ML Authentication Policy Generation for Multi-Tenant Network Zones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems require manual and time-consuming establishment of authentication policies and network zones, which are inefficient and unreliable.

Innovation Solution

Utilization of machine learning models to automatically generate and update authentication policies and network zones based on data from multiple tenants, ensuring privacy preservation and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual establishment of authentication policies and network zones is used, then security control is achieved, but time consumption and inefficiency increase

Engineering Contradiction:
Improvepolicy establishment efficiencyVSAvoidtime for manual policy configuration
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables self-service through ML models that automatically generate and update authentication policies and network zones without requiring manual configuration. The ML model analyzes tenant data and autonomously creates security policies, allowing the system to serve itself rather than relying on manual administrator input for each policy change.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring authentication policies and network zones based on ML analysis before users need them. The ML model continuously learns from tenant data and prepares security policies in advance, so when policy updates are needed, they are already generated and ready for deployment, eliminating wait time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual authentication policy configuration is used, then security rules are established, but reliability and consistency across tenants deteriorate

Engineering Contradiction:
Improvepolicy consistencyVSAvoidmanual configuration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The ML model serves as a universal system that handles authentication policy generation for multiple tenants simultaneously. It analyzes data from various tenants and applies learned patterns across all tenants consistently, ensuring that the same security standards and rules are applied universally rather than requiring individual manual configuration for each tenant.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback loops where the ML model continuously monitors authentication patterns, security events, and policy effectiveness across tenants. This feedback is used to automatically refine and update policies, ensuring consistency and reliability while adapting to new threats and patterns without manual intervention.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If ML models use data from multiple tenants for policy generation, then efficiency and accuracy improve, but tenant data privacy may be compromised

Engineering Contradiction:
Improvepolicy accuracyVSAvoiddata privacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The ML model acts as an intermediary that processes tenant data without exposing actual tenant information. The model learns from aggregated, anonymized patterns across tenants and generates policies based on these learned patterns rather than accessing or exposing raw tenant data, thus maintaining privacy while achieving accurate policy generation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms raw tenant data into different parameter representations that preserve statistical patterns necessary for ML learning while removing personally identifiable information. By changing the parameters from raw data to aggregated statistical features, the system maintains measurement precision for policy accuracy while protecting tenant privacy.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260058998A1Dynamic policy and network security zone generation
Publication Date: 2026.02.26 OKTA INC
  • US20260058998A1 patent drawing
  • US20260058998A1 patent drawing
  • US20260058998A1 patent drawing

AI summary

An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.