Centralized Identity Redistribution

The centralized identity redistribution system addresses scalability and consistency issues in SD-WAN environments by using a cloud-based user identity broker for unified user context distribution, ensuring efficient and real-time security policy enforcement across various security platforms.

JP2025527093APending Publication Date: 2025-08-20PALO ALTO NETWORKS INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024570639
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-14
Filing Date
2023-11-10
Publication Date
2025-08-20

AI Technical Summary

Technical Problem

Existing security architectures face challenges in scalable and centralized user context redistribution, particularly in SD-WAN environments, leading to inconsistent security policy enforcement and inefficient traffic inspection, with a need for real-time and extensible identity context redistribution.

Method used

A system and method for centralized identity redistribution that includes receiving user context information from a cloud security service and applying security policies using IP-user, user-tag, IP-tag, IP-port-user, and IP-device ID mappings, with a cloud-based user identity broker service facilitating segment-based flow control and unified user context distribution across security platforms.

Benefits of technology

Enables real-time, scalable, and extensible user context redistribution, ensuring consistent security policy enforcement and reducing CPU/memory usage on security platforms by leveraging cloud resources for unified user context management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025527093000001_ABST
    Figure 2025527093000001_ABST
Patent Text Reader

Abstract

Techniques for providing centralized identity redistribution for security services are disclosed. In some embodiments, a system / process / computer program product for providing centralized identity redistribution for security services includes receiving, at a security platform, user context information (e.g., IP-user mapping, user-tag mapping, IP-tag mapping, IP-port-user mapping, IP-device ID mapping, 5G user context information, and / or other user context information / data) from a cloud security service, and applying, at the security platform, a security policy using the user context information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a system and method for synchronizing honey network configurations to reflect a target network environment. [Background technology]

[0002] A firewall generally allows authorized communications to pass through the firewall while protecting a network from unauthorized access. A firewall is typically a device, set of devices, or software running on devices that provides firewall functionality for network access. For example, a firewall may be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of network-enabled device). A firewall may also be integrated into or run as one or more software applications on various types of devices, such as computer servers, gateways, network / routing devices (e.g., network routers), and data appliances (e.g., security appliances or other types of dedicated devices).

[0003] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies. For example, a firewall can filter inbound traffic by applying a set of rules or policies. A firewall can also filter outbound traffic by applying a set of rules or policies. A firewall can also perform basic routing functions.

[0004] According to its Abstract, U.S. Patent Application Publication No. 2022 / 070223 A1 describes techniques for a security platform with external inline processing of assembled and selected traffic. In some embodiments, a system / method / computer program product for providing a security platform with external inline processing of assembled and selected traffic includes: monitoring network traffic of a session at the security platform; selecting a subset of the monitored network traffic associated with the session to send to a cloud-based security service for analysis based on a security policy, the selected subset of the monitored network traffic being proxied to the cloud-based security service; receiving results of the security policy-based analysis from the cloud-based security service; and performing a response action based on the results of the security policy-based analysis.

[0005] EP 3993331 A1, according to its Abstract, describes techniques for providing flow metadata exchange between a network and a security function for a security service. In some embodiments, a system / process / computer program product for providing flow metadata exchange between a network function and a security function for a security service includes receiving a flow at a network gateway of a security service from a Software Defined Wide Area Network (SD-WAN) device, inspecting the flow to determine meta information associated with the flow, and communicating the meta information associated with the flow to the SD-WAN device.

[0006] According to its Abstract, U.S. Patent Application Publication No. 2019 / 0089678 A1 describes a technique for outbound / inbound lateral traffic punting based on process risk. In some embodiments, a system / process / computer program product for process risk-based outbound / inbound lateral traffic punting includes: receiving, at a network device on an enterprise network, process identification (ID) information from an endpoint (EP) agent running on the EP device, the process ID information identifying a process associated with an outbound or inbound network session on the EP device in the enterprise network; selecting the network session for punting to the network device for inspection; monitoring network communications associated with the network session at the network device to identify an application identification (APP ID) of the network session; and performing an action based on a security policy using the process ID information and the APP ID. Summary of the Invention

[0007] According to one aspect, a system is provided, comprising: a processor configured to receive, at a security platform, user context information from a cloud security service and apply, at the security platform, a security policy using the user context information; and a memory coupled to the processor and configured to provide instructions to the processor.

[0008] In one embodiment, the security platform includes a physical firewall, a virtual machine firewall, or a container-based firewall.

[0009] In an optional embodiment, the user context information includes at least one of an IP-user mapping, a user-tag mapping, an IP-tag mapping, an IP-port-user mapping, and an IP-device ID mapping.

[0010] In one embodiment, the security platform subscribes to a segment for centralized identity redistribution.

[0011] According to another aspect, a method is provided that includes receiving, at a security platform, user context information from a cloud security service, and applying, at the security platform, a security policy using the user context information.

[0012] In one embodiment, the security platform includes a physical firewall, a virtual machine firewall, or a container-based firewall.

[0013] In an optional embodiment, the user context information includes at least one of an IP-user mapping, a user-tag mapping, an IP-tag mapping, an IP-port-user mapping, and an IP-device ID mapping.

[0014] In one embodiment, the security platform subscribes to a segment for centralized identity redistribution.

[0015] According to another aspect, there is provided a computer program product embodied in a tangible computer-readable storage medium and comprising computer instructions for performing the methods defined herein.

[0016] According to another aspect, a processor-implemented method is provided, the method including generating user context information at an authenticated security platform and / or obtaining user context information from one or more sources at the security platform, and transmitting the user context information to a cloud security service. It will be apparent that this method may be implemented in the same system as described above.

[0017] In one embodiment, the security platform is an edge device in an SD-WAN network, the edge device configured to function as an access point and / or an exit point for the SD-WAN network, and the edge device further configured to connect to the cloud security service via an IPsec tunnel.

[0018] In one embodiment, the security platform includes a physical firewall, a virtual machine firewall, or a container-based firewall.

[0019] In one embodiment, the security platform publishes to a segment for centralized identity redistribution, where preferably the segment is a grouping of security platforms or firewalls.

[0020] According to yet another aspect, a system is provided, comprising: a processor, at a cloud security service, configured to receive user context information from a security platform and store the user context information in a data store of the cloud security service for redistribution of the user context information to another security platform; and a memory, coupled to the processor and configured to provide instructions to the processor.

[0021] In one embodiment, the user context information includes at least one of an IP-user mapping, a user-tag mapping, an IP-tag mapping, an IP-port-user mapping, and an IP-device ID mapping.

[0022] In one embodiment, another security platform subscribes to a segment for centralized identity redistribution to receive the user context information from the cloud security service, and the cloud security service publishes the user context information to the other security platform.

