Local Host Interface for Dual Endpoint Cloud Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud storage security policies are cumbersome for users to configure effectively, leading to misconfigurations and potential data leakages, as users struggle with managing access controls across different cloud service providers.

Innovation Solution

A dual endpoint access control system that enables local host management of cloud-stored resource security, using a local host interface to enforce access policies and send individualized access requests to remote servers, thereby offloading access policy management from the cloud end.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex access control policies are implemented in cloud storage, then security protection is improved, but configuration difficulty and risk of misconfiguration increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess control configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a local host interface as an intermediary between the end-user entity and the remote cloud server. This interface mediates all access requests by first evaluating local access policies before forwarding to the cloud server, which evaluates remote access policies. This intermediary layer simplifies the overall system by distributing policy evaluation across multiple locations, making each individual policy easier to manage and less prone to misconfiguration while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access control policies are centralized at cloud server, then security management is simplified, but data privacy and local control are reduced

Engineering Contradiction:
Improvesecurity managementVSAvoiddata privacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the access control system into two distinct parts: a local host interface that handles local access policies and data privacy, and a remote cloud server that handles remote access policies. This segmentation allows each component to operate independently with its own policy evaluation logic, enabling centralized security management while preserving local data privacy and control. The local interface retains information about local access decisions, preventing loss of privacy-sensitive data.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple cloud service providers are used, then service versatility is improved, but access control consistency and security uniformity deteriorate

Engineering Contradiction:
Improvecloud service provider optionsVSAvoidaccess control consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a universal access control framework where the local host interface serves multiple functions: it evaluates local access policies, encrypts data locally, and forwards requests to various cloud servers. This universal interface can work with different cloud service providers (AWS, Azure, Google Cloud, etc.) while maintaining consistent security practices. The standardized local interface ensures uniform access control behavior across different cloud providers, resolving the inconsistency problem while preserving service versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250126130A1System and method for providing dual endpoint access control of remote cloud-stored resources
Publication Date: 2025.04.17 THALES DIS CPL USA INC
  • US20250126130A1 patent drawing
  • US20250126130A1 patent drawing

AI summary

A system for providing dual endpoint access control of remote cloud-stored resources that includes at least one end-user entity running at least one application, the at least one application being adapted to perform at least one operation to at least one cloud-stored resource; and a local host interface configured to control access to the remote cloud-stored resources over a communication network by the at least one end-user entity running the at least one application, wherein the local host interface comprises a first access policy relating a set of authorized operations with at least one access permission to one or more of the of cloud-stored resources. Other aspects are described herein.