Cloud Secure Web Gateway Dynamic User Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure Web Gateways (SWGs) face challenges in dynamically associating and enforcing policies on traffic from mobile devices, especially with encrypted communications and non-standard protocols, which complicates user identification and access control in cloud-based environments.
Innovation Solution
A cloud-based SWG system dynamically associates traffic with users, maintaining these associations over time and sharing them across a distributed security system to apply policies such as allowing, blocking, or cautioning traffic, and logs the traffic based on these associations, using a network interface, processor, and memory to execute instructions for authentication and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional HTTP proxy authentication mechanisms are used, then authenticated traffic can be identified, but unknown traffic from mobile devices using non-standard protocols and encryption cannot be properly associated with users
Solution Approach 1:
The patent introduces an intermediary mechanism that captures traffic at the network interface level before it reaches its destination. This intermediary captures both authenticated HTTP traffic and unknown encrypted traffic from mobile devices, acting as a mediator between traditional authentication systems and modern encrypted communications. The system associates unknown traffic with users through network-level observation without requiring the traffic to follow standard HTTP protocols.
Solution Approach 2:
The patent segments traffic handling into multiple pathways: one for traditional authenticated HTTP traffic and another for unknown encrypted traffic from mobile devices. By dividing the traffic processing into separate handling mechanisms, the system can apply appropriate identification methods to each type, maintaining precision for both authenticated and unknown traffic types.
2Productivity
If cloud-based distributed security system is implemented, then scalability and sharing of dynamic associations are improved, but system complexity increases
Solution Approach 1:
The patent creates a universal dynamic association mechanism that functions across multiple cloud-based secure web gateways. The same association data structure and sharing protocol work consistently across different gateways in the distributed system, allowing the system to scale without increasing complexity. Each gateway performs the same functions and uses the same methods for creating and sharing associations.
Solution Approach 2:
The patent implements feedback loops where gateways share association data with other gateways in the distributed system. This feedback mechanism allows the system to maintain consistent user associations across multiple gateways, enabling scalability while managing complexity through standardized information exchange protocols.
3Measurement precision
If dynamic association is maintained over time, then user identification accuracy improves, but processing time and resource consumption increase
Solution Approach 1:
The patent performs preliminary actions by capturing and associating traffic at the network interface level as early as possible in the traffic flow. By establishing user associations before traffic needs to be processed for security policies, the system avoids repeated identification operations and reduces processing time while maintaining accurate user identification throughout the session.
Data Source
AI summary
A cloud-based secure Web gateway, a cloud-based secure Web method, and a network deliver a secure Web gateway (SWG) as a cloud-based service to organizations and provide dynamic user identification and policy enforcement therein. As a cloud-based service, the SWG systems and methods provide scalability and capability of accommodating multiple organizations therein with proper isolation therebetween. There are two basic requirements for the cloud-based SWG: (i) Having some means of forwarding traffic from the organization or its users to the SWG nodes, and (ii) Being able to authenticate the organization and users for policy enforcement and access logging. The SWG systems and methods dynamically associate traffic to users regardless of the source (device, location, encryption, application type, etc.), and once traffic is tagged to a user/organization, various polices can be enforced and audit logs of user access can be maintained.


