IP Library Granted Patent US 10,154,007
Granted Patent B1
US 10,154,007 · App. 14/705,824 · Granted Dec 11, 2018

Enterprise cloud access control and network access control policy using risk based blocking

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,154,007
App. No.
14/705,824
Granted
Dec 11, 2018
Kind
B1
Abstract

A cloud access control server and method provides a cloud service access control database to implement cloud services access control policy. The cloud service access control database stores thereon cloud service identifiers associated with cloud service providers having high risk scores. In some embodiments, the cloud service identifiers form a block list of cloud services which is provided to network device of the enterprise data network to implement cloud service access control. In other embodiments, a cloud access control server and method implements cloud services access control policy for an enterprise. The cloud access control server and method receives network traffic data from the installed firewall or proxy at the enterprise and process the network traffic data with respect to cloud service access. The cloud access control server provides instructions to the firewall or proxy to allow or deny the network access at the enterprise.

Claims (21)

1. A method of implementing cloud service access control in a network device associated with an enterprise data network, comprising:

receiving, by a cloud access control server that includes a hardware processor and that is outside of the enterprise data network, on a periodic basis, information relating to a plurality of cloud service providers and risk scores indicative of risk associated with the plurality of cloud service providers;

storing, at a cloud service access control database associated with the cloud access control server, a first cloud service block list, the first cloud service block list comprising first cloud service identifiers associated with a first set of two or more of the plurality of cloud service providers, wherein the risk scores of the first set of two or more of the plurality of cloud service providers are above a given threshold;

providing the first cloud service block list to the network device of the enterprise data network, the network device applying the first cloud service block list to allow or deny network traffic between the enterprise data network and at least one of the first set of two or more of the plurality of cloud service providers; and

storing a second cloud service block list, the second cloud service block list comprising second cloud service identifiers associated with a second set of two or more of the plurality of cloud service providers,

wherein storing, at the cloud service access control database associated with the cloud access control server, the first cloud service block list comprises storing universal resource locators (URLs) of the first set of two or more of the plurality of cloud service providers as the cloud service identifiers associated with the first set of two or more of the plurality of cloud service providers having the risk scores above the given threshold, and

wherein the first set of two or more of the plurality of cloud service providers and the second set of two or more of the plurality of cloud service providers belong to different service categories.

2. The method of claim 1 , wherein providing the first cloud service block list to the network device of the enterprise data network comprises providing the first cloud service block list to a web proxy, a proxy server or a gateway of the enterprise data network.

3. The method of claim 1 , further comprising:

receiving a request for the first cloud service block list from the network device of the enterprise data network; and

in response to the request from the network device, providing the first cloud service block list to the network device of the enterprise data network.

4. The method of claim 1 , further comprising:

in response to receiving the information relating to the plurality of cloud service providers and the risk scores indicative of risk associated with the plurality of cloud service providers, evaluating the risk scores to assess which of the risk scores of the plurality of cloud service providers are above the given threshold.

5. A system for providing cloud service access control to a network device of an enterprise data network, comprising:

a cloud access control server that includes a hardware processor and that is configured outside of the enterprise data network, the cloud access control server being configured to receive information relating to a plurality of cloud service providers and risk scores indicative of risk associated with the plurality of cloud service providers, to store in a cloud service access control database a first cloud service block list, the first cloud service block list comprising first cloud service identifiers associated with a first set of two or more of the plurality of cloud service providers, wherein the risk scores of the first set of two or more of the plurality of cloud service providers are above a given threshold, and to provide the first cloud service block list to the network device of the enterprise data network, wherein the network device applies the first cloud service block list to allow or deny network traffic between the enterprise data network and at least one of the first set of two or more of the plurality of cloud service providers,

wherein the cloud service identifiers in the first cloud service block list comprise universal resource locators (URLs) of the first set of two or more of the plurality of cloud service providers,

wherein the cloud access control server is further configured to store in a cloud service access control database a second cloud service block list including second cloud service identifiers associated with a second set of two or more of the plurality of cloud service providers, and

wherein the first set of two or more of the plurality of cloud service providers and the second set of two or more of the plurality of cloud service providers belong to different service categories.

6. The system of claim 5 , wherein the network device of the enterprise data network comprises a web proxy, a proxy server or a gateway of the enterprise data network.

7. The system of claim 5 , wherein the cloud access control server is further configured to receive a request for the first cloud service block list from the network device of the enterprise data network and to provide the first cloud service block list to the network device of the enterprise data network in response to the request from the network device.

8. The system of claim 5 , wherein the cloud access control server is further configured to evaluate the risk scores to assess which of the risk scores of the plurality of cloud service providers are above the given threshold in response to receiving the information relating to the plurality of cloud service providers and the risk scores indicative of risk associated with the plurality of cloud service providers.

Assignments (16)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 27, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 047985/0887 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2015
From: VISWANATHAN, SURENDRAKUMAR; NARAYAN, KAUSHIK; TARANIGANTY, RAMA
To: SKYHIGH NETWORKS, INC.
Reel/Frame 036062/0235 →
Cited By (5)
US 12,301,632 US 12,309,152 US 12,531,850 US 12,563,040 US 12,695,789