ML Authentication Policy Generation for Multi-Tenant Network Zones
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems require manual and time-consuming establishment of authentication policies and network zones, which are inefficient and unreliable.
Innovation Solution
Utilization of machine learning models to automatically generate and update authentication policies and network zones based on data from multiple tenants, ensuring privacy preservation and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual establishment of authentication policies and network zones is used, then security control is achieved, but time consumption and inefficiency increase
Solution Approach 1:
The system enables self-service through ML models that automatically generate and update authentication policies and network zones without requiring manual configuration. The ML model analyzes tenant data and autonomously creates security policies, allowing the system to serve itself rather than relying on manual administrator input for each policy change.
Solution Approach 2:
The system performs preliminary action by pre-configuring authentication policies and network zones based on ML analysis before users need them. The ML model continuously learns from tenant data and prepares security policies in advance, so when policy updates are needed, they are already generated and ready for deployment, eliminating wait time.
2Reliability
If manual authentication policy configuration is used, then security rules are established, but reliability and consistency across tenants deteriorate
Solution Approach 1:
The ML model serves as a universal system that handles authentication policy generation for multiple tenants simultaneously. It analyzes data from various tenants and applies learned patterns across all tenants consistently, ensuring that the same security standards and rules are applied universally rather than requiring individual manual configuration for each tenant.
Solution Approach 2:
The system implements feedback loops where the ML model continuously monitors authentication patterns, security events, and policy effectiveness across tenants. This feedback is used to automatically refine and update policies, ensuring consistency and reliability while adapting to new threats and patterns without manual intervention.
3Measurement precision
If ML models use data from multiple tenants for policy generation, then efficiency and accuracy improve, but tenant data privacy may be compromised
Solution Approach 1:
The ML model acts as an intermediary that processes tenant data without exposing actual tenant information. The model learns from aggregated, anonymized patterns across tenants and generates policies based on these learned patterns rather than accessing or exposing raw tenant data, thus maintaining privacy while achieving accurate policy generation.
Solution Approach 2:
The system transforms raw tenant data into different parameter representations that preserve statistical patterns necessary for ML learning while removing personally identifiable information. By changing the parameters from raw data to aggregated statistical features, the system maintains measurement precision for policy accuracy while protecting tenant privacy.
Data Source
AI summary
An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.


