Cloud Secure Web Gateway Dynamic User Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure Web Gateways (SWGs) face challenges in dynamically associating and enforcing policies on traffic from mobile devices, especially with encrypted communications and apps that ignore HTTP protocols, making it difficult to maintain user identification and apply security policies effectively.

Innovation Solution

A cloud-based SWG system dynamically associates traffic with users, maintaining this association over time, and shares it across a distributed security system to apply policies such as allowing, blocking, or cautioning traffic, while logging these actions, even with encrypted or unknown traffic sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional HTTP proxy authentication mechanisms (cookies, HTTP authentication) are used to authenticate users and associate transactions, then user identification works for standards-compliant browsers, but mobile applications that use encryption techniques ignore these mechanisms and cannot be properly authenticated or associated with users

Engineering Contradiction:
Improvecompatibility with different traffic sourcesVSAvoiduser identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the authentication parameters from HTTP-specific mechanisms (cookies, HTTP authentication headers) to application-layer parameters that can be extracted from encrypted mobile application traffic. This includes analyzing application metadata, device identifiers, and communication patterns to dynamically associate traffic with users, thereby maintaining user identification accuracy across different traffic sources while improving compatibility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary authentication layer between the mobile application and the Secure Web Gateway. This intermediary component intercepts and analyzes encrypted traffic, extracts identifying parameters, and creates associations without requiring the mobile application to implement standard HTTP authentication mechanisms. This mediator enables reliable user identification for both traditional browsers and modern mobile applications

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SSL encryption is used to protect Internet traffic, then security is improved, but intermediate proxies cannot enforce policies without performing man-in-the-middle attacks to break SSL tunnels

Engineering Contradiction:
ImprovesecurityVSAvoidpolicy enforcement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts authentication and identification information from encrypted SSL traffic without breaking the encryption tunnel. By analyzing metadata, headers, and traffic patterns at the application layer, the system extracts sufficient information to authenticate users and enforce policies while leaving the encrypted payload intact, thus maintaining security while simplifying policy enforcement complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary authentication and user association actions before policy enforcement occurs. By establishing user identities and traffic associations upfront through analysis of encrypted traffic characteristics, the system prepares all necessary authentication data in advance, allowing policy engines to operate on already-authenticated traffic without needing to break SSL encryption

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If a single SWG enforces policies locally, then policy enforcement is straightforward, but distributed SWGs cannot share user associations and dynamic policy enforcement across multiple gateways is difficult

Engineering Contradiction:
Improvedistributed system capabilityVSAvoiduser association data
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent creates a universal user association data structure and protocol that can be shared across multiple distributed SWGs. This universal format includes user identifiers, traffic characteristics, and association metadata that can be exchanged between gateways through standardized interfaces. This enables any SWG in the distributed system to understand and enforce policies for any user, regardless of which gateway initially authenticated the user, thereby maintaining user association data across the distributed system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9531758B2Dynamic user identification and policy enforcement in cloud-based secure web gateways
Publication Date: 2016.12.27 ZSCALER INC
  • US9531758B2 patent drawing
  • US9531758B2 patent drawing
  • US9531758B2 patent drawing

AI summary

A cloud-based secure Web gateway, a cloud-based secure Web method, and a network deliver a secure Web gateway (SWG) as a cloud-based service to organizations and provide dynamic user identification and policy enforcement therein. As a cloud-based service, the SWG systems and methods provide scalability and capability of accommodating multiple organizations therein with proper isolation therebetween. There are two basic requirements for the cloud-based SWG: (i) Having some means of forwarding traffic from the organization or its users to the SWG nodes, and (ii) Being able to authenticate the organization and users for policy enforcement and access logging. The SWG systems and methods dynamically associate traffic to users regardless of the source (device, location, encryption, application type, etc.), and once traffic is tagged to a user/organization, various polices can be enforced and audit logs of user access can be maintained.