SDLC Application Segmentation for Zero-Trust Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional enterprise network perimeter has expanded to the Internet due to cloud-based applications, increasing security risks from unsecured devices and wildcard application policies, which expand the attack surface.

Innovation Solution

Implementing a cloud-based system that autonomously generates SDLC-based application segments by defining application pairs, performing similarity and environment keyword filters, and generating segments to reduce the attack surface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wildcard application policies are used to provide broad access, then ease of operation is improved, but security is worsened due to expanded attack surface

Engineering Contradiction:
Improveapplication access policy managementVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments applications into distinct groups based on SDLC environments (development, testing, production, staging) rather than using wildcard policies. This segmentation allows precise control over which applications are accessible to which users, eliminating the need for broad wildcard rules while maintaining ease of access management through environment-based categorization.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional perimeter-based security is used, then device security is improved, but adaptability is worsened as applications move to cloud and perimeter extends to Internet

Engineering Contradiction:
Improvedevice securityVSAvoidcloud application access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the security parameter from location-based (perimeter) to environment-based (SDLC stage). By categorizing applications according to their SDLC environment rather than their network location, the system maintains security controls as applications move to the cloud. The security model adapts to cloud environments by focusing on the functional environment (dev, test, prod) rather than physical or network boundaries.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If manual application segmentation is performed, then security precision is improved, but productivity is worsened due to time-consuming analysis

Engineering Contradiction:
Improveapplication segmentation accuracyVSAvoidsegmentation implementation speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs automatic segmentation by analyzing application metadata, domain names, and SDLC environment indicators without requiring manual security analyst intervention. The segmentation process serves itself by using readily available application information to automatically categorize applications into appropriate SDLC environment groups, achieving both precision and speed.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs segmentation analysis in advance by examining application metadata, domain patterns, and environment keywords before policy implementation. This preliminary automated analysis prepares the segmentation structure ahead of time, eliminating the need for time-consuming manual review during policy deployment and enabling rapid security policy implementation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260067353A1Generating Software Development Life Cycle (SDLC)-based application segments
Publication Date: 2026.03.05 ZSCALER INC
  • US20260067353A1 patent drawing
  • US20260067353A1 patent drawing
  • US20260067353A1 patent drawing

AI summary

Systems and methods for generating SDLC-based application segments include defining a set of applications, the set of applications comprising a plurality of applications associated with a tenant of the cloud-based system; generating a plurality of application pairs from the set of applications; analyzing applications within each application pair of the plurality of application pairs for filtering the plurality of application pairs, the analyzing comprising a plurality of similarity checks and identification of environment key words; and generating one or more application segments each comprising one or more applications from the set of applications based on the filtering.