Dynamic Access Control System for Zero Trust Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional networks manage user access through VPNs, which provide broad access but increase security risks, are complex to manage, especially for large and distributed user bases, and lack client control over authorization processes.
Innovation Solution
A dynamic access control system (DACS) that implements a 'zero trust' security framework, allowing clients to define custom access policies based on various trust information sources, enabling fine-grained access control and routing decisions without requiring broad network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPNs are used to manage user access, then broad network access is provided, but security risks increase and management complexity increases
Solution Approach 1:
The patent segments the network into multiple network segments and divides user access control into granular policy rules. Instead of providing broad VPN access to the entire network, the system creates separate segments for different resources and applies specific access policies to each segment, thereby reducing management complexity while maintaining security.
Solution Approach 2:
The patent implements dynamic access control policies that can be adjusted in real-time based on user identity, device state, and contextual factors. The system evaluates trust information dynamically and adjusts access permissions accordingly, replacing static VPN configurations with adaptive policy-based control that simplifies management for distributed user bases.
2Ease of operation
If VPNs are used to manage user access, then broad network access is provided, but security risks increase
Solution Approach 1:
The patent segments the network into isolated network segments, each with its own access control policies. This segmentation limits the attack surface and contains security risks to specific segments rather than exposing the entire network, thereby maintaining security while providing broad access to authorized users.
Solution Approach 2:
The patent introduces an intermediary access control system that sits between users and network resources. This intermediary evaluates trust information, enforces security policies, and mediates access requests, providing security verification without requiring users to establish direct VPN connections to the entire network.
3Reliability
If fine-grained access control is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal access control system that handles multiple security policies, trust evaluations, and network segments through a single integrated platform. The system provides multi-functional capabilities including policy enforcement, trust information collection, dynamic decision-making, and audit logging, thereby achieving fine-grained security control without proportionally increasing complexity.
Solution Approach 2:
The patent enables the access control system to automatically evaluate trust information, enforce policies, and make access decisions without requiring manual intervention for each request. The system self-manages policy evaluation, trust scoring, and access granting/denying, reducing operational complexity while maintaining fine-grained security control.
4Adaptability or versatility
If custom access policies are defined by clients, then client control over authorization is improved, but device complexity increases
Solution Approach 1:
The patent enables clients to define and manage their own custom access policies through a self-service interface. Clients can configure policy rules, specify trust information sources, and set access conditions without requiring vendor intervention or complex configuration procedures. The system automatically processes these client-defined policies and enforces them across the network.
Solution Approach 2:
The patent allows clients to pre-define access policies and trust information sources before actual access requests occur. Clients can configure policy templates, specify evaluation criteria, and set up trust information collection methods in advance, thereby simplifying real-time policy enforcement while maintaining high adaptability to different client requirements.
Data Source
AI summary
Systems and methods are provided for creating and running an instance of a dynamic access control system (DACS). Trust providers may be defined in a trust broker of the DACS such that trust information associated with the trust providers can be used to create a custom data structure. Resources and resource groups may be defined in the DACS. Policies may be configured or coded in the DACS to map the custom data structure to recourses or resources groups. Additionally, policies may be configured or coded in the DACS to route the data structure and request to network segments or shared with other parties.


