Proxy Server Cookie Transformation for Cloud Access Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for cloud access security brokers (CASBs) lack granular controls over cloud application usage and cannot enforce access through a proxy server, failing to provide adequate security and compliance for enterprise data accessed using unmanaged devices.
Innovation Solution
A cloud-based method using a transparent proxy server as a man-in-the-middle for authentication and authorization, transforming cookies to enforce access controls, monitor for threats, and prevent data leakage, with the proxy server determining authentication based on cookie presence and transforming cookies using standard crypto algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If a proxy server is used to detect cloud application usage, then visibility of cloud application usage is improved, but granular control and enforcement of access policies cannot be achieved
Solution Approach 1:
The patent introduces a CASB (Cloud Access Security Broker) as an intermediary component positioned between users and cloud applications. This broker acts as a mediator that can intercept, inspect, and control traffic to cloud applications, enabling both visibility and granular policy enforcement. The broker implements identity brokerage to authenticate users and enforce security policies without requiring changes to the cloud applications themselves.
Solution Approach 2:
The patent segments the authentication and authorization process into distinct components: identity verification, cookie transformation, and policy enforcement. By separating these functions and implementing them as independent modules within the CASB architecture, the system achieves granular control over different aspects of cloud application access while maintaining overall visibility.
2Ease of operation
If direct access to cloud applications is allowed, then ease of access is improved, but security and compliance control over enterprise data is reduced
Solution Approach 1:
The CASB broker serves as a mandatory intermediary that all access requests must pass through. It transforms authentication cookies to route users through the broker while maintaining seamless user experience. This intermediary position enables the system to enforce security policies and maintain compliance control without preventing legitimate access to cloud applications.
Solution Approach 2:
The patent changes the state of authentication cookies through transformation processes. The broker modifies cookie parameters to encode security policies and routing information, enabling controlled access. This parameter transformation allows the system to maintain ease of access while embedding security controls within the authentication mechanism itself.
3Reliability
If cookie transformation is implemented to enforce access control, then security control is improved, but system complexity increases
Solution Approach 1:
The patent replaces complex mechanical authentication systems with cryptographic cookie transformation. Instead of implementing intricate access control mechanisms, the system uses cryptographic algorithms to transform cookies, which automatically enforce security policies. This substitution reduces operational complexity while maintaining strong access control enforcement.
Data Source
AI summary
A cloud-based method, a system, and a cloud-based security system include receiving a request from a user for a cloud application at a proxy server; determining whether the user is authenticated based on a presence of cookies in the request; if the cookies are present, un-transforming the cookies by the proxy server and forwarding the request with the un-transformed cookies to the cloud application; and, if the cookies are not present, forwarding the request to the cloud application by the proxy server for authentication and transforming the cookies subsequent to the authentication prior to sending the cookies to the user.


