Policy-Controlled Electronic Agent Access in Multi-Tenant Clouds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic agents pose security risks due to unrestricted use, leading to privacy issues, unauthorized access, and potential misuse, which can result in legal disputes, financial loss, and reputational damage for organizations.

Innovation Solution

A policy-controlled access security system for electronic agents in cloud-based multi-tenant systems, utilizing a client device, mid-link server, and web server, with AI devices, to enforce policies, manage tokens, and update privileges based on compliance, ensuring controlled access and alerting for non-compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If electronic agents are made freely accessible to employees, then ease of operation and productivity are improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improveaccessibility of electronic agentsVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A policy-controlled access security system acts as an intermediary between employees and electronic agents. The system includes a policy component that evaluates access requests against predefined policies, a token component that manages authentication tokens, and a compliance component that monitors AI device usage. This intermediary layer enables broad accessibility while maintaining security by filtering and controlling access based on organizational policies without restricting employee productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access control policies are strictly enforced, then security is improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

Access policies and security rules are predefined and configured in advance before employees need to access electronic agents. The policy component is pre-loaded with organizational security requirements, and the token component is pre-configured with authentication mechanisms. This preliminary setup allows the system to automatically evaluate and enforce security policies in real-time without requiring employees to manually configure security settings or undergo complex authentication processes, thus maintaining user convenience while ensuring strict security enforcement.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If monitoring and compliance checking are continuously performed, then reliability and security are improved, but use of energy and system complexity increase

Engineering Contradiction:
Improvecompliance monitoringVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The compliance component implements continuous monitoring of AI device usage by electronic agents and provides real-time feedback to the policy component. When the compliance component detects that an electronic agent is using an AI device in violation of organizational policies, it immediately feeds this information back to the policy component, which then triggers the token component to revoke access tokens and block further access. This feedback-based approach enables continuous reliability monitoring without requiring exhaustive analysis of all system operations, thereby reducing unnecessary energy consumption while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12413629B2Artificial intelligence (AI) devices control based on policies
Publication Date: 2025.09.09 NETSKOPE INC
  • US12413629B2 patent drawing
  • US12413629B2 patent drawing
  • US12413629B2 patent drawing

AI summary

A policy-controlled access security system for managing access security to electronic agents in cloud based multi-tenant systems includes a client device, a mid-link server, and a web server. A local application running on the client device requests access to an electronic agent of a remote application of the web server. Policies are determined for controlled access to the electronic agent. A token for the electronic agent is correlated with a plurality of tokens for identifying a user application associated with the token. The remote application is compared with the user application. A non-compliance of the set of policies is identified by determining enabling of one or more AI devices by the plurality of end users. The set of policies are modified based on the non-compliance and the functionality associated with the electronic agent and the plurality of privileges are updated for the end user based on the modified policies.