Cloud Secure Web Gateway Dynamic User Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure Web Gateways (SWGs) face challenges in dynamically associating and enforcing policies on traffic from mobile devices, especially with encrypted communications and non-standard protocols, which complicates user identification and access control in cloud-based environments.

Innovation Solution

A cloud-based SWG system dynamically associates traffic with users, maintaining these associations over time and sharing them across a distributed security system to apply policies such as allowing, blocking, or cautioning traffic, and logs the traffic based on these associations, using a network interface, processor, and memory to execute instructions for authentication and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional HTTP proxy authentication mechanisms are used, then authenticated traffic can be identified, but unknown traffic from mobile devices using non-standard protocols and encryption cannot be properly associated with users

Engineering Contradiction:
Improvecompatibility with various devices and encryption methodsVSAvoiduser identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary mechanism that captures traffic at the network interface level before it reaches its destination. This intermediary captures both authenticated HTTP traffic and unknown encrypted traffic from mobile devices, acting as a mediator between traditional authentication systems and modern encrypted communications. The system associates unknown traffic with users through network-level observation without requiring the traffic to follow standard HTTP protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments traffic handling into multiple pathways: one for traditional authenticated HTTP traffic and another for unknown encrypted traffic from mobile devices. By dividing the traffic processing into separate handling mechanisms, the system can apply appropriate identification methods to each type, maintaining precision for both authenticated and unknown traffic types.

Inventive Principle:
Principle #1Segmentation

2Productivity

If cloud-based distributed security system is implemented, then scalability and sharing of dynamic associations are improved, but system complexity increases

Engineering Contradiction:
Improvescalability of security systemVSAvoidcomplexity of distributed system architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal dynamic association mechanism that functions across multiple cloud-based secure web gateways. The same association data structure and sharing protocol work consistently across different gateways in the distributed system, allowing the system to scale without increasing complexity. Each gateway performs the same functions and uses the same methods for creating and sharing associations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback loops where gateways share association data with other gateways in the distributed system. This feedback mechanism allows the system to maintain consistent user associations across multiple gateways, enabling scalability while managing complexity through standardized information exchange protocols.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If dynamic association is maintained over time, then user identification accuracy improves, but processing time and resource consumption increase

Engineering Contradiction:
Improveuser identification accuracyVSAvoidprocessing time for traffic association
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by capturing and associating traffic at the network interface level as early as possible in the traffic flow. By establishing user associations before traffic needs to be processed for security policies, the system avoids repeated identification operations and reduces processing time while maintaining accurate user identification throughout the session.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9065800B2Dynamic user identification and policy enforcement in cloud-based secure web gateways
Publication Date: 2015.06.23 ZSCALER INC
  • US9065800B2 patent drawing
  • US9065800B2 patent drawing
  • US9065800B2 patent drawing

AI summary

A cloud-based secure Web gateway, a cloud-based secure Web method, and a network deliver a secure Web gateway (SWG) as a cloud-based service to organizations and provide dynamic user identification and policy enforcement therein. As a cloud-based service, the SWG systems and methods provide scalability and capability of accommodating multiple organizations therein with proper isolation therebetween. There are two basic requirements for the cloud-based SWG: (i) Having some means of forwarding traffic from the organization or its users to the SWG nodes, and (ii) Being able to authenticate the organization and users for policy enforcement and access logging. The SWG systems and methods dynamically associate traffic to users regardless of the source (device, location, encryption, application type, etc.), and once traffic is tagged to a user/organization, various polices can be enforced and audit logs of user access can be maintained.