×

Apparatus, method and system for context-aware security control in cloud environment

  • US 9,294,463 B2
  • Filed: 08/23/2014
  • Issued: 03/22/2016
  • Est. Priority Date: 02/20/2014
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus for context-aware security control in a cloud environment, the apparatus, communicated with one or more terminals and at least one server via a cloud network, comprising at least one computer processor, a communications interface, and a non-transitory computer-readable medium bearing algorithm arranged for causing the computer processor to perform:

  • an authentication header inspector which generates an authentication header based on context information and a key transmitted from a first user terminal, and compares the generated authentication header with an authentication header of packet data received from a second user terminal; and

    a packet data processor, communicated between a cloud server and the first and the second user terminals via a cloud service network, configured at an entrance of the cloud service network based on in-line mode, and configured to selectively perform one of transmission, modulation and discarding of packet data transmitted from the cloud server in response to determination of the comparison of the generated authentication header with an authentication header of packet data received from the second user terminal transmitted to the cloud server,wherein the packet data processor performs modulation among transmission, modulation and discarding of the packet data, and the packet data processor modulates the packet data received from the cloud server and then transmits the modulated packet data to the second user terminal,wherein the generated authentication header and the authentication header of the packet data received from the second user terminal are generated using a hash-based message authentication code (HMAC) function, andwherein the context information of the user comprises location information, and the location information is provided in such a way that a single unique value is mapped to a specific Global Positioning System (GPS) range block.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×