[0023] According to another aspect, there is provided an assembly including the system defined herein.

[0024] According to another aspect, a method is provided that includes receiving, at a security platform, user context information from a cloud security service, and storing the user context information in a data store of the cloud security service for redistribution of the user context information to another security platform.

[0025] According to another aspect, there is provided a computer program product embodied in a tangible computer-readable storage medium and comprising computer instructions for performing the methods defined herein. [Brief explanation of the drawings]

[0026] Various embodiments of the present invention are disclosed in the following detailed description and accompanying drawings. [Figure 1A] FIG. 1A is a diagram of a system environment including an exemplary SD-WAN architecture and security services, according to some embodiments. [Figure 1B] FIG. 1B is a diagram of a system environment including an exemplary SD-WAN architecture and security services, according to some embodiments. [Figure 2] FIG. 2 is a cloud user context architecture for centralized identity redistribution for security services, according to some embodiments. [Figure 3A] FIG. 3A illustrates an architecture overview of user context information grouped into segments and shared to provide centralized identity redistribution for security services, according to some embodiments. [Figure 3B] FIG. 3B illustrates another architecture overview of user context information grouped into segments and shared to provide centralized identity redistribution for security services, according to some embodiments. [Figure 3C] FIG. 3C illustrates an architecture for a firewall daemon to provide centralized identity redistribution for security services, according to some embodiments. [Figure 3D] FIG. 3D illustrates an architecture for IP-user mapping that can be uploaded and downloaded to the cloud to provide centralized identity redistribution for security services, according to some embodiments. [Figure 3E] FIG. 3E illustrates an IP user mapping workflow for providing centralized identity redistribution for security services, according to some embodiments. [Figure 3F] FIG. 3F illustrates an architecture for IP tag mapping that can be uploaded and downloaded to the cloud to provide centralized identity redistribution for security services, according to some embodiments. [Figure 3G] FIG. 3G illustrates an architecture for using segments to provide centralized identity redistribution for security services, according to some embodiments. [Figure 3H] FIG. 3H illustrates a cloud-based user ID component architecture for providing centralized identity redistribution for security services, according to some embodiments. [Figure 4A] FIG. 4A illustrates an embodiment of a network gateway, according to some embodiments. [Figure 4B] FIG. 4B is a functional diagram of the logical components of an embodiment of a data appliance. [Figure 5] FIG. 5 is a flow chart illustrating a process for providing centralized identity redistribution for security services, according to some embodiments. [Figure 6] FIG. 6 is another flow chart illustrating a process for providing centralized identity redistribution for security services, according to some embodiments. [Figure 7] FIG. 7 is another flow diagram illustrating a process for providing centralized identity redistribution for security services, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0027] The present invention can be implemented in numerous ways, including as a process, an apparatus, a system, a composition of matter, a computer program product embodied on a computer-readable storage medium, and / or a processor, such as instructions stored on a memory and / or a processor configured to execute instructions stored and / or provided by a memory coupled to the processor. These implementations, or any other form the present invention may take, may be referred to herein as techniques. In general, the order of steps in disclosed processes may be varied within the scope of the present invention. Unless otherwise specified, components, such as a processor or memory, described as configured to perform a task may be implemented as general-purpose components temporarily configured to perform the task at a given time, or as specific components manufactured to perform the task. As used herein, the term “processor” refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.

[0028] A detailed description of one or more embodiments of the present invention is provided below along with accompanying figures that illustrate the principles of the invention. While the present invention will be described in connection with such embodiments, the present invention is not limited to any embodiment. The scope of the present invention is limited only by the claims, and the present invention encompasses numerous alternatives, modifications, and equivalents. Numerous specific details are set forth in the following description to provide a thorough understanding of the present invention. These details are provided for the purpose of example, and the present invention may be practiced according to the claims without some or all of these specific details. For purposes of clarity, technical material known in the art related to the present invention has not been described in detail so as not to unnecessarily obscure the present invention.

[0029] Advanced or Next-Generation Firewalls

[0030] Malware is a general term commonly used to refer to malicious software (e.g., including various hostile, intrusive, and / or other unwanted software). Malware can be in the form of code, scripts, active content, and / or other software. Examples of malware uses include disrupting computer and / or network operations, stealing confidential information (e.g., confidential information such as information related to identity, finances, and / or intellectual property), and / or gaining access to private / private computer systems and / or computer networks. Unfortunately, as techniques are developed to help detect and mitigate malware, nefarious authors find ways to circumvent these efforts. Thus, there continues to be a need for improvements to techniques for identifying and mitigating malware.

[0031] A firewall generally allows authorized communications to pass through the firewall while protecting a network from unauthorized access. A firewall is typically a device, set of devices, or software running on devices that provides firewall functionality for network access. For example, a firewall may be integrated into the operating system of a device (e.g., a computer, smartphone, or other type of network-enabled device). A firewall may also be integrated into or run as one or more software applications on various types of devices, such as computer servers, gateways, network / routing devices (e.g., network routers), and data appliances (e.g., security appliances or other types of dedicated devices, and in some implementations, certain operations may be implemented in dedicated hardware, such as an ASIC or FPGA).

[0032] Firewalls typically deny or allow network transmissions based on a set of rules. These sets of rules are often referred to as policies (e.g., network policies or network security policies). For example, a firewall can filter inbound traffic by applying a set of rules or policies to prevent unwanted external traffic from reaching a protected device. A firewall can also filter outbound traffic by applying a set of rules or policies (e.g., allow, block, monitor, notify, or log, and / or other actions that may be specified in a firewall rule or firewall policy, which may be triggered based on various criteria, as described herein). A firewall can also filter local network (e.g., intranet) traffic by similarly applying a set of rules or policies.

[0033] Security devices (e.g., security appliances, security gateways, security services, and / or other security devices) may perform various security operations (e.g., firewall, anti-malware, intrusion prevention / detection, proxy, and / or other security functions), network functions (e.g., routing, quality of service (QoS), workload balancing of network-related resources, and / or other network functions), and / or other security and / or network-related functions. For example, routing may be based on source information (e.g., IP address and port), destination information (e.g., IP address and port), and protocol information.

[0034] Basic packet filtering firewalls filter network communication traffic by inspecting individual packets sent over the network (e.g., stateless packet filtering firewalls, or first-generation firewalls). Stateless packet filtering firewalls typically inspect the individual packets themselves and then apply rules based on the inspected packets (e.g., using a combination of the packet's source and destination address information, protocol information, and port numbers).

