Dynamic Micro-Segmentation Policy Switching for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security architectures and micro-segmentation policy controllers are inflexible and hardcoded to deny access to user devices outside the enterprise network, failing to adapt to location changes and implement location-specific access control policies, which can lead to vulnerabilities and unauthorized access.

Innovation Solution

A computer-implemented method and system that dynamically switches between micro-segmentation policies based on the current location of user devices, associating a security context with each device to enforce context-aware access controls, allowing selective and secured access to enterprise resources while accounting for changes in device location and trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network security architectures use hardcoded access control policies to deny external devices, then network security is improved, but adaptability to location changes and device mobility deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidadaptability to location changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control policies that automatically adjust based on device location, network context, and security requirements. The system transitions from static hardcoded rules to dynamic policy enforcement, allowing the network to adapt to mobile devices and location changes while maintaining security. This is achieved through continuous monitoring of device context and real-time policy evaluation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes access control parameters dynamically based on device location, network attachment, and security context. Instead of fixed allow/deny rules, the patent modifies policy parameters in real-time according to contextual factors such as whether the device is internal or external, the sensitivity of resources, and the current security posture, enabling both security and adaptability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network access control policies are hardcoded to deny external devices, then unauthorized access is prevented, but legitimate remote access is blocked

Engineering Contradiction:
Improveprevention of unauthorized accessVSAvoidlegitimate remote access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different access control policies to different devices based on their location and context. Instead of a blanket deny rule for all external devices, the system evaluates each device individually using contextual information (network attachment, device profile, user identity) to determine appropriate access rights. This allows legitimate remote devices to access necessary resources while maintaining protection against unauthorized access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously monitors device context, network conditions, and access patterns to dynamically adjust access control decisions. By implementing feedback loops that evaluate current device state and security context, the patent enables automatic differentiation between legitimate remote devices requiring access and unauthorized devices that should be blocked, resolving the contradiction between security and operational ease.

Inventive Principle:
Principle #23Feedback

3Reliability

If micro-segmentation policies are applied to all devices uniformly, then network security is enhanced, but device complexity and policy management burden increase

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements network micro-segmentation that divides the network into fine-grained security zones based on resource sensitivity, device type, and location. This segmentation enables targeted access control policies for different network segments rather than uniform policies across the entire network, enhancing security while reducing the complexity of managing device-specific configurations through centralized policy definition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates universal access control policies that automatically apply to multiple devices and scenarios through centralized management. Instead of configuring individual policies for each device, the patent defines multi-functional policies that can be dynamically instantiated across different devices based on their context, reducing policy management complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If access control decisions are based solely on device location, then policy enforcement is simplified, but context-aware security requirements are not met

Engineering Contradiction:
Improvepolicy enforcement simplicityVSAvoidcontext-aware security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extends access control decision-making from a single dimension (device location) to multiple dimensions by incorporating additional contextual factors such as device profile, user identity, resource sensitivity, network conditions, and temporal information. This multi-dimensional approach maintains policy enforcement simplicity through automated evaluation while achieving comprehensive context-aware security that single-dimensional location-based policies cannot provide.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11533312B2Dynamically enforcing context sensitive network access control policies
Publication Date: 2022.12.20 COLORTOKENS INC
  • US11533312B2 patent drawing
  • US11533312B2 patent drawing
  • US11533312B2 patent drawing

AI summary

The present disclosure envisages enforcing micro-segmentation policies on a user computer that intermittently migrates between a secured enterprise network and an unsecured network, for instance, a public network. The present disclosure envisages switching between appropriate micro-segmentation policies, in-line with the change in the current location of the user device, the change triggered by the user device migrating from the enterprise network to an unsecured network or vice-versa. The present disclosure envisages selectively enforcing micro-segmentation policies upon a user device based on the current location thereof, such that the micro-segmentation policies and the corresponding access permissions assigned to the user device differ in line with the current location of the user device, thereby exposing sensitive enterprise resources, forming a part of the enterprise network, in a selective and restricted manner, in line with the micro-segmentation policies enforced upon the user device based primarily on the current location of the user device.