ML Zero-Trust Policy Generation for Fine-Grained App Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise networks face challenges in configuring zero-trust policies due to the increased complexity and risk associated with applications moving to the cloud, leading to expanded attack surfaces from wildcard access rules, which are time-consuming and lack fine-grained control.

Innovation Solution

Utilizing machine learning to analyze user-to-application traffic and automatically generate zero-trust policies, reducing onboarding time from months to over a month by identifying app-segments and user-groups, and continuously refining policies based on monitoring and verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual policy configuration is used for zero-trust access, then security control precision can be improved, but configuration time and complexity increase significantly

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy configuration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically analyzing network traffic patterns and generating zero-trust policies without requiring manual configuration. The machine learning model autonomously processes traffic data, identifies access patterns, and creates policy recommendations, eliminating the time-consuming manual policy creation process while maintaining high precision through data-driven insights.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual configuration process with an automated machine learning system. Instead of security personnel manually analyzing traffic and creating policies, the system uses ML algorithms to automatically process traffic data and generate policy recommendations, significantly reducing configuration time while maintaining or improving precision through consistent, data-driven decision-making.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If wildcard rules are used for application access, then ease of configuration is improved, but attack surface increases

Engineering Contradiction:
Improvepolicy configuration easeVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by generating specific, targeted policies for different user groups and applications based on analyzed traffic patterns. Instead of applying uniform wildcard rules across all access scenarios, the machine learning model creates customized policies that match actual usage patterns, allowing precise control over who accesses what, thereby reducing the attack surface while maintaining ease of configuration through automation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by creating selective access policies rather than comprehensive wildcard rules. The system analyzes traffic to identify only the necessary access relationships that exist in practice, creating policies for specific user-application pairs rather than granting broad access. This partial policy coverage reduces the attack surface by limiting access to only what is actually needed based on observed usage patterns.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If fine-grained access control is implemented, then security precision is improved, but policy management complexity increases

Engineering Contradiction:
Improveaccess control granularityVSAvoidpolicy management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs self-service by automatically generating fine-grained policies based on traffic analysis without requiring manual management of each individual policy. The machine learning model autonomously creates, updates, and refines policies based on observed patterns, eliminating the complexity of manual fine-grained policy management while maintaining high precision through continuous data-driven optimization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-analyzing traffic patterns and pre-generating policy recommendations before deployment. The system processes historical traffic data to identify access patterns and creates policy frameworks in advance, reducing the complexity of ongoing policy management by establishing a data-driven foundation that guides subsequent policy decisions and simplifies iterative refinement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4167116B1Generating zero-trust policy for application access using machine learning
Publication Date: 2026.05.20 ZSCALER INC
  • EP4167116B1 patent drawingFigure 1
  • EP4167116B1 patent drawingFigure 2
  • EP4167116B1 patent drawingFigure 3

AI summary

Systems and methods include obtaining log data for a plurality of users (102) of an enterprise where the log data relates to usage of a plurality of applications (402, 404) by the plurality of users (102); determining i) app-segments that are groupings of application (402, 404) of the plurality of applications (402, 404) and ii) user-groups that are groupings of users (102) of the plurality of users (102); and providing access policy of the plurality of applications based on the user-groups and the app-segments. The steps can further include monitoring the access policy over time based on ongoing log data, manual verification of the access policy, and incidents where users are prevented from accessing any application (402, 404); and adjusting the determined based on the monitoring.