Granular SaaS Tenant Restriction via Sub-Application Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in implementing granular access control within Software-as-a-Service (SaaS) applications due to the loss of control over cloud-based resources, as existing solutions rely on global allow or block lists, failing to restrict access to specific sub-applications based on user identity, role, and location.

Innovation Solution

A cloud-based security system that enforces granular tenant restrictions by creating business process-specific sub-applications within SaaS platforms, using a Cloud Access Security Broker (CASB) to monitor and control access based on user profiles, rules, and location, allowing tailored access to specific sections of applications like Office 365, Box, Dropbox, and YouTube.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If global allow list or block list configuration is used, then implementation simplicity is improved, but access control granularity deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidaccess control granularity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent segments SaaS applications into sub-applications or functional modules (e.g., Gmail into compose, send, delete functions; Office 365 into specific apps and features). This segmentation enables granular access control where users can be granted access to specific sub-applications rather than entire applications, resolving the contradiction by providing fine-grained control without requiring complex global configuration for each individual control point.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different access control policies to different sub-applications within the same SaaS platform. Each sub-application can have its own access rules, user permissions, and security policies tailored to specific business needs, allowing organizations to grant access to certain functions while restricting others, thus achieving granular control without blanket restrictions.

Inventive Principle:
Principle #3Local quality

2Reliability

If IT admins have full control of access privileges, then security control is improved, but cloud service adaptability deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidcloud service adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where permissions and access rights can be adjusted in real-time based on user roles, device status, location, and security policies. The system dynamically evaluates access requests against defined policies and automatically grants or denies access without requiring manual IT admin intervention for each decision, thus maintaining security control while adapting to changing cloud service requirements and user needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary access control system that sits between users and cloud SaaS applications. This intermediary layer enforces security policies, monitors user activity, and manages access rights without requiring IT admins to directly control each application. The intermediary translates high-level security policies into granular access decisions, maintaining security control while enabling cloud service adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If blanket access control is implemented, then policy enforcement simplicity is improved, but user productivity deteriorates

Engineering Contradiction:
Improvepolicy enforcement simplicityVSAvoiduser productivity
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

By segmenting applications into sub-applications with distinct access controls, the system enables simple policy enforcement at the sub-application level while maintaining user productivity. Users gain access to all sub-applications necessary for their role without requiring complex approval processes, as the segmentation allows for role-based access that automatically grants appropriate permissions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal access control framework that applies across multiple SaaS applications and sub-applications. Once access policies are defined at the framework level, they are automatically enforced across all connected applications, providing simple policy enforcement through a single system that manages multiple applications, thereby maintaining both simplicity and productivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12041053B2Granular SaaS tenant restriction systems and methods
Publication Date: 2024.07.16 ZSCALER INC
  • US12041053B2 patent drawing
  • US12041053B2 patent drawing
  • US12041053B2 patent drawing

AI summary

Systems and methods include obtaining a profile for an application, wherein the profile includes one or more tenants, rules for use of the application by the one or more tenants, and users for the rules; monitoring a user of a tenant of the one or more tenants inline via a node in a cloud-based system; identifying an application of the one or more applications based on the monitoring and associated rules for the user; and enforcing the associated rules for the user for the application.