[0035] Application firewalls can also perform application layer filtering (e.g., application layer filtering firewalls or second-generation firewalls that function at the application level of the TCP / IP stack). Application layer filtering firewalls or application firewalls can generally identify certain applications and protocols (e.g., web browsing using the Hypertext Transfer Protocol (HTTP), Domain Name System (DNS) requests, file transfers using the File Transfer Protocol (FTP), and various other types of applications and protocols, such as Telnet, DHCP, TCP, UDP, and TFTP (GSS)). For example, an application firewall can block unauthorized protocols that attempt to communicate over standard ports (e.g., unauthorized / out-of-policy protocols that attempt to sneak through by using non-standard ports for that protocol can generally be identified using an application firewall).

[0036] Stateful firewalls can also perform state-based packet inspection, where each packet is inspected within the context of the sequence of packets associated with that network outbound packet / packet flow (e.g., a stateful firewall or third-generation firewall). This firewall technique is commonly referred to as stateful packet inspection because it keeps a record of all connections passing through the firewall and can determine whether a packet is the start of a new connection, part of an existing connection, or an invalid packet. For example, the state of a connection can itself be one of the criteria that triggers a rule in a policy.

[0037] Advanced or next-generation firewalls can perform stateless and stateful packet filtering and application layer filtering, as described above. Next-generation firewalls can also implement additional firewall technologies. For example, certain newer firewalls, sometimes referred to as advanced or next-generation firewalls, can also identify users and content. In particular, certain next-generation firewalls have expanded the list of applications they can automatically identify to thousands of applications. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., Palo Alto Networks PA Series Next-Generation Firewalls, Palo Alto Networks VM Series Virtualized Next-Generation Firewalls, and CN Series Containerized Next-Generation Firewalls).

[0038] As one example, advanced or next-generation firewalls may also be implemented using virtualized firewalls. Examples of such next-generation firewalls are commercially available from Palo Alto Networks (e.g., VMware® ESXi). TM and NSX TM, Citrix® Netscaler SDX TM Palo Alto Networks firewalls support a variety of commercial virtualization environments, including KVM / OpenStack (Centos / RHEL, Ubuntu®), and Amazon Web Services (AWS). For example, virtualized firewalls can support similar or identical next-generation firewall and advanced threat prevention capabilities available in physical form factor appliances, allowing enterprises to securely enable applications to flow into and across their private, public, and hybrid cloud computing environments. Automation capabilities such as VM monitoring, dynamic address groups, and REST-based APIs enable enterprises to proactively monitor VM changes to dynamically supply that context into security policies, thereby eliminating policy lag that can occur when VMs are modified.

[0039] For example, Palo Alto Networks' next-generation firewalls enable enterprises and service providers to identify and control applications, users, and content—not just ports, IP addresses, and packets—using a variety of identification technologies, including: APP-ID for precise application identification; TM (e.g., App ID), User-ID for user identification (e.g., by user or user group) TM (e.g., User ID), and Content-ID for real-time content scanning (e.g., controlling web surfing and restricting data and file transfers) TM(e.g., Content ID). These identification technologies allow enterprises to securely enable applications using business-relevant concepts instead of following the traditional approach offered by traditional port-blocking firewalls. Also, dedicated hardware for next-generation firewalls, implemented as dedicated appliances, typically offers higher performance levels for application inspection than software running on general-purpose hardware (e.g., security appliances offered by Palo Alto Networks, which utilize dedicated, function-specific processing tightly integrated with a single-pass software engine to maximize network throughput while minimizing latency in their PA Series next-generation firewalls).

[0040] Overview of Techniques for Providing Centralized Identity Redistribution

[0041] Existing approaches for user context redistribution typically require a separate protocol for each data type. These approaches are not easily scalable to more data types. Furthermore, these approaches generally require the deployment of complex configurations (e.g., agent-client) and do not provide central visibility of such user context data. Furthermore, such existing approaches offer limited scalability (e.g., limited based on security platform / firewall resources).

[0042] Thus, a technical challenge exists in current security architectures: specifically, the need to have authenticated user identities in any security architecture (e.g., in an enterprise network computing environment) to ensure secure access to resources and implement zero trust.

[0043] For example, security architectures are highly distributed, with unlimited workforces (e.g., geographically distributed users and / or hybrid / remote users), and distributing locally learned identity contexts (e.g., IP-user, user tag, IP tag, IP-port-user, IP-device ID, and / or various other identity contexts) throughout the security architecture for consistent enforcement of security is a significant technical challenge. Also, the problem of deploying and debugging user context redistribution is a complex technical challenge.

[0044] Therefore, what is needed is a solution that provides real-time user context redistribution for timely and effective security policy enforcement.

[0045] It is also desirable to provide user context available for consumption to security entities / devices (e.g., firewalls, gateways, etc.) as well as SD-WAN environments.

[0046] It is also desirable to provide a highly available and robust redistribution point (eg, to avoid creating a single point of failure).

[0047] It would also be desirable to provide a solution for identity context redistribution that is extensible for other context types (e.g., 5G data, device ID, etc.).

[0048] Accordingly, various techniques for centralized identity redistribution are disclosed.

[0049] In some embodiments, a system / process / computer program product for centralized identity redistribution for a security service includes receiving user context information (e.g., IP-user mapping, user-tag mapping, IP-tag mapping, IP-port-user mapping, IP-device ID mapping, 5G user context information, and / or other user context information / data) at a security platform from a cloud security service and applying a security policy at the security platform using the user context information. In one example, the security system applies the user context information in a policy based on the type of user context information. Some user context information, such as user-tag mapping, IP tag mapping, IP port mapping, and IP-port-user mapping, may be used to directly apply a policy, while some types, such as 5G data and device ID, are used to determine membership of objects used in the policy.

[0050] In some embodiments, a system / process / computer program product for centralized identity redistribution for a security service includes transmitting user context information (e.g., IP-user mapping, user-tag mapping, IP-tag mapping, IP-port-user mapping, IP-device ID mapping, 5G user context information, and / or other user context information / data) from a security platform to a cloud security service and storing the user context information in a data store of the cloud security service for redistribution to another security platform. The disclosed techniques for centralized identity information redistribution enable learning user context information at a security platform and using the user context information to apply security policies at a security platform different from the security platform from which the user context information was learned. It will be apparent that a security platform can be configured to send and receive user context information.

[0051] For example, the disclosed techniques for centralized identity redistribution can be implemented across all security platforms, including physical firewalls as well as virtual machine (VM) and container firewalls.

[0052] As another example, the disclosed techniques for centralized identity redistribution may be implemented to facilitate segment-based flow control for identity information / data.

