Cloud Security Policy Agent for Edge Device Customization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based security systems often employ a one-size-fits-all approach to security protocols, which can lead to either unnecessary security features being deployed or insufficient security robustness for specific user applications, devices, or situations in edge computing environments.

Innovation Solution

The implementation of a method that uses a security policy agent to determine specific security policies based on user device parameters, such as device type, user group, or application, and embeds metadata into data packets to selectively apply Secure Access Service Edge (SASE) security services in a cloud-based environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-size-fits-all approach to security protocols is used, then security coverage is comprehensive, but security efficiency deteriorates due to unnecessary security features being deployed

Engineering Contradiction:
Improvesecurity robustnessVSAvoidsecurity efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by customizing security protocols according to specific user parameters such as device type, user group, and application. Instead of uniformly applying all security measures to all traffic, the system selectively applies security services based on the characteristics of each user or device, thereby improving security efficiency while maintaining appropriate security robustness for each specific case.

Inventive Principle:
Principle #3Local quality

2Productivity

If customized security protocols are implemented based on user parameters, then security efficiency is improved by avoiding unnecessary measures, but system complexity increases

Engineering Contradiction:
Improvesecurity efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security system into multiple components including a security policy agent that receives and processes user parameters, a policy evaluation module that determines appropriate security protocols, and a service application module that implements the selected security services. This segmentation allows the system to handle complexity in a modular fashion, improving security efficiency through customization while managing system complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security policy agent as an intermediary component that mediates between user parameters and security protocol selection. This intermediary receives user parameters, determines the appropriate security protocols based on predefined policies, and directs the application of specific security services, thereby simplifying the overall system architecture while enabling customized security implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of energy

If security services are selectively applied based on metadata, then resource consumption is reduced, but processing overhead increases due to metadata attachment and evaluation

Engineering Contradiction:
Improveresource consumptionVSAvoidprocessing overhead
Core Design Contradiction:
Loss of energyVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining security policies that map user parameters to appropriate security protocols. The security policy agent receives user parameters and evaluates them against predefined policies before security services are applied, allowing the system to make efficient decisions about resource allocation and service selection in advance, thereby reducing both resource consumption and processing overhead during actual security operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250150490A1Method for implementing cloud-based security protocols for a user device
Publication Date: 2025.05.08 CISCO TECHNOLOGY INC
  • US20250150490A1 patent drawing
  • US20250150490A1 patent drawing
  • US20250150490A1 patent drawing

AI summary

A method and system for implementing security policies for a user device based on one or more user device parameters. When a user device joins a domain, the security policy agent determines one or more security policies for the user device based on one or more parameters of the user device. The user parameters may include the type of user device, a user group, an application to be used, etc. The security polies are sent to the user device. The user device generates a data packet having metadata indicating the one or more device parameters. The data packet is sent to a remote security service where security policies are implemented based on the metadata.