Cloud Security System for Dynamic Mobile Device Risk Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Network Access Control (NAC) systems are static and limited in scope, failing to effectively manage the growing complexity of mobile devices accessing cloud services across diverse operating systems and network topologies, leading to compatibility issues and increased security risks due to inadequate risk profiling and management.

Innovation Solution

A cloud-based security system performs multidimensional risk profiling of mobile devices, combining device, application, user, and environmental risks to dynamically assess and manage access, using a mobile application for unified service discovery and secure connectivity, eliminating the need for multiple applications and reducing administrative burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional static NAC systems are used, then system simplicity is maintained, but security effectiveness deteriorates due to inadequate risk profiling for diverse mobile devices

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidNAC system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The NAC system transitions from static access control to dynamic risk-based profiling. The system continuously assesses device risk profiles by analyzing posture data, device fingerprints, and contextual information, then dynamically adjusts access decisions based on calculated risk scores. This enables the system to adapt to diverse mobile devices and changing security conditions without requiring complex manual configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of risk assessment from binary (access/denial) to multi-dimensional scoring. By calculating risk scores based on multiple factors including device posture, application risk, user risk, and environmental risk, the system achieves more nuanced security decisions. This parameter transformation allows effective security profiling across diverse device types without proportionally increasing system complexity.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple applications are deployed for different services, then service coverage is improved, but device complexity and user burden increase

Engineering Contradiction:
Improveservice coverageVSAvoidnumber of applications
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A single unified application provides access to multiple cloud services (VPN, web security, email, file sharing) that previously required separate applications. The application performs multidimensional risk profiling and service discovery to dynamically determine which services to connect to, consolidating multiple functions into one universal access point and reducing device complexity while maintaining comprehensive service coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges multiple separate security applications (VPN client, web security firewall, email client) into a single unified application. This consolidation integrates multiple security functions and service access points into one application interface, reducing the number of applications users must manage while maintaining the functional capabilities of each individual service.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If manual configuration is required for each application, then security control is precise, but productivity deteriorates due to time-consuming setup and management

Engineering Contradiction:
Improvesecurity controlVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The unified application performs automatic service discovery and configuration based on multidimensional risk profiling. Instead of requiring manual user setup, the application autonomously assesses device posture, discovers available cloud services, determines appropriate connections, and configures access parameters automatically. This self-service capability maintains precise security control through risk-based decisions while eliminating time-consuming manual configuration steps.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary risk assessment and service discovery before establishing connections. By pre-evaluating device fingerprints, posture data, and contextual risk factors, the system prepares access configurations in advance, enabling automatic connection establishment without requiring users to manually configure each service at the moment of need.

Inventive Principle:
Principle #10Preliminary action

4Stability of the object's composition

If static NAC policies are enforced, then policy consistency is maintained, but adaptability to changing network conditions and device types deteriorates

Engineering Contradiction:
Improvepolicy consistencyVSAvoidadaptability to network conditions
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The NAC system implements continuous feedback loops where device posture data, network conditions, and access outcomes are constantly monitored and fed back into the risk profiling engine. This feedback mechanism allows the system to maintain consistent security policies while adapting to changing conditions by adjusting risk scores and access decisions based on real-time information about device state, network environment, and service availability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10225740B2Multidimensional risk profiling for network access control of mobile devices through a cloud based security system
Publication Date: 2019.03.05 ZSCALER INC
  • US10225740B2 patent drawing
  • US10225740B2 patent drawing
  • US10225740B2 patent drawing

AI summary

Systems and methods implemented in a cloud node in a cloud based security system for network access control of a mobile device based on multidimensional risk profiling thereof include receiving posture data from the mobile device; determining a device fingerprint and a risk index of the mobile device based on the posture data; and, responsive to a request by the mobile device for network resources through the cloud based security system, performing a multidimensional risk analysis based on the device fingerprint and the risk index and allowing or denying the request based on the multidimensional risk analysis.