[0053] Furthermore, the disclosed techniques for centralized identity redistribution can simplify and unify the redistribution of user context, for example, the disclosed techniques for centralized identity redistribution can simplify and unify the redistribution of user context and can provide a central location / source for consuming all user context information.

[0054] Additionally, the disclosed techniques for centralized identity redistribution generally do not require any changes in existing enterprise customer deployments. For example, the disclosed techniques can facilitate cloud-based identity redistribution across domains, where adding / removing security platforms (e.g., firewalls, devices, etc.) is simple and generally does not require any configuration changes.

[0055] Finally, the disclosed techniques for centralized identity redistribution facilitate reduced CPU and memory resource usage in each security platform (e.g., firewall, gateway / device, etc.) because most processing / merging can be implemented using cloud resources and receiving data, e.g., from only a centralized / single source, to be performed.

[0056] Thus, as further described below, various techniques are disclosed for centralized identity redistribution for security services.

[0057] System environment including an exemplary cloud user context architecture for centralized identity redistribution for security services

[0058] 1A-1B are system environment diagrams including example SD-WAN architectures and security services, according to some embodiments. These example system diagrams generally show security services for securing branch and headquarters sites using SD-WAN connections that communicate with security services (e.g., cloud-based security services).

[0059] As organizations grow across different geographic locations, selecting a network becomes a delicate balancing act between cost, performance, and security. Software-defined WAN (SD-WAN) simplifies WAN management and operation by separating the networking hardware (data plane) from its control mechanisms (control plane). SD-WAN technology enables enterprises to build higher-performance WANs using lower-cost internet access. By adopting SD-WAN, organizations are increasingly connecting directly to the internet, creating security challenges for protecting remote networks and mobile users. In addition, the deployment of Software as a Service (SaaS) applications has increased significantly, with many organizations connecting directly to these cloud-based SaaS applications, creating additional security challenges. The adoption of SD-WAN technology offers many cost-saving benefits and enables organizations to be agile and optimized. However, it also makes branch offices and users targets for cyberattacks and other technical security challenges, as discussed above.

[0060] While SD-WAN security is generally desirable to be as flexible as networking, adapting traditional security approaches to evolving SD-WAN networking in various enterprise network environments, such as those shown in Figures 1A and 1B, is also a technical challenge, as explained below. In traditional campus network designs, a full stack of network security devices exists at the Internet perimeter that can protect branch offices. This is true when all traffic comes through the core network to pass through this full stack of network security devices at the Internet perimeter. However, SD-WANs do not always use this network architecture, such as when the SD-WAN is configured to integrate cloud / SaaS applications.

[0061] One alternative to the traditional approach is to deploy network security equipment at branch offices. However, this traditional approach complicates deployment by placing security devices / elements closer to the branch offices.

[0062] SD-WAN technologies generally use software-defined networking (SDN) principles and separate the control plane and data plane. Based on this principle, SD-WAN deployments typically include the following components: (1) a controller, which administrators use to centrally configure the WAN topology and define traffic routing rules, and (2) physical or virtual SD-WAN edge devices that reside at every site and serve as the connection and termination points for the SD-WAN fabric.

[0063] In one exemplary SD-WAN Type 1 deployment (e.g., branch and headquarters deployment), an organization can deploy one or more SD-WAN edge devices at each branch and connect them to form an SD-WAN fabric or overlay. Administrators use an SD-WAN controller, based either in the cloud or on the organization's premises, to manage and configure these edge devices and define traffic forwarding policies at each site.

[0064] Referring to FIG. 1A for an example deployment (e.g., a branch office, headquarters, and regional data center deployment), IPSec tunnels are set up between each of SD-WAN edge devices 102A, 102B, and 102C at each data center (e.g., including IPSec tunnels between the SD-WAN edge devices at each branch office and headquarters site) and a security service 120 (e.g., a cloud-based security service such as Prisma Access (PA), a cloud-based security service available from Palo Alto Networks, Inc., headquartered in Santa Clara, California). This example system diagram is an example deployment for securing traffic from each branch office using one WAN link (Type 1), as shown at 110. The SD-WAN fabric 110 and security service 120 each communicate with the Internet 140. The security service 120 connects to a data store 130 (e.g., a Cortex A5000 Access Point, a cloud-based security service available from Palo Alto Networks, Inc., headquartered in Santa Clara, California). TM It communicates with a data store for network / security logging data, such as a data lake.

[0065] Specifically, this architecture adds SD-WAN devices in regional data centers along with SD-WAN devices at each branch and headquarters site. These regional data centers can be public or private cloud environments. The SD-WAN devices in the regional data centers aggregate network traffic for smaller sites within that region. For example, an organization can use this deployment if it has multiple regional branch offices with lower-bandwidth connections to the Internet.

[0066] 1B, for another exemplary deployment (e.g., a deployment of branch offices, a headquarters, and a regional data center), IPSec tunnels are set up between SD-WAN edge devices (e.g., including SD-WAN devices 102D and 102E) in each data center and a security service 120 (e.g., a cloud-based security service such as Prisma Access (PA), a cloud-based security service available from Palo Alto Networks, Inc., headquartered in Santa Clara, California). This exemplary system diagram is an exemplary deployment for securing an SD-WAN deployment using a regional hub / POP architecture. As shown, IPSec tunnels are set up between each of the regional data centers or hubs 106A and 106B and the security service 120.

[0067] A common network architecture today is to tunnel traffic between a company's headquarters and branches over either MPLS links or dedicated encrypted VPN links. More and more services are cloud-based (e.g., Microsoft Office 365). (R) , Salesforce (R)As more and more information becomes available on the Internet (including SaaS solutions such as , , etc.), tunneling traffic back to an aggregation point before routing it to its final destination generally makes less sense. Breaking out traffic locally from the branch office (as opposed to, for example, on-premise equipment) generally allows traffic to reach its destination faster and allows for more efficient use of bandwidth. However, enabling traffic directly between devices in the branch office and the Internet also introduces new technical security challenges, similar to those discussed above.

[0068] Specifically, in these and other example SD-WAN architectures and security services, flows can be configured to pass through security service 120 or to bypass security service 120 and be routed to a regional data center, or a hub, or the Internet without passing through security service 120. Thus, these and other example SD-WAN architectures and security services create the technical security problem described above because traffic passing through a security service is inefficiently inspected / monitored (e.g., DPI or other monitoring / inspection activities) at both the egress SD-WAN device / element and the security service. Additionally, these and other example SD-WAN architectures and security services create the technical security problem described above because traffic bypassing a security service is not consistently inspected / monitored, and analytics for security insights into the network and security functions for the security service are not gathered.

