Cloud Policy Enforcement via Network Trust Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise network security models are inadequate for mobile users connecting from diverse and potentially insecure networks, as they apply uniform policies regardless of network security levels, leading to increased risks for enterprise data and access.

Innovation Solution

Implementing a cloud-based system that dynamically adjusts security policies based on network trust levels, using Domain Name Server (DNS) configurations, device posture, and security settings to categorize networks as trusted or untrusted, enabling granular enforcement of security measures such as content filtering and Data Loss Prevention (DLP) across multiple geographies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform security policies are applied to all mobile devices regardless of network, then policy consistency is maintained, but security effectiveness deteriorates on untrusted networks

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidnetwork-aware policy adaptation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts security policies based on real-time network trust assessments. Enforcement nodes continuously evaluate network characteristics and modify policy enforcement levels accordingly, transitioning from static uniform policies to adaptive dynamic policies that respond to changing network conditions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different security policies are applied to different network contexts. Trusted networks receive standard security enforcement while untrusted networks trigger enhanced security measures. This local differentiation allows the system to optimize security effectiveness for each specific network environment rather than applying a one-size-fits-all approach

Inventive Principle:
Principle #3Local quality

2Reliability

If enhanced security measures are applied on untrusted networks, then security protection is improved, but user experience deteriorates due to additional restrictions

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies security measures proportionally to the risk level. On untrusted networks, enhanced security is applied only to specific high-risk operations or data types rather than blocking all user activities. This partial action approach maintains security protection while minimizing the impact on overall user experience

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If cloud-based security services are implemented, then security management is improved, but network latency increases

Engineering Contradiction:
Improvesecurity managementVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security policies are pre-configured and cached at enforcement nodes before actual traffic needs to be processed. The cloud-based system pushes policy updates in advance to edge enforcement nodes, allowing them to enforce policies locally without real-time cloud consultation, thereby reducing latency while maintaining centralized security management

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If network trust assessment is implemented, then policy accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvepolicy accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Enforcement nodes act as intermediaries between cloud-based security services and user devices. These intermediaries perform network trust assessments and policy enforcement locally, simplifying the overall system architecture by distributing functionality rather than concentrating all complexity in a single centralized system

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11985129B2Cloud policy enforcement based on network trust
Publication Date: 2024.05.14 ZSCALER INC
  • US11985129B2 patent drawing
  • US11985129B2 patent drawing
  • US11985129B2 patent drawing

AI summary

Systems and methods include obtaining trusted network rules for a plurality of networks, wherein the trusted network rules include whether a network is untrusted or one of a plurality of trusted networks; obtaining policy configurations for each of the trusted network rules, wherein the policy configurations define configurations for a cloud-based system to use with a user device based on a corresponding network where the user device is connected; communicating with the user device and determining which network of the plurality of network the user device is connected; and applying the configurations in the cloud-based system for the user device based on the network the user device is connected. The steps can further include obtaining forwarding policies for each of the plurality of networks; and providing the forwarding policies to a connector application executed on the user device.