Client Device Identity Tags for Dynamic Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to dynamically enforce security policies on client devices based on user identity, location, and device type, especially in remote work scenarios where client devices are often shared and accessed by multiple users.

Innovation Solution

A system utilizing a device identity entity and a security policy enforcement entity to create and enforce security policies based on user identity, location, and device type by associating a tag with the client device, which is validated through a cloud network infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security policies are enforced statically on client devices, then device access control is simplified, but security cannot adapt to different users, locations, or device types

Engineering Contradiction:
Improvesecurity policy adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on user identity, device type, location, and network conditions. The security policy enforcement entity receives context information and dynamically modifies policy enforcement rules, transforming static security configurations into adaptive security measures that respond to changing conditions without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security policy parameters based on multiple input factors including user credentials, device characteristics, geographic location, and network posture. By varying security parameters dynamically according to these inputs, the system achieves high adaptability while maintaining manageable complexity through automated parameter adjustment rather than manual configuration.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security policies are customized for each user and device, then security compliance is improved, but policy management complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security policy enforcement entity autonomously retrieves user credentials, device information, and location data, then automatically applies appropriate security policies without requiring manual configuration for each user or device. The system serves itself by automatically managing the complexity of customized policy enforcement through automated credential verification and context-based policy selection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A single security policy enforcement entity handles multiple functions including authentication, authorization, policy retrieval, and dynamic policy application for diverse users, devices, and locations. This universal entity manages all security policy customization needs through one system component, reducing overall management complexity while maintaining high security compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If cloud network enforces security policies dynamically, then remote work security is enhanced, but network infrastructure complexity increases

Engineering Contradiction:
Improveremote access securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security policy enforcement entity acts as an intermediary between the cloud network and client devices, handling all security policy enforcement operations. This intermediary receives connection requests, verifies credentials, determines appropriate policies based on user and device context, and enforces security measures before granting network access, thereby enhancing remote security without requiring complex distributed security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system continuously monitors network conditions, user behavior, and device posture, then adjusts security policy enforcement in real-time based on this feedback. The security policy enforcement entity receives ongoing information about network context and dynamically modifies security measures, enabling enhanced remote work security through adaptive response to actual network conditions rather than static pre-configured rules.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12407736B2Dynamically enforcing security policies on client devices using a device identity entity and a security policy enforcement entity
Publication Date: 2025.09.02 CISCO TECHNOLOGY INC
  • US12407736B2 patent drawing
  • US12407736B2 patent drawing
  • US12407736B2 patent drawing

AI summary

Techniques and architecture are described for determining an identity of a client device and utilizing security policies associated with the client device provided by a device identity entity. For example, a tag associated with security policies is created for use in enforcing the security policies by a security policy enforcement entity associated with a cloud network. The techniques and architecture also allow for identification of a particular user on a client device that may be shared by multiple users based at least in part on the user accessing an application. Also, the techniques and architecture described herein provide a generic and agnostic approach to enforcing security policies for users and/or client devices.