Proxy Server Cookie Transformation for Cloud Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for cloud access security brokers (CASBs) lack granular controls over cloud application usage and cannot enforce access through a proxy server, failing to provide adequate security and compliance for enterprise data accessed using unmanaged devices.

Innovation Solution

A cloud-based method using a transparent proxy server as a man-in-the-middle for authentication and authorization, transforming cookies to enforce access controls, monitor for threats, and prevent data leakage, with the proxy server determining authentication based on cookie presence and transforming cookies using standard crypto algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If a proxy server is used to detect cloud application usage, then visibility of cloud application usage is improved, but granular control and enforcement of access policies cannot be achieved

Engineering Contradiction:
Improvevisibility of cloud application usageVSAvoidgranular control and enforcement of access policies
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent introduces a CASB (Cloud Access Security Broker) as an intermediary component positioned between users and cloud applications. This broker acts as a mediator that can intercept, inspect, and control traffic to cloud applications, enabling both visibility and granular policy enforcement. The broker implements identity brokerage to authenticate users and enforce security policies without requiring changes to the cloud applications themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication and authorization process into distinct components: identity verification, cookie transformation, and policy enforcement. By separating these functions and implementing them as independent modules within the CASB architecture, the system achieves granular control over different aspects of cloud application access while maintaining overall visibility.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If direct access to cloud applications is allowed, then ease of access is improved, but security and compliance control over enterprise data is reduced

Engineering Contradiction:
Improveaccess to cloud applicationsVSAvoidsecurity and compliance control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The CASB broker serves as a mandatory intermediary that all access requests must pass through. It transforms authentication cookies to route users through the broker while maintaining seamless user experience. This intermediary position enables the system to enforce security policies and maintain compliance control without preventing legitimate access to cloud applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of authentication cookies through transformation processes. The broker modifies cookie parameters to encode security policies and routing information, enabling controlled access. This parameter transformation allows the system to maintain ease of access while embedding security controls within the authentication mechanism itself.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If cookie transformation is implemented to enforce access control, then security control is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control enforcementVSAvoidcookie transformation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical authentication systems with cryptographic cookie transformation. Instead of implementing intricate access control mechanisms, the system uses cryptographic algorithms to transform cookies, which automatically enforce security policies. This substitution reduces operational complexity while maintaining strong access control enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9654507B2Cloud application control using man-in-the-middle identity brokerage
Publication Date: 2017.05.16 ZSCALER INC
  • US9654507B2 patent drawing
  • US9654507B2 patent drawing
  • US9654507B2 patent drawing

AI summary

A cloud-based method, a system, and a cloud-based security system include receiving a request from a user for a cloud application at a proxy server; determining whether the user is authenticated based on a presence of cookies in the request; if the cookies are present, un-transforming the cookies by the proxy server and forwarding the request with the un-transformed cookies to the cloud application; and, if the cookies are not present, forwarding the request to the cloud application by the proxy server for authentication and transforming the cookies subsequent to the authentication prior to sending the cookies to the user.