Cloud-Based Risk Profiling for Mobile Device Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Network Access Control (NAC) systems are static and limited in scope, failing to effectively manage the growing complexity of mobile devices accessing cloud services across diverse operating systems and network topologies, leading to compatibility issues and increased security risks due to their inability to adapt to changing network conditions and emerging threats.

Innovation Solution

A cloud-based security system performs multidimensional risk profiling of mobile devices, combining device, application, user, and environmental risks to dynamically assess and control network access, using a client application to collect posture data and update risk indices, allowing or denying access based on a weighted risk analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional static NAC systems are used, then system simplicity is maintained, but security risk increases and adaptability to changing network conditions deteriorates

Engineering Contradiction:
Improvesecurity riskVSAvoidadaptability to changing network conditions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic risk indexing that continuously updates security assessments based on real-time network conditions, device posture data, and threat intelligence. The system transitions from static access control lists to dynamic risk-based policies that automatically adapt to changing environmental factors, device states, and emerging threats without requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates continuous feedback loops where device posture data, network behavior analytics, and threat intelligence are constantly monitored and fed back into the risk assessment engine. This feedback mechanism enables the NAC system to learn from observed patterns and automatically adjust access decisions based on updated risk profiles, creating a self-improving security system.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple separate applications are deployed for different services, then service functionality is comprehensive, but device complexity and user configuration burden increase

Engineering Contradiction:
Improveservice functionalityVSAvoidnumber of applications
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal NAC agent that consolidates multiple security functions into a single application. This unified agent handles device profiling, posture assessment, policy enforcement, and access control across various network services and cloud resources, eliminating the need for separate applications while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges previously separate security functions (device management, access control, threat detection, and policy enforcement) into an integrated cloud-based NAC platform. This consolidation reduces the number of individual applications and components while providing coordinated security across all enterprise resources through a single management interface.

Inventive Principle:
Principle #5Merging (Combining)

3Stability of the object's composition

If static NAC policies are enforced, then policy consistency is maintained, but productivity decreases due to manual reconfiguration requirements

Engineering Contradiction:
Improvepolicy consistencyVSAvoiduser productivity
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The system performs preliminary risk assessment and policy determination before access requests are processed. Device posture data is collected and evaluated in advance, and appropriate access policies are pre-configured based on device profiles and historical behavior patterns. This preliminary action enables automatic policy application without requiring manual user intervention during access attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The NAC system automatically performs policy enforcement and access decisions without requiring manual user configuration or administrator intervention. The system self-adjusts access policies based on real-time risk assessments, automatically adapting to changing conditions while maintaining policy consistency through centralized cloud-based policy management.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If cloud-based dynamic risk profiling is implemented, then security adaptability and intelligence improve, but system complexity and data processing requirements increase

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based intermediary NAC service that handles complex risk assessment computations and policy decision-making. The lightweight on-device agent collects posture data and communicates with the cloud service, which performs the heavy lifting of multidimensional risk analysis using aggregated data from multiple sources. This intermediary architecture distributes system complexity from the endpoint to the cloud infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transitions risk assessment from a single-device perspective to a multidimensional cloud-based analysis that incorporates data from multiple sources including device posture, network behavior, threat intelligence feeds, and organizational context. This dimensional expansion enables more sophisticated security adaptability while distributing computational complexity across the cloud infrastructure rather than individual devices.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10511607B2Multidimensional risk profiling for network access control of mobile devices through a cloud based security system
Publication Date: 2019.12.17 ZSCALER INC
  • US10511607B2 patent drawing
  • US10511607B2 patent drawing
  • US10511607B2 patent drawing

AI summary

A server configured to profile a mobile device for a cloud-based system, includes a network interface, a data store, and a processor communicatively coupled to one another; and memory storing computer executable instructions, and in response to execution by the processor, the computer-executable instructions cause the processor to, based on communication to a client application on the mobile device, cause the client application to collect data associated with the mobile device; receive the collected data; and determine a device fingerprint and a risk index for the mobile device based on the collected data, wherein the device fingerprint is utilized to uniquely identify the mobile device and the risk index is utilized to manage the mobile device.