring complex architectural reconfiguration.
Data Source
AI summary
The present disclosure relates to systems and methods for tying activity of a user or group in a cloud service with an identity provider (IDP). This intelligence from the cloud service can be used to continuously authenticate a user or group as they are using the cloud service, thus confirming authentication beyond the initial identity (ID) determination or login process. By gathering a baseline for the access of users and groups, it is possible to detect when a user or user device shows anomalous behavior. Responsive to detecting anomalous behavior, the IDP can be notified, and remediation can be quickly initiated with the utilization of security measures such as access denial, account disabling, requiring a user to change a password, and/or other actions of the like. Such security actions may be preset in a playbook built for response to various security risks.


