Location-Based Application Segments for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of cloud-based applications and the extension of enterprise networks beyond traditional perimeters have resulted in heightened security risks, including data breaches on unsecured devices and vulnerabilities in accessing sensitive applications.

Innovation Solution

The implementation of a cloud-based system that generates location-based application segments by leveraging transactional data and location information to adjust application segmentation factor thresholds, thereby reducing the attack surface and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter-based security is used, then security for on-premises resources is maintained, but security for cloud-based applications and mobile users deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies segmentation by dividing applications into location-based segments (e.g., office locations, remote locations, mobile locations) and user groups into location-based categories. This allows security policies to be applied at the application level rather than network level, enabling differentiated security controls for different application types and locations while maintaining adaptability to various access scenarios.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional network perimeter-based security to application-level security by adding a new dimension of classification based on application location and type. This dimensional shift enables security controls to operate independently of network topology, addressing both on-premises and cloud-based applications uniformly while maintaining adaptability to diverse access patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If application segmentation is performed without location data, then segmentation process is simpler, but security effectiveness deteriorates

Engineering Contradiction:
Improvesegmentation process complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent performs preliminary classification of applications into segments based on location data before applying security policies. By pre-categorizing applications into location-based segments (office, remote, mobile) and pre-defining access rules for each segment, the system simplifies the overall security management process while enhancing effectiveness through location-aware segmentation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter used for application classification from traditional network-based criteria to location-based criteria. This parameter change enables more effective security segmentation by considering where applications are accessed from rather than where they are hosted, thereby improving security effectiveness without significantly increasing process complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If location-based application segments are generated, then security against lateral movement is improved, but data processing requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoiddata processing volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts location information from transactional data and uses it to classify applications into segments. By extracting only the necessary location metadata rather than processing complete transactional records, the system reduces data processing volume while maintaining the ability to generate effective location-based application segments for security control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by processing only the location-related portions of transactional data rather than analyzing all data fields. This selective processing approach reduces the quantity of data that needs to be processed while still providing sufficient information to generate accurate location-based segments for security purposes.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If application access is restricted based on location segments, then security is enhanced, but user accessibility may deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing differentiated access policies for different application segments based on their location characteristics. Each application segment receives customized access controls appropriate to its deployment environment (office, remote, or mobile), allowing security to be enhanced where needed while maintaining ease of access for legitimate users through location-appropriate policies.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250291943A1Systems and methods for generating location-based application segments
Publication Date: 2025.09.18 ZSCALER INC
  • US20250291943A1 patent drawing
  • US20250291943A1 patent drawing
  • US20250291943A1 patent drawing

AI summary

Systems and methods for generating location-based application segments include obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users; obtaining location data associated with the plurality of applications; and generating one or more application segments based on the transactional data and the location data. In various embodiments, the location data can be leveraged to alter various application segmentation factor thresholds for adapting the likelihood of applications to be grouped together.