[0069] Thus, the disclosed techniques for centralized identity redistribution may be implemented in these example SD-WAN architectures and security services, as further described below with respect to FIG. 2.

[0070] 2 is a cloud user context architecture for centralized identity redistribution for security services, according to some embodiments. The user identity component is typically the central component for security policies (e.g., firewall policies), and the user identity component is the backbone of many security design principles. The disclosed techniques for centralized identity redistribution provide a global context that can consume user context and provide it to all downstream consumers, as will now be further described with respect to FIG. 2.

[0071] Referring to FIG. 2 , user identity broker service 202 is a cloud component that provides an application programming interface (API) gateway. The user identity broker service includes one or more broker pods 204. The user identity broker service can accept data from any authorized entity (e.g., including non-PAN-OS entities / firewalls) such as cloud identity engine (CIE) 206 (e.g., a cloud-native single sign-on (SSO) and directory service that facilitates centralized visibility and channel / segment configuration, as described further below) via an API (e.g., a REST API). The user identity broker service can accept data of any data type and is easily extensible to more data types (e.g., user ID, device ID, 5G data, etc.). Edge user identity service 210 is another cloud component that interacts with security platforms 214A, 214B, and 214C (e.g., Palo Alto Networks firewalls and / or other compliant devices / entities) as shown in FIG. 2 .

[0072] As also shown in FIG. 2, the edge user identity service includes edge pods 212A, 212B, and 212C as shown. The edge user identity service accepts and transmits data (e.g., user context / identity information / data) from these devices / entities via a communication protocol (e.g., gRPC). The edge user identity service and the user identity broker service share data via a data store, shown as Big Table 208 (e.g., the edge user identity service and the user identity broker service can store data in a Big Table, which may be implemented using the Google Cloud Big Table data store solution commercially available from Google, or another cloud data store may be similarly implemented). As described further below, the user context / identity information may be distributed using a publish and subscribe distribution model (e.g., publishing and subscribing to segments, as described further below with respect to FIG. 3A).

[0073] FIG. 3A illustrates an architecture overview for user context information grouped into segments and shared to provide centralized identity redistribution for security services, according to some embodiments. In this example, incoming traffic on a firewall (device) is attributed to a user identified based on its IP address. User context information (e.g., IP tag, IP-user mapping, IP-port-user, IP quarantine, user tag, etc.) is associated with the available IP address through a cloud-based redistribution service (e.g., periodically providing redistribution, such as every two seconds or some other periodic interval for time-sensitive user context data, to provide real-time user context redistribution for timely and effective enforcement of security policies), as also described above with respect to FIG. 2. Cloud User ID (CUID) 302 (e.g., an exemplary implementation of a user ID broker service in the cloud, shown at 202 in FIG. 2) is a multi-tenant redistribution service hosted in multiple cloud domains. Security platforms (e.g., firewalls and / or other security devices / entities) such as those shown at 304A, 304B, 304C, 304D, 304E, and 304F may be grouped into "segments," and redistribution of user context / identity / data may be restricted to remain within a segment, such as remote networks (RNs) for the United States (US) region, the European (EU) region, and the Asia-Pacific (AP) region, as shown at 306A, 306B, and 306C.

[0074] In this example implementation, any authorized security platform (e.g., firewalls and / or other security devices / entities, such as those shown at 304A, 304B, 304C, 304D, 304E, and 304F in FIG. 3A) generating user context information can be configured to publish to a segment within a CUID. Any authorized security platform (e.g., firewalls and / or other security devices / entities) can also subscribe to a segment (e.g., RN US 306A, RN EU 306B, and / or RN AP 306C, as shown in FIG. 3A) to consume user context information for a particular tenant.

[0075] FIG. 3B illustrates another architecture overview for user context information grouped into segments and shared to provide centralized identity redistribution for security services, according to some embodiments. In this exemplary implementation, configuration is centralized, and contributing security platforms (e.g., firewalls and / or other security devices / entities) generally do not need to know about the configuration involved in the redistribution. Configuration of CUID 302 can be performed using a CIE interface (e.g., GUI) 320 via HUB 322. As also discussed above with respect to FIG. 3A, CUID can replicate data to make user context information / data available across segments (e.g., regions and / or other segmentation can be configured), ensuring secure access regardless of the user's location.

[0076] 3B, CUID 302 includes branch A segment 324A and branch B segment 324B. Branch A firewall 326A is in publish / subscribe communication with branch A segment 324A for different user context data types. Branch B firewall 326B is in publish / subscribe communication with branch B segment 324B for different user context data types. Data center firewall 328 is in publish / subscribe communication with all branch offices for different user context data types, including branch A segment 324A and branch B segment 324B in this exemplary implementation as shown in FIG. 3B.

[0077] FIG. 3C illustrates an architecture for a firewall daemon to provide centralized identity redistribution for security services, according to some embodiments. In this exemplary implementation, a cloud service user ID broker (e.g., a user ID broker service in the cloud, such as shown at 202 in FIG. 2 ) communicates / interacts with a CIE (e.g., a cloud identity engine 206, such as shown in FIG. 2 ). An edge user ID service (e.g., an edge user ID service in the cloud, such as shown at 210 in FIG. 2 ) collects user context information / data from and distributes user context information / data to all security platforms (e.g., firewalls and / or other security devices / entities for security services) based on a distribution (e.g., publish / subscribe) model. As also described above with respect to FIG. 2 , the user ID broker and edge user ID use a big table (e.g., big table 208 shown in FIG. 2 ) to store such user context / identity data. 3A and 3B, segments can be used to group security platforms (e.g., firewalls and / or other security devices / entities for security services) and restrict data flow for specific tenants. The edge user ID receives security platform to segment mapping from the CIE via the broker. The CIE queries the broker to obtain user context / identity data for visibility requirements.

[0078] 3C , Broker / Edge User ID 330 communicates with the management plane 332 of the security platform (e.g., a firewall and / or other security device / entity). Specifically, the Identity Cloud Daemon (ICD) 334 of the security platform's management plane communicates with the Broker / Edge User ID to communicate IP-to-user mappings (e.g., PAN-OS User ID) (upload / download) and other data types (upload / download). The ICD 334 communicates with the User ID component 340 (e.g., the PAN-OS User ID component in this exemplary implementation for the PAN-OS firewall, which communicates with the PAN-OS firewall's Data Plane (DP), as shown at 342) to upload data to the Edge User ID service. Additionally, the ICD 334 fetches data from the Edge User ID service and sends it to the User ID component 340 or the IoT component 338 based on the data type. The Redis component 336 is an in-memory data store (for example, the Redis component can be implemented using Hiredis, a minimalistic C client library for Redis databases, or another commercial or open-source Redis solution can also be used). Host Information Profile (HIP) information can also be redistributed and made available via the cloud using similar techniques.

