IP Library Patent Application 16215199
Patent Application
App. No. 16/215,199

ENTERPRISE CLOUD ACCESS CONTROL AND NETWORK ACCESS CONTROL POLICY USING RISK BASED BLOCKING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/215,199
Abstract

A cloud access control server and method provides a cloud service access control database to implement cloud services access control policy. The cloud service access control database stores thereon cloud service identifiers associated with cloud service providers having high risk scores. In some embodiments, the cloud service identifiers form a block list of cloud services which is provided to network device of the enterprise data network to implement cloud service access control. In other embodiments, a cloud access control server and method implements cloud services access control policy for an enterprise. The cloud access control server and method receives network traffic data from the installed firewall or proxy at the enterprise and process the network traffic data with respect to cloud service access. The cloud access control server provides instructions to the firewall or proxy to allow or deny the network access at the enterprise.

Claims (17)

1 . A method of providing cloud service access control to a network device of an enterprise data network, the method comprising:

receiving, at a cloud access control server configured outside of the enterprise data network, a request message including a request for resource or a response to a request for resource received at the network device and destined for or originated from a cloud service, the cloud service being configured outside of the enterprise data network;

extracting, at the cloud access control server, information from the request message relating to a destination of the request for resource or an origin of the response to the request for resource;

applying one or more access control policies to the request for resource or the response to the request for resource;

generating a policy enforcement result in response to the application of the one or more access control policies to the request for resource or the response to the request for resource, the policy enforcement result comprising an instruction to allow or deny the request for resource or the response to the request for resource; and

providing the policy enforcement result to the network device.

2 . The method of claim 1 , wherein receiving, at the cloud access control server configured outside of the enterprise data network, the request message including the request for resource or the response to the request for resource received at the network device and destined for the cloud service comprises:

receiving an ICAP request message encapsulating the request for resource or the response to the request for resource in the ICAP request message body.

3 . The method of claim 1 , wherein generating the policy enforcement result in response to the application of the one or more access control policies to the request for resource or the response to the request for resource further comprises:

generating the policy enforcement result comprising an instruction to allow or deny the request for resource or the response to the request for resource based on the direction of network traffic or the cloud service usage rate.

4 . A system for providing cloud service access control to a network device of an enterprise data network, comprising:

a cloud access control server configured outside of the enterprise data network and configured to receive a request message including a request for resource or a response to the request for resource received at the network device and destined for or originating from a cloud service, the cloud service being configured outside of the enterprise data network, the cloud access control server comprising:

a message server configured to receive the request message and to extract information from the request message relating to a destination of the request for resource or an origin of the response to the request for resource; and

a policy engine configured to apply one or more access control policies to the request for resource or the response to the request for resource and to generate a policy enforcement result in response to the application of the one or more access control policies to the request for resource or the response to the request for resource, the policy enforcement result comprising an instruction to allow or deny the request for resource or the response to the request for resource,

wherein the cloud access control server provides the policy enforcement result to the network device.

5 . The system of claim 4 , wherein the cloud access control server is configured to receive an ICAP request message as the request message, the ICAP request message encapsulating the request for resource or the response to the request for resource in the ICAP request message body.

6 . The system of claim 4 , wherein the policy engine is further configured to generate a policy enforcement result comprising an instruction to allow or deny the request for resource or the response to the request for resource based on the direction of network traffic or the cloud service usage rate.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
CHANGE OF NAME Recorded Jun 1, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 060247/0079 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2022
From: VISWANATHAN, SURENDRAKUMAR; NARAYAN, KAUSHIK; TARANIGANTY, RAMA
To: SKYHIGH NETWORKS, INC.
Reel/Frame 059759/0987 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
CHANGE OF NAME Recorded Dec 11, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 047787/0980 →