Proxy Server Domain Attribution for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud environments, existing security measures fail to adequately protect network resources when access is requested from uncontrolled locations, suspect applications, or blocked devices, leading to potential data theft and loss due to the lack of real-time session monitoring and appropriate session policies.

Innovation Solution

A proxy server automatically attributes a domain with a cloud resource using statistical techniques to determine the most likely cloud application, applying pre-configured session policies such as blocking downloads or modifications to protect the resource, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is strengthened to protect cloud resources from uncontrolled locations and suspect applications, then security is improved, but user productivity deteriorates due to restricted access

Engineering Contradiction:
ImprovesecurityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a proxy server as an intermediary between users and cloud resources. This proxy server monitors and controls access requests, applying session policies to evaluate whether to permit or block access based on factors like location, application type, and device status. This intermediary approach enables security enforcement without completely blocking legitimate user access, thus resolving the contradiction between security and productivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes access parameters by evaluating multiple factors (user location, application type, device status, time of access) and adjusting session policies accordingly. Rather than applying fixed restrictive rules, the system modifies access parameters in real-time based on risk assessment, allowing legitimate access while blocking malicious attempts, thereby maintaining both security and productivity

Inventive Principle:
Principle #35Parameter changes

2Reliability

If domain attribution is performed manually to apply session policies, then security control is improved, but system complexity and time consumption worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The proxy server automatically performs domain attribution by monitoring user sessions and comparing accessed domains against known cloud resource domains. The system self-services the attribution process without requiring manual configuration or intervention, using automated algorithms to match domains and apply appropriate session policies. This automation reduces system complexity while maintaining security control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-establishes session policies for different cloud resources before actual access occurs. When a user accesses a domain, the proxy server has already prepared the appropriate security policies in advance, enabling rapid automatic attribution and policy application without real-time manual intervention. This preliminary preparation simplifies the system operation while ensuring security control

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If basic authentication is used for cloud resource access, then ease of operation is improved, but security deteriorates due to insufficient protection against unauthorized access

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security evaluations before granting access to cloud resources. The proxy server assesses multiple factors including user location, application type, device status, and time of access before permitting the session. This preliminary security check occurs transparently in the background, maintaining ease of operation for legitimate users while enhancing security by blocking unauthorized access attempts

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The proxy server acts as an intermediary authentication layer between basic login credentials and actual resource access. Even when users provide valid credentials, the proxy server intercepts and evaluates the access request against session policies. This intermediary mechanism maintains ease of operation for authenticated users while adding enhanced security layers to prevent unauthorized access from uncontrolled locations or suspect applications

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3994868B1Domain-application attribution
Publication Date: 2024.04.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3994868B1 patent drawingFigure 1
  • EP3994868B1 patent drawingFigure 2
  • EP3994868B1 patent drawingFigure 3

AI summary

A domain is automatically attributed to a cloud application hosted on a cloud service. The attribution of a domain with a cloud application is used to initiate session policies that protect the cloud applications. A security session monitors the operations performed by a user with a cloud application and applies session policies that are pre-configured automated actions used to protect a particular cloud application, such as blocking downloads, blocking modifications, etc.