Network Appliance External User Identity Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for restricting user access to external resources, such as firewalls, often hinder legitimate activities by not distinguishing between different external user accounts, leading to unnecessary restrictions on employees' access to websites and services.

Innovation Solution

A data appliance that identifies external user accounts and enforces policies based on these identities, allowing for differentiated access rules, such as allowing access through corporate accounts while restricting personal accounts, using a process that involves packet processing, application identification, and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewalls are used to prevent users from accessing external resources, then security is improved, but legitimate activities are hindered

Engineering Contradiction:
ImprovesecurityVSAvoidlegitimate access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments users into different categories (internal users, external users, authenticated users, anonymous users) and applies different access policies to each segment. This allows the firewall to restrict anonymous access while permitting authenticated users to access external resources legitimately, thus maintaining security without hindering legitimate activities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different access control policies to different user types and different external resources. Internal users accessing corporate resources receive different treatment than external users accessing public resources, allowing fine-grained control that preserves legitimate access while maintaining security.

Inventive Principle:
Principle #3Local quality

2Reliability

If all access to specific websites is prohibited for all users, then security is improved, but employee productivity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidemployee productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic access control where permissions are not static but change based on user authentication status and identity. Users can dynamically transition from restricted anonymous access to permitted authenticated access, allowing employees to access necessary external resources for productivity while maintaining security through conditional policies.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of user identity from unknown to known through authentication. By detecting and identifying user identities, the system changes access parameters from restrictive (anonymous) to permissive (authenticated), enabling employees to access external resources needed for productivity while maintaining security through identity-based controls.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If external user accounts are identified and differentiated policies are enforced, then access control flexibility is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having the system automatically detect, identify, and authenticate user identities without manual intervention. The firewall automatically determines user categories and applies appropriate policies, reducing the need for complex manual configuration while maintaining high access control flexibility through automated identity-based decisions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9787635B1Identifying external user names and enforcing policies
Publication Date: 2017.10.10 PALO ALTO NETWORKS INC
  • US9787635B1 patent drawing
  • US9787635B1 patent drawing
  • US9787635B1 patent drawing

AI summary

Techniques for identifying external user names and enforcing policies are disclosed. A request is received from a first client device within a first network to access an external application that is outside of the first network. An identification of an external user account associated with the received request is identified. A determination is made, based at least in part on the identification, of a policy to apply to the request. The policy is applied.