Dynamic Hyper Context Network Segmentation for Zero Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contemporary network segmentation methods, relying on NAC and VLANs, are complex to manage, fail to segment based on device risk and compliance, and lack the entire device context, limiting their ability to make informed segmentation decisions.

Innovation Solution

The system dynamically assigns computing devices to network segments by using a hyper context network sensor, hyper context cloud server, and cloud controller to analyze network and device properties, applying policies to segment devices based on their hyper context, risk, and compliance posture, enabling granular access control and zero-trust architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional NAC and VLAN-based segmentation is used, then network segmentation is achieved, but the system complexity increases and management becomes difficult

Engineering Contradiction:
Improvenetwork segmentationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the network into multiple segments based on device risk and compliance posture. Instead of using traditional VLANs that segment based on location or user, the system segments devices dynamically into different network segments according to their security context, thereby achieving segmentation without increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network sensor and controller as intermediary components that automatically assess device context and enforce segmentation policies. These intermediaries handle the complexity of segmentation decisions, allowing the core network infrastructure to remain simple while achieving sophisticated segmentation through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional VLAN assignment based on user authentication is used, then devices are segmented, but the system lacks device context information for informed segmentation decisions

Engineering Contradiction:
Improvesegmentation decision accuracyVSAvoiddevice context information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs preliminary assessment of device context information before making segmentation decisions. The network sensor collects and analyzes device properties, risk factors, and compliance posture before the device is fully integrated into the network, ensuring that segmentation decisions are made with complete information available.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback by monitoring device context information and dynamically adjusting segmentation based on real-time assessments. The network sensor continuously evaluates device risk and compliance posture, providing feedback to the controller which then adjusts network segment assignment accordingly, ensuring decisions are always based on current device context.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If static network segmentation is used, then network stability is maintained, but the system cannot adapt to changing device risk and compliance postures

Engineering Contradiction:
Improvedynamic segmentationVSAvoidnetwork stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent implements dynamic segmentation where network segment assignments are not fixed but continuously adjusted based on device risk and compliance posture. The system automatically reassigns devices to different network segments as their security context changes, enabling the network to adapt to changing conditions while maintaining stability through automated policy enforcement.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12107898B2Dynamic hyper context-driven microsegmentation
Publication Date: 2024.10.01 NETSKOPE INC
  • US12107898B2 patent drawing
  • US12107898B2 patent drawing
  • US12107898B2 patent drawing

AI summary

Systems and methods for dynamic, hyper context-based microsegmentation are described. In one aspect, a computing device is detected on a network. A network hyper context is assigned to the computing device based on network properties and computing device properties associated with the computing device. A policy defining a segment identifier identifying a network segment and corresponding to the network hyper context is accessed. The segment identifier is assigned to the computing device. The computing device is segmented onto the network responsive to detecting the computing device.