Security Access Layer for Cloud Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing services pose a risk of unauthorized access to user data, as data is stored online and vulnerable to malicious activities, necessitating enhanced security measures to protect user data stored in Internet cloud facilities.
Innovation Solution
A security access layer is implemented between the user and cloud computing facilities, utilizing proxy access credentials, secure communication links, and identity verification to ensure compliance with security policies before allowing access to cloud services, thereby protecting user data from unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is stored in cloud computing facilities, then user flexibility and accessibility are improved, but security vulnerability increases
Solution Approach 1:
The patent introduces a security access layer as an intermediary component between the user's client device and the cloud computing facility. This intermediary layer performs authentication, authorization, and security policy enforcement before allowing access to cloud resources, thereby maintaining user flexibility while mitigating security vulnerabilities through controlled access points.
2Ease of operation
If access credentials are stored for multiple cloud facilities, then access convenience is improved, but security risk increases
Solution Approach 1:
The patent segments the authentication process into two distinct phases: initial authentication to the security access layer, and subsequent authentication to individual cloud facilities. Credentials are not stored for multiple cloud facilities but are instead verified dynamically through the security access layer, which maintains access convenience while reducing security risk by centralizing credential management.
3Reliability
If security access layer is added between user and cloud facility, then data protection is improved, but system complexity increases
Solution Approach 1:
The security access layer is implemented as a standalone intermediary service that handles all security-related operations. By centralizing authentication and authorization functions in this intermediary layer, the patent simplifies the overall system architecture compared to implementing security measures within each individual cloud facility, while still providing comprehensive data protection.
4Measurement precision
If client device security state is assessed, then access control accuracy is improved, but processing time increases
Solution Approach 1:
The patent performs security state assessment of the client device as a preliminary action before allowing access to cloud facilities. Security policies are evaluated and compliance determinations are made in advance, enabling faster subsequent access decisions. This preliminary assessment approach improves access control accuracy while minimizing the time impact during actual access requests.
Data Source
AI summary
In embodiments of the present invention improved capabilities are described for a method and system including storing a plurality of proxy access credentials for a user to securely access each of a plurality of cloud computing facilities; receiving a request from a client device for access to one of the plurality of cloud computing facilities; securing a communication link to the client device, thereby providing a secure link; receiving access credentials from the user through the secure link; verifying an identity of the user with the access credentials; assessing a security state of the client device to determine if the client is in compliance with a security policy; and if the client is in compliance with the security policy, coupling the client to one of the plurality of cloud computing facilities through a second secure link using a corresponding one of the plurality of proxy access credentials for the user.


