Context-Aware SASE Engine for Dynamic Security Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security access service edge (SASE) framework provides a single security approach that is not optimal for specific endpoints, applications, or tenants, lacking the flexibility to adapt dynamically to changing security needs and behaviors.

Innovation Solution

A context-aware SASE engine is deployed on network edge devices to generate security profiles based on endpoint information and default profiles from enterprise networks, enabling dynamic and autonomous security adjustments tailored to specific endpoints, applications, and tenants, with feedback loops for continuous updates and vulnerability management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single security approach is used for all users in the SASE framework, then the system is simple to manage and implement, but it cannot provide optimal security capabilities tailored to specific endpoints, applications, or tenants

Engineering Contradiction:
Improvesecurity capability adaptabilityVSAvoidsecurity system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the unified security approach into multiple tenant-specific security profiles, each tailored to specific endpoints, applications, or tenants. The SASE framework divides security capabilities into discrete, configurable units that can be independently customized and applied to different segments of the network, allowing optimal security for each segment without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security profiles that can be automatically adjusted based on contextual information such as endpoint behavior, application performance metrics, and security threats. The system dynamically modifies security parameters in real-time without requiring manual reconfiguration, enabling adaptability while maintaining manageable complexity through automated decision-making processes.

Inventive Principle:
Principle #15Dynamics

2Reliability

If context-aware security profiles are generated for each endpoint, then optimal security capabilities are provided, but the processing time and computational resources increase

Engineering Contradiction:
Improvesecurity evaluation accuracyVSAvoidsecurity profile generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-generates and caches security profiles based on endpoint characteristics, application types, and tenant requirements before actual security evaluation is needed. By preparing security configurations in advance and storing them for quick retrieval, the system reduces real-time processing requirements while maintaining high reliability in security assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that use historical security evaluation data to continuously refine and optimize security profiles. The system learns from past security events, endpoint behaviors, and threat patterns, automatically adjusting profiles to improve accuracy while reducing the computational overhead required for generation and evaluation over time.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11979375B2Context-aware secure access service edge (SASE) engine
Publication Date: 2024.05.07 CISCO TECHNOLOGY INC
  • US11979375B2 patent drawing
  • US11979375B2 patent drawing
  • US11979375B2 patent drawing

AI summary

Techniques for a context-aware secure access service edge (SASE) engine for generating security profile(s) associated with endpoint device(s) accessing the network and using the security profile(s) to evaluate a traffic flow from the endpoint device(s). The SASE engine may execute on an edge device of a computing resource network and may be configured to maintain a security profile database including an endpoint security profile mapping. Endpoint device(s) accessing the network may share endpoint, application, and/or user specific information with the SASE engine so that the SASE engine may generate a security profile specific to the endpoint, application, and/or user. Additionally, an enterprise network, associated with endpoint device(s) accessing the network, may provide default SASE security profile templates to the SASE engine. Further, a feedback loop may be established between the SASE engine and the endpoint device(s), enabling the SASE engine with the ability to autonomously and dynamically update security profiles.