Security Gateway Identity Mapping