Security Access Layer for Cloud Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing services pose a risk of unauthorized access to user data, as data is stored online and vulnerable to malicious activities, necessitating enhanced security measures to protect user data stored in Internet cloud facilities.

Innovation Solution

A security access layer is implemented between the user and cloud computing facilities, utilizing proxy access credentials, secure communication links, and identity verification to ensure compliance with security policies before allowing access to cloud services, thereby protecting user data from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in cloud computing facilities, then user flexibility and accessibility are improved, but security vulnerability increases

Engineering Contradiction:
Improveuser flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security access layer as an intermediary component between the user's client device and the cloud computing facility. This intermediary layer performs authentication, authorization, and security policy enforcement before allowing access to cloud resources, thereby maintaining user flexibility while mitigating security vulnerabilities through controlled access points.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access credentials are stored for multiple cloud facilities, then access convenience is improved, but security risk increases

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into two distinct phases: initial authentication to the security access layer, and subsequent authentication to individual cloud facilities. Credentials are not stored for multiple cloud facilities but are instead verified dynamically through the security access layer, which maintains access convenience while reducing security risk by centralizing credential management.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security access layer is added between user and cloud facility, then data protection is improved, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security access layer is implemented as a standalone intermediary service that handles all security-related operations. By centralizing authentication and authorization functions in this intermediary layer, the patent simplifies the overall system architecture compared to implementing security measures within each individual cloud facility, while still providing comprehensive data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If client device security state is assessed, then access control accuracy is improved, but processing time increases

Engineering Contradiction:
Improveaccess control accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs security state assessment of the client device as a preliminary action before allowing access to cloud facilities. Security policies are evaluated and compliance determinations are made in advance, enabling faster subsequent access decisions. This preliminary assessment approach improves access control accuracy while minimizing the time impact during actual access requests.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8713633B2Security access protection for user data stored in a cloud computing facility
Publication Date: 2014.04.29 SOPHOS LTD
  • US8713633B2 patent drawing
  • US8713633B2 patent drawing
  • US8713633B2 patent drawing

AI summary

In embodiments of the present invention improved capabilities are described for a method and system including storing a plurality of proxy access credentials for a user to securely access each of a plurality of cloud computing facilities; receiving a request from a client device for access to one of the plurality of cloud computing facilities; securing a communication link to the client device, thereby providing a secure link; receiving access credentials from the user through the secure link; verifying an identity of the user with the access credentials; assessing a security state of the client device to determine if the client is in compliance with a security policy; and if the client is in compliance with the security policy, coupling the client to one of the plurality of cloud computing facilities through a second secure link using a corresponding one of the plurality of proxy access credentials for the user.