Identity Intelligence in Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased use of cloud services and remote work has expanded enterprise attack surfaces, leading to security risks due to misconfigured Identity as a Service (IDaaS) solutions, which struggle with latency in notification and low Signal-to-Noise ratio in logs, making it difficult to detect anomalous behavior and providing weak defense mechanisms, as Identity Providers lack visibility into user activities during cloud service sessions.

Innovation Solution

The system continuously monitors user activity in cloud services, gathering a baseline to detect anomalous behavior and notify Identity Providers for remediation, such as disabling accounts or requiring password changes, while users are accessing the service, using contextual connectors to enrich data and create dynamic risk-based profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IDaaS solutions are used for authentication, then user access to cloud services is enabled, but security detection capability and real-time monitoring are insufficient

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidmonitoring and detection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges cloud service monitoring capabilities with IDaaS authentication systems by integrating a monitoring system that collects user activity data from cloud services and feeds it back to the IDP for continuous authentication decisions. This combination enables security monitoring to be built into the existing authentication infrastructure rather than adding separate complex systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback by continuously monitoring user activity in cloud services and using this information to update authentication decisions in real-time. The monitoring system collects data about user behavior patterns and feeds this back to the IDP, which then adjusts authentication requirements based on detected anomalies or changes in behavior.

Inventive Principle:
Principle #23Feedback

2Reliability

If continuous monitoring of user activity is implemented, then real-time security detection is improved, but system latency in notification increases

Engineering Contradiction:
Improvereal-time security detectionVSAvoidnotification latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing baseline user behavior patterns during normal operation and pre-configuring security policies and response actions. When anomalies are detected, the system can immediately execute pre-planned responses without delay, as the detection criteria and remediation steps are already established before the incident occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system dynamically adjusts its monitoring intensity and notification thresholds based on current user behavior patterns and risk assessments. By continuously learning from user activity and adapting baseline expectations, the system can detect anomalies more quickly without generating excessive false positives that would cause notification delays.

Inventive Principle:
Principle #15Dynamics

3Loss of information

If Identity Providers are given access to cloud service activity data, then contextual awareness is improved, but data privacy and security risks increase

Engineering Contradiction:
Improvecontextual awarenessVSAvoiddata privacy risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system extracts only the necessary security-relevant information from cloud service activity logs and transmits minimal data to the IDP for authentication decisions. Rather than sharing complete user activity datasets, the system extracts specific anomaly indicators and behavior patterns that are sufficient for security monitoring while leaving sensitive personal information local to the cloud service providers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a monitoring system as an intermediary between cloud services and IDPs. This intermediary layer collects, processes, and filters activity data before sharing with the IDP, enabling contextual awareness while maintaining data privacy through centralized security processing and selective data sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If traditional perimeter-based security is used, then network defense is simplified, but attack surface expansion due to cloud and remote work increases

Engineering Contradiction:
Improvesecurity architecture complexityVSAvoidattack surface
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system transitions from static perimeter-based security to dynamic identity-based security that adapts to user location, device, and behavior context. Authentication and access controls dynamically adjust based on real-time monitoring of user activity, enabling the security system to respond to changing threat conditions without requiring complex architectural reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230129466A1Identity intelligence in cloud-based services
Publication Date: 2023.04.27 ZSCALER INC
  • US20230129466A1 patent drawing
  • US20230129466A1 patent drawing
  • US20230129466A1 patent drawing

AI summary

The present disclosure relates to systems and methods for tying activity of a user or group in a cloud service with an identity provider (IDP). This intelligence from the cloud service can be used to continuously authenticate a user or group as they are using the cloud service, thus confirming authentication beyond the initial identity (ID) determination or login process. By gathering a baseline for the access of users and groups, it is possible to detect when a user or user device shows anomalous behavior. Responsive to detecting anomalous behavior, the IDP can be notified, and remediation can be quickly initiated with the utilization of security measures such as access denial, account disabling, requiring a user to change a password, and/or other actions of the like. Such security actions may be preset in a playbook built for response to various security risks.