Web Cookie Message Transport for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud access security brokers (CASBs) often require complex technical architectures that can be cumbersome and invasive, failing to effectively communicate blockages to users and potentially impacting computing ecosystem efficiency.
Innovation Solution
A proxy server intercepts requests between a client computer and an application server, generating a response that includes a command to create a web cookie on the client with data for custom code components, allowing for agile and efficient communication of security messages without intrusive intervention in client-side/cloud application traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a CASB implements robust access control protocols and real-time reporting, then security control and visibility are improved, but device complexity increases
Solution Approach 1:
The patent introduces a proxy server as an intermediary component between the client and cloud application. This proxy server handles security policy enforcement, traffic monitoring, and message relay functions, thereby improving security control without requiring the entire CASB architecture to become more complex. The proxy server acts as a mediator that simplifies the overall system structure while maintaining robust security capabilities.
2Reliability
If a CASB blocks user activity to enforce security policies, then security control is improved, but loss of information occurs because users are not communicated the reasons for blockage
Solution Approach 1:
The patent implements a feedback mechanism where the proxy server captures blockage reasons generated by security policy enforcement, formats these reasons into user-friendly messages, and relays them back to the client. This feedback loop ensures that users receive clear explanations for why their activities were blocked, maintaining security control while preventing information loss about the blockage reasons.
3Loss of information
If a conventional proxying environment uses complex multi-channel communication schemes to communicate blockages, then communication completeness is improved, but productivity decreases due to resource impact
Solution Approach 1:
The patent makes the proxy server multi-functional by combining security policy enforcement, traffic interception, message generation, and communication relay into a single component. This universal approach allows the system to maintain complete communication of blockage reasons through a streamlined single-channel mechanism rather than requiring multiple communication channels, thereby preserving productivity while achieving communication completeness.
Data Source
AI summary
Embodiments described herein leverage web cookies to carry messages across cloud application communications, wherein the messages are between entities that are not part of the cloud application itself. For example, in embodiments, a proxy server is interconnected between a client computer that is executing a front-end component of an application and an application server that is executing a back-end component of the application. The proxy server intercepts a request from the front-end component that is intended for the back-end component and generates a response thereto that includes a command to create a web cookie at the client computer, wherein the web cookie includes data to be utilized by a custom code component of the client computer. The proxy server may further cause the custom code component to be injected into the application front-end component for execution by the client computer.