[0079] FIG. 3D illustrates an architecture for IP-user mapping that can be uploaded and downloaded to the cloud to provide centralized identity redistribution for security services, according to some embodiments. As shown, the user ID component 340 receives user mappings 350 from various sources (e.g., Syslog, XML API, Active Directory (AD), agents, captive portals (CP) (e.g., the PAN-OS firewall may be configured to prompt users to authenticate through a captive portal (CP) when they initiate web traffic (HTTP or HTTPS) that matches an authentication policy rule. This ensures that we know exactly who is accessing, for example, sensitive applications and data, based on user information collected during authentication. The firewall can then create a new IP address-to-user name mapping or update an existing mapping for that user. For example, this method of user mapping can be useful in environments where the firewall cannot learn mappings through other means, such as server monitoring (where there may be users who are not logged into the monitored domain servers, e.g., users of Linux clients), VPNs such as GlobalProtect (GP) available from Palo Alto Networks, Inc., headquartered in Santa Clara, California, etc.). The user ID component 340 updates the mappings to the LRU cache as shown. The IP address may be used as a key for an LRU cache. The user ID component 340 publishes updates to a Redis list, which may be used as an upload queue as shown. The key name of the list is "UPLOADQ". "UPLOADQ" is a list of IP addresses. The ICD 334 consumes IP-user mappings from "UPLOADQ".The ICD 334 uploads IP-user mappings to the edge (i.e., broker / edge-user ID) 330 as shown. The ICD 334 also downloads IP-user mappings from the edge 330 as shown. The ICD 334 stores the IP-user mappings in an LRU cache (e.g., the LRU cache size may be implemented as a 500K cache by default, or some other cache size may be similarly implemented in the IP-user mapping component 350). The ICD 334 publishes the IP-user mappings to a Redis list used as a download queue. The key name of the list is "DOWNLOADQ" (e.g., "DOWNLOADLOADQ" is a list of IP addresses). The user ID component 340 consumes "DOWNLOADQ". The user ID component 340 pushes the IP-user mappings to the DP 342.

[0080] 3E illustrates an IP-user mapping workflow for providing centralized identity redistribution for security services, according to some embodiments. FIG. 3E illustrates an example implementation of the upload workflow and unknown query and download workflow for cloud user-ID IP-user mapping.

[0081] FIG. 3F illustrates an architecture for IP tag mappings that can be uploaded and downloaded to the cloud to provide centralized identity redistribution for security services, according to some embodiments. As illustrated, IP tag mappings can similarly be redistributed using the disclosed centralized identity redistribution techniques. For example, IP tag mappings can be maintained in User ID memory and similarly saved to disk, as shown at 350. The User ID component can obtain IP tag mappings from a variety of sources (e.g., VM monitoring, XML APIs, auto-tagging, agents, Panorama, a commercially available management platform from Palo Alto Networks, Inc., headquartered in Santa Clara, California, and / or various other sources can also be used). The User ID component publishes IP tag mappings to the Redis "UPLOADQ." The ICD consumes the "UPLOADQ." The ICD uploads IP tag mappings to the edge. The ICD downloads IP tag mappings from the edge. The ICD publishes updates to the "DOWNLOADQ." The User ID component consumes the “DOWNLOADQ.” The User ID component saves the updates to the XML file on the local disk and then notifies the development server (Devsrvr), as shown at 352.

[0082] In another example implementation, user context information, such as IP-port-user mappings (e.g., and / or other user mappings), may be similarly redistributed using the disclosed centralized identity redistribution techniques.

[0083] 3G illustrates an architecture for using segments to provide centralized identity redistribution for security services, according to some embodiments. Whenever user context data (e.g., user context information) is published by a security platform to an edge (i.e., broker / edge user ID), the user context data is associated (e.g., stored) with a segment (e.g., a segment generally refers to a grouping of security platforms / firewalls, also referred to herein as a channel, as shown in FIG. 3F) configured by the CIE. All security platforms belonging to the same segment receive this published data (e.g., each firewall publishes data and subscribes user context data to a segment, and the edge provides logical separation between different segments in the big table data store).

[0084] In one example implementation, the edge (i.e., broker / edge user ID) detects any changes to the segment and moves the security platform to the new segment. The edge downloads all data from the new segment to the security platform after the change. Existing old segment data in the cloud is untouched. Existing data on the security platform from the old segment is left untouched. Data with a timeout times out. Data without a timeout, such as IP host or IP tag, can remain on the security platform. Whenever the security platform loses connectivity to the edge for an extended period of time (e.g., one minute, or some other predetermined or configurable period), it can perform the following re-sync operations: (1) when the security platform reconnects, the edge can dump all data for the segment to the security platform; and (2) the security platform can publish all new data to the edge.

[0085] FIG. 3H illustrates a cloud-based user ID component architecture for providing centralized identity redistribution for security services, according to some embodiments. In this exemplary implementation, the Device Association Service (DAS) provides a solution for customers to associate a group of devices (e.g., security platforms such as network gateway firewalls (NGFWs), Prisma Access (PAs), software-defined wide area networks (SD-WANs), etc.) to a single tenant ID, called a TSGID. Thus, it associates the serial number of the security platform to the TSGID. The Enforcer component queries the instance store (e.g., the front end of the DAS) to obtain the TSGID given the serial number. The Enforcer instance is queried by the Edge, which obtains the TSGID once the firewall connects to the Edge. The TSGID provides a global tenant ID for grouping all devices together created by the DAS. As used herein, Segment TSGID generally refers to a global tenant ID for a customer that can be used across all security services that the customer can use (e.g., all security platforms / firewalls and services (service tenant IDs) can be mapped to this global TSGID, which can be used to provide data isolation between customers in the Big Table backend).

[0086] In one exemplary implementation, the NGFW (e.g., security platform / firewall) workflow begins with a customer onboarding a CIE, CDL, and FAWKES to a TSG. The DAS can then be used to associate the firewall appliance with the TSG. The CIE can then be used to configure segments for each of these associated devices provided by the DAS. This configuration is pushed to the edge and is globally available to all regions, as shown in FIG. 3H. Finally, the firewall can connect to the edge deployed in a specific region based on a geolocation service (e.g., using AWS geolocation services or another geolocation service). Once connected, it uploads / downloads data based on the configuration pushed by the CIE.

