ML-Driven Authentication Policy and Network Zone Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems require manual and time-consuming establishment of authentication policies and network zones, which are inefficient and unreliable.

Innovation Solution

Utilization of machine learning models to automatically generate and update authentication policies and network zones based on data from multiple tenants, ensuring privacy preservation and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual establishment of authentication policies and network zones is used, then users have full control over security configurations, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improveease of policy establishmentVSAvoidtime for manual configuration
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables self-service through ML-driven automatic policy generation. The ML model analyzes tenant data, application patterns, and security requirements to autonomously generate authentication policies and network zone configurations, eliminating the need for manual intervention while maintaining security effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual configuration process with an intelligent automated system. The ML model processes security requirements, tenant data, and application metadata to automatically generate and update policies, substituting human operators with an automated intelligent system that operates continuously and efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If ML models automatically generate policies based on multi-tenant data, then efficiency and reliability improve, but privacy preservation challenges arise

Engineering Contradiction:
Improvepolicy management efficiencyVSAvoidtenant data privacy
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system segments tenant data processing through isolated ML model instances or dedicated processing pipelines for each tenant. This segmentation allows the ML model to learn from multi-tenant patterns while maintaining data isolation, ensuring that each tenant's data contributes to policy generation without exposing sensitive information to other tenants.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces privacy-preserving intermediaries such as data anonymization layers, federated learning mechanisms, or secure enclaves that mediate between multi-tenant data and the ML model. These intermediaries enable the system to leverage multi-tenant data for improved policy generation while preventing direct access to sensitive tenant information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication policies are manually established, then security control is maintained, but the system lacks adaptability to changing threats and tenant needs

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic authentication policies that automatically adapt to changing conditions. The ML model continuously monitors tenant data, application usage patterns, and security threats, then dynamically updates authentication policies and network zone configurations in real-time, maintaining both security control and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback loops where the ML model continuously receives information from authentication events, security incidents, and tenant operations. This feedback enables the system to learn from actual usage patterns and security outcomes, automatically refining and updating policies to maintain reliable security control while adapting to new threats and requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12574420B2Dynamic policy and network security zone generation
Publication Date: 2026.03.10 OKTA INC
  • US12574420B2 patent drawing
  • US12574420B2 patent drawing
  • US12574420B2 patent drawing

AI summary

An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.