ML-Driven Authentication Policy and Network Zone Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems require manual and time-consuming establishment of authentication policies and network zones, which are inefficient and unreliable.
Innovation Solution
Utilization of machine learning models to automatically generate and update authentication policies and network zones based on data from multiple tenants, ensuring privacy preservation and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual establishment of authentication policies and network zones is used, then users have full control over security configurations, but the process becomes time-consuming and inefficient
Solution Approach 1:
The system enables self-service through ML-driven automatic policy generation. The ML model analyzes tenant data, application patterns, and security requirements to autonomously generate authentication policies and network zone configurations, eliminating the need for manual intervention while maintaining security effectiveness.
Solution Approach 2:
The patent replaces the mechanical manual configuration process with an intelligent automated system. The ML model processes security requirements, tenant data, and application metadata to automatically generate and update policies, substituting human operators with an automated intelligent system that operates continuously and efficiently.
2Productivity
If ML models automatically generate policies based on multi-tenant data, then efficiency and reliability improve, but privacy preservation challenges arise
Solution Approach 1:
The system segments tenant data processing through isolated ML model instances or dedicated processing pipelines for each tenant. This segmentation allows the ML model to learn from multi-tenant patterns while maintaining data isolation, ensuring that each tenant's data contributes to policy generation without exposing sensitive information to other tenants.
Solution Approach 2:
The patent introduces privacy-preserving intermediaries such as data anonymization layers, federated learning mechanisms, or secure enclaves that mediate between multi-tenant data and the ML model. These intermediaries enable the system to leverage multi-tenant data for improved policy generation while preventing direct access to sensitive tenant information.
3Reliability
If authentication policies are manually established, then security control is maintained, but the system lacks adaptability to changing threats and tenant needs
Solution Approach 1:
The system implements dynamic authentication policies that automatically adapt to changing conditions. The ML model continuously monitors tenant data, application usage patterns, and security threats, then dynamically updates authentication policies and network zone configurations in real-time, maintaining both security control and adaptability.
Solution Approach 2:
The patent incorporates feedback loops where the ML model continuously receives information from authentication events, security incidents, and tenant operations. This feedback enables the system to learn from actual usage patterns and security outcomes, automatically refining and updating policies to maintain reliable security control while adapting to new threats and requirements.
Data Source
AI summary
An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.