[0087] In another exemplary implementation, a PA (e.g., the Prisma Access Security Solution commercially available from Palo Alto Networks, Inc., headquartered in Santa Clara, California) starts with a customer onboarding a CIE, CDL, and FAWKES to a TSG. A DAS can then be used to associate the PA instance with the TSG. A SaaS agent can then push a list of devices to the CIE. The CIE can configure segments on these devices. This configuration is pushed to the edge and is globally available to all regions. The PA firewall can connect to edges deployed in specific regions based on a geolocation service (e.g., using AWS geolocation services or another geolocation service). Once connected, it uploads / downloads data based on the configuration pushed by the CIE.

[0088] In one exemplary implementation, data replication can be performed to replicate user context information, as described below. In some use cases, the SD-WAN and PA can require data to be replicated across regions (e.g., US, APAC, EU, etc.). For example, user context information, such as a specific IP-user mapping created in the EU region, should be available for use in a security platform in the US region (e.g., a use case in which a US data center security platform needs to be accessed by users from different regions). Data replication in such use cases can be implemented using the big table replication feature described above. For example, any IP-user mapping created in the EU region can be configured to automatically synchronize to the US region using Google Cloud Platform (GCP) (e.g., controlled by a global replication configuration on the segment).

[0089] Thus, the disclosed techniques for centralized identity redistribution can be implemented across different security platforms, including physical, VM, and container firewalls, and, again, without requiring any changes in existing customer deployments. The disclosed techniques for centralized identity redistribution can also simplify and unify user context redistribution by providing a central source for consuming all user context information (e.g., using a publish and subscribe communication model, including, by way of example, IP tag and user tag redistribution).

[0090] Additionally, the disclosed techniques for centralized identity redistribution facilitate cloud-based identity redistribution across segments and provide segment-based (e.g., region-based, as also described above with respect to Figures 3A and 3B) flow control for identity data.

[0091] Additionally, segment-based flow control for identity data facilitates reduced CPU and memory resources in each security platform (e.g., firewall or other security device / entity) because most processing / merging / storage occurs in the cloud and data is received from only one source. Furthermore, adding / removing security platforms (e.g., firewalls or other security devices / entities) is simple and does not require any configuration changes.

[0092] One embodiment of network gateway 214 is shown in FIG. 4A (e.g., network gateways 214A-C in FIG. 2). The illustrated example is a representation of physical components that may be included in network gateway 214 when the network gateway is implemented as a data appliance, in various embodiments. Specifically, the data appliance includes a high-performance multi-core central processing unit (CPU) 402 and random access memory (RAM) 404. The data appliance also includes storage 410 (such as one or more hard disks or solid-state units). In various embodiments, the data appliance stores (either in RAM 404, storage 410, and / or other suitable locations) information used to monitor the enterprise network and implement the disclosed techniques. Examples of such information include application identifiers, content identifiers, user identifiers, requested URLs, IP address mappings, policy and other configuration information, signatures, hostname / URL categorization information, malware profiles, and machine learning (ML) models. The data appliance may also include one or more optional hardware accelerators. For example, the data appliance may include a cryptographic engine 406 configured to perform encryption and decryption operations, and one or more field programmable gate arrays 408 configured to perform matching, act as a network processor, and / or perform other tasks.

[0093] The functionality described herein as being performed by a data appliance may be provided / implemented in a variety of ways. For example, a data appliance may be a dedicated device or set of devices. The functionality provided by a data appliance may also be integrated with or executed as software on a general-purpose computer, computer server, gateway, and / or network / routing device. In some embodiments, at least some of the services described as being provided by a data appliance are instead (or in addition) provided to a client device (e.g., an endpoint device such as a laptop, smartphone, etc.) by software running on the client device.

[0094] Whenever a data appliance is described as performing a task, a single component, a subset of components, or all components of the data appliance may cooperate to perform the task. Similarly, whenever a component of a data appliance is described as performing a task, a subcomponent may perform the task and / or the component may perform the task in conjunction with other components. In various embodiments, portions of the data appliance are provided by one or more third parties. Depending on factors such as the amount of computing resources available to the data appliance, various logical components and / or features of the data appliance may be omitted, and the techniques described herein may be adapted accordingly. Similarly, additional logical components / features may be included in embodiments of the data appliance, as applicable. One example of a component included in a data appliance in various embodiments is an application identification engine configured to identify applications (e.g., using various application signatures to identify applications based on packet flow analysis). For example, the application identification engine may determine the type of traffic a session involves, such as web browsing-social networking, web browsing-news, SSH, etc.

[0095] The disclosed system processing architecture can be used with different types of clouds in different deployment scenarios: (1) public clouds, (2) on-premise private clouds, and (3) within high-end physical firewalls. Some processing power can be allocated to run the private clouds (e.g., using the management plane (MP) in Palo Alto Networks PA series firewall appliances).

[0096] 4B is a functional diagram of logical components according to one embodiment of a data appliance. The illustrated example is a representation of logical components (e.g., network gateways 214A-C in FIG. 2) that may be included in network gateway 214 in various embodiments. Unless otherwise specified, the various logical components of network gateway 214 may generally be implemented in a variety of ways, including as a set of one or more scripts (e.g., written in Java, Python, etc., where applicable).

[0097] As shown, network gateway 214 includes a firewall and includes a management plane 432 and a data plane 434. The management plane is responsible for managing user interaction, such as by providing a user interface for setting policies and displaying log data, and the data plane is responsible for data management, such as by performing packet processing and session handling.

[0098] The network processor 436 is configured to receive packets from client devices (e.g., endpoint devices such as a user's laptop, smartphone, tablet, etc.) and provide them to the data plane 434 for processing. The flow module 438 creates a new session flow whenever it identifies a packet as part of a new session. Subsequent packets are identified as belonging to the session based on the flow lookup. If applicable, SSL decryption is applied by the SSL decryption engine 440. Otherwise, processing by the SSL decryption engine 440 is skipped. The decryption engine 440 helps the network gateway 214 inspect and control SSL / TLS and SSH encrypted traffic and, therefore, helps stop threats that might otherwise remain hidden within the encrypted traffic. The decryption engine 440 can also help prevent sensitive content from leaving the enterprise / secure customer network. Decryption can be selectively controlled (e.g., enabled or disabled) based on parameters such as URL category, traffic source, traffic destination, user, user group, and port. In addition to decryption policies (e.g., specifying which sessions to decrypt), decryption profiles can be assigned to control various options of the sessions controlled by the policy, for example, requiring the use of specific cipher suites and encryption protocol versions.

[0099] The application identification (APP-ID) engine 442 is configured to determine the type of traffic a session involves. As one example, the application identification engine 442 can recognize a GET request in the received data and conclude that the session requires an HTTP decoder. In some cases, such as a web browsing session, the identified application can change, and such changes are noted by the network gateway 214. For example, a user can first browse a company's wiki (categorized as "Web Browsing-Productivity" based on the URLs visited) and then browse a social networking site (categorized as "Web Browsing-Social Networking" based on the URLs visited). Different types of protocols have corresponding decoders.

