Dynamic Micro-Segmentation Policy Switching for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security architectures and micro-segmentation policy controllers are inflexible and hardcoded to deny access to user devices outside the enterprise network, failing to adapt to location changes and implement location-specific access control policies, which can lead to vulnerabilities and unauthorized access.
Innovation Solution
A computer-implemented method and system that dynamically switches between micro-segmentation policies based on the current location of user devices, associating a security context with each device to enforce context-aware access controls, allowing selective and secured access to enterprise resources while accounting for changes in device location and trustworthiness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network security architectures use hardcoded access control policies to deny external devices, then network security is improved, but adaptability to location changes and device mobility deteriorates
Solution Approach 1:
The patent implements dynamic access control policies that automatically adjust based on device location, network context, and security requirements. The system transitions from static hardcoded rules to dynamic policy enforcement, allowing the network to adapt to mobile devices and location changes while maintaining security. This is achieved through continuous monitoring of device context and real-time policy evaluation.
Solution Approach 2:
The system changes access control parameters dynamically based on device location, network attachment, and security context. Instead of fixed allow/deny rules, the patent modifies policy parameters in real-time according to contextual factors such as whether the device is internal or external, the sensitivity of resources, and the current security posture, enabling both security and adaptability.
2Reliability
If network access control policies are hardcoded to deny external devices, then unauthorized access is prevented, but legitimate remote access is blocked
Solution Approach 1:
The patent applies different access control policies to different devices based on their location and context. Instead of a blanket deny rule for all external devices, the system evaluates each device individually using contextual information (network attachment, device profile, user identity) to determine appropriate access rights. This allows legitimate remote devices to access necessary resources while maintaining protection against unauthorized access.
Solution Approach 2:
The system continuously monitors device context, network conditions, and access patterns to dynamically adjust access control decisions. By implementing feedback loops that evaluate current device state and security context, the patent enables automatic differentiation between legitimate remote devices requiring access and unauthorized devices that should be blocked, resolving the contradiction between security and operational ease.
3Reliability
If micro-segmentation policies are applied to all devices uniformly, then network security is enhanced, but device complexity and policy management burden increase
Solution Approach 1:
The patent implements network micro-segmentation that divides the network into fine-grained security zones based on resource sensitivity, device type, and location. This segmentation enables targeted access control policies for different network segments rather than uniform policies across the entire network, enhancing security while reducing the complexity of managing device-specific configurations through centralized policy definition.
Solution Approach 2:
The system creates universal access control policies that automatically apply to multiple devices and scenarios through centralized management. Instead of configuring individual policies for each device, the patent defines multi-functional policies that can be dynamically instantiated across different devices based on their context, reducing policy management complexity while maintaining comprehensive security coverage.
4Ease of operation
If access control decisions are based solely on device location, then policy enforcement is simplified, but context-aware security requirements are not met
Solution Approach 1:
The patent extends access control decision-making from a single dimension (device location) to multiple dimensions by incorporating additional contextual factors such as device profile, user identity, resource sensitivity, network conditions, and temporal information. This multi-dimensional approach maintains policy enforcement simplicity through automated evaluation while achieving comprehensive context-aware security that single-dimensional location-based policies cannot provide.
Data Source
AI summary
The present disclosure envisages enforcing micro-segmentation policies on a user computer that intermittently migrates between a secured enterprise network and an unsecured network, for instance, a public network. The present disclosure envisages switching between appropriate micro-segmentation policies, in-line with the change in the current location of the user device, the change triggered by the user device migrating from the enterprise network to an unsecured network or vice-versa. The present disclosure envisages selectively enforcing micro-segmentation policies upon a user device based on the current location thereof, such that the micro-segmentation policies and the corresponding access permissions assigned to the user device differ in line with the current location of the user device, thereby exposing sensitive enterprise resources, forming a part of the enterprise network, in a selective and restricted manner, in line with the micro-segmentation policies enforced upon the user device based primarily on the current location of the user device.


