Multi-perspective Security Context Constructor for Dynamic Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems struggle to adapt dynamically to user behavior changes and provide comprehensive, multi-perspective security contexts for effective policy enforcement, often relying on static or limited data sources.

Innovation Solution

A flexible security system that continuously collects and updates multi-perspective security contexts for users by aggregating behavioral information from various sources, using a security context constructor to generate and attach descriptors to user accounts, enabling dynamic security policy enforcement based on these contexts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static or limited data sources are used for security contexts, then system complexity is reduced, but adaptability to user behavior changes deteriorates

Engineering Contradiction:
Improveadaptability to user behavior changesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security context system transitions from static to dynamic by continuously updating user contexts based on real-time behavioral data. The system monitors user actions, device information, and environmental factors, then dynamically adjusts security contexts and policies accordingly, allowing security measures to evolve with user behavior patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security context is divided into multiple independent descriptors representing different aspects of user behavior and system state. Each descriptor can be independently collected, updated, and evaluated from various data sources, allowing the system to manage complexity through modular organization while maintaining comprehensive adaptability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If multi-perspective security contexts are aggregated from various sources, then measurement precision of user behavior is improved, but device complexity increases

Engineering Contradiction:
Improvevisibility into user behaviorVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security context framework serves multiple functions simultaneously: it collects behavioral data, stores user profiles, evaluates security policies, and enforces access controls. By creating a universal system that handles diverse security operations through a common descriptor-based architecture, the patent achieves comprehensive behavioral visibility without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces intermediary components such as security context constructors and policy enforcers that mediate between raw data sources and security decisions. These intermediaries aggregate data from multiple sources, process it through standardized descriptors, and present unified security contexts, thereby managing complexity while enhancing measurement precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time security policy enforcement is implemented, then reliability of security operations is improved, but loss of time in processing increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-evaluating security policies and caching security contexts before actual access requests occur. User profiles and security descriptors are established in advance, and policies are pre-computed where possible, reducing the processing time required during real-time enforcement while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent dynamically changes parameters such as evaluation depth, data retrieval scope, and policy complexity based on contextual factors. For low-risk operations, the system uses simplified parameter sets with fewer checks, while high-risk operations trigger more comprehensive evaluations, thereby balancing reliability with processing efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12010150B2Multi-perspective security context per actor
Publication Date: 2024.06.11 PALO ALTO NETWORKS INC
  • US12010150B2 patent drawing
  • US12010150B2 patent drawing
  • US12010150B2 patent drawing

AI summary

A flexible security system has been created that allows for fluid security operations that adapt to the dynamic nature of user behavior while also allowing the security related operations themselves to be dynamic. This flexible system includes ongoing collection and/or updating of multi-perspective “security contexts” per actor and facilitating consumption of these multi-perspective security contexts for security related operations on the users. These security related operations can include policy-based security enforcement and inspection. A security platform component or security entity uses a multi-perspective security context for a user or actor. Aggregating and maintaining behavioral information into a data structure for an actor over time from different sources allows a security platform component or entity to have historical context for an actor from one or more security perspectives. Descriptors that form a security context can originate from various sources having visibility of user behavior and/or user attributes.