[0100] Based on the determinations made by the application identification engine 442, the packets are reassembled by the threat engine 444 into the correct order (which may be received out of order), tokenized, and sent to the appropriate decoder configured to extract the information. The threat engine 444 also performs signature matching to determine what should happen to the packets. If necessary, the SSL encryption engine 446 can re-encrypt the decrypted data. The packets are forwarded using the forwarding module 448 for forwarding (e.g., to a destination).

[0101] 4B, a policy 452 is also received and stored in the management plane 432. The policy can include one or more rules, which can be specified using domain names and / or host / server names, and the rules can apply one or more signatures or other matching criteria or heuristics, such as for enforcing security policies on subscriber / IP flows, based on various extracted parameters / information from the monitored session traffic flows. An interface (I / F) communicator 450 is provided for management communications (e.g., via (REST) APIs, messages, or network protocol communications, or other communications mechanisms).

[0102] Exemplary Process for Providing Centralized Identity Redistribution for Security Services

[0103] 5 is a flowchart illustrating a process for providing centralized identity redistribution for security services, according to some embodiments. In one embodiment, process 500 is performed using the system architecture described above (e.g., as described above with respect to FIGS. 1-4B).

[0104] The process begins when a flow is received at a security platform of a security service at 502. For example, the security service may be a cloud-based security service, as also described above.

[0105] At 504, user context information (e.g., IP-user mapping, user-tag mapping, IP-tag mapping, IP-port-user mapping, IP-device ID mapping, 5G user context information, and / or other user context information / data) is received at the security platform from the cloud security service using the centralized identity redistribution technique described above.

[0106] At 506, security policies are applied in the security platform using the user context information.

[0107] 6 is another flowchart illustrating a process for providing centralized identity redistribution for security services, according to some embodiments. In one embodiment, process 600 is performed using the system architecture described above (e.g., as described above with respect to FIGS. 1-4B).

[0108] The process begins when a flow is received at a security platform of a security service at 602. For example, the security service may be a cloud-based security service, as also described above.

[0109] At 604, user context information (e.g., IP-user mapping, user-tag mapping, IP-tag mapping, IP-port-user mapping, IP-device ID mapping, 5G user context information, and / or other user context information / data) is sent from the security platform to the cloud security service.

[0110] At 606, the user context information is stored in a data store of the cloud security service for redistribution of the user context information to another security platform using the centralized identity redistribution techniques described above.

[0111] 7 is another flow diagram illustrating a process for providing centralized identity redistribution for security services, according to some embodiments. In one embodiment, process 700 is performed using the system architecture described above (e.g., as described above with respect to FIGS. 1-4B).

[0112] Although the foregoing embodiments have been described in some detail for purposes of clarity of understanding, the invention is not limited to the details provided. There are many alternative ways of implementing the invention. The disclosed embodiments are illustrative and not limiting.

Claims

1. 1. A processor implementation method, comprising: receiving, at the security platform, user context information from the cloud security service; The user context information includes at least one of an IP-user mapping, a user-tag mapping, an IP-tag mapping, an IP-port-user mapping, and an IP-device ID mapping; Steps and applying, at the security platform, a security policy using the user context information; A method comprising:

2. The security platform includes a physical firewall, a virtual machine firewall, or a container-based firewall. The method of claim 1.

3. The security platform is an edge device in an SD-WAN network; the edge device is configured to serve as an attachment point and / or a termination point for the SD-WAN network; and the edge device is further configured to connect to the cloud security service via an IPsec tunnel. The method of claim 1.

4. The security platform subscribes to segments for centralized identity redistribution; The segment is a group of security platforms or firewalls. The method of claim 1.

5. The security platform is a certified platform for security services; The method further includes, before the step of receiving the user context information, receiving, at the security platform, incoming traffic; The user context information is associated with an IP address of the incoming traffic; and applying the security policy includes attributing the incoming traffic to an identified user by associating the user context information with the IP address; The method of claim 1.

6. A processor implementation method, generating user context information at an authenticated security platform and / or obtaining user context information from one or more sources at said security platform; sending the user context information to a cloud security service; A method comprising:

7. The security platform is an edge device in an SD-WAN network; the edge device is configured to serve as an attachment point and / or a termination point for the SD-WAN network; and the edge device is further configured to connect to the cloud security service via an IPsec tunnel. The method of claim 6.

8. 1. A processor implementation method, comprising: receiving, at the cloud security service, user context information from the security platform; The user context information includes at least one of an IP-user mapping, a user-tag mapping, an IP-tag mapping, an IP-port-user mapping, and an IP-device ID mapping; Steps and storing the user context information in a data store of the cloud security service for redistribution of the user context information to another security platform; A method comprising:

9. the other security platform is subscribed to a segment for centralized identity redistribution to receive the user context information from the cloud security service; The method further comprises: publishing the user context information to the other security platform; and The segment is a group of security platforms or firewalls. The method of claim 8.

10. 1. A system including a processor and a memory, the memory storing a plurality of computer instructions; The computer instructions, when executed by the processor, cause the processor to perform the method of any one of claims 1 to 5. system.

11. 1. A system including a processor and a memory, the memory storing a plurality of computer instructions; The computer instructions, when executed by the processor, cause the processor to perform the method of claim 6 or 7. system.

12. 1. A system including a processor and a memory, the memory storing a plurality of computer instructions; The computer instructions, when executed by the processor, cause the processor to perform the method of claim 8 or 9. system.

13. The system comprises the system according to claim 10 and the system according to claim 12. assembly.

14. The assembly further comprises the system of claim 11 , The security platform of the system of claim 11 is configured to be connected to a cloud security platform of the system of claim 12; The user context information generated and / or acquired by the security platform of the system of claim 11 is received and stored by the cloud security system of claim 12, and is received from the cloud security system by the security platform of the system of claim 10.

14. The assembly of claim 13.

15. A computer program comprising a plurality of computer instructions, stored on a tangible computer-readable storage medium; The computer instructions, when executed by a processor, cause the processor to perform the method of any one of claims 1 to 9. Computer program.

Citation Information

Patent Citations

  • Automatic construction method for VPN, policy managing device and user device

    JP2005136631A

  • Traffic control system and traffic control method

    JP2008219149A

  • Systems and methods for characterizing and managing electronic traffic

    JP2008508805A

  • Management program, management method, and management device

    JP2016157323A

  • Device system, device management device, device, computer program and device system control method

    JP2021033370A