Dynamic Identity-Based Network Security Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Increasing frequency and sophistication of network attacks render existing network security measures inadequate, particularly due to vulnerabilities introduced by external access points and the complexity of modern networks.
Innovation Solution
A system for dynamically applying an identity-based security policy across all layers of a network, where a centralized security policy is enforced through multiple network layers using switch-based threat assessment and management systems, allowing for real-time anomaly detection and mitigation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If external network access points are provided to enable users to retrieve and exchange data, then network accessibility and ease of operation are improved, but network vulnerability to malicious attacks increases
Solution Approach 1:
The patent introduces a network access controller as an intermediary component that sits between external access points and internal network systems. This controller dynamically evaluates user credentials, device states, and traffic patterns to mediate access decisions, allowing legitimate user access while blocking malicious traffic before it reaches sensitive network resources
Solution Approach 2:
The patent implements dynamic security policies that adapt in real-time based on observed network conditions, user behavior patterns, and threat assessments. Access control decisions are not static but change dynamically according to the current security context, enabling the system to maintain accessibility for legitimate users while responding to emerging threats
2Reliability
If network security measures are increased to protect against sophisticated attacks, then network reliability is improved, but device complexity and difficulty of operation increase
Solution Approach 1:
The patent consolidates multiple security functions including authentication, authorization, encryption, and threat detection into a unified network access controller. This merging of previously separate security components into a single integrated system reduces overall system complexity while maintaining comprehensive security protection across all network layers
Solution Approach 2:
The network access controller is designed as a universal security platform that performs multiple security functions simultaneously - it handles user authentication, device validation, traffic inspection, and threat response all through a single system. This multi-functionality eliminates the need for multiple separate security devices and simplifies security management
3Adaptability or versatility
If centralized security policy enforcement is implemented across all network layers, then adaptability to threats is improved, but real-time processing speed and productivity may be reduced
Solution Approach 1:
The patent implements preliminary security assessments by evaluating user credentials, device states, and traffic patterns before granting network access. By performing security validations in advance and caching authentication results, the system establishes security policies proactively rather than reacting to each individual packet, thereby maintaining both security adaptability and processing efficiency
Solution Approach 2:
The network access controller applies partial security inspection to different types of traffic based on risk assessment. Low-risk traffic from authenticated users receives expedited processing with minimal inspection, while suspicious or high-risk traffic undergoes more thorough analysis. This selective application of security measures maintains productivity for legitimate traffic while ensuring thorough threat detection when needed
Data Source
AI summary
A method of dynamically applying a control policy to a network is described. A network layer of a plurality of network layers associated with user traffic is determined. A portion of a control policy corresponding to the network layer and the user traffic is accessed. Then, the portion is sent to a security device associated with the network layer, the portion being configured to be applied by the security device to the network layer and the user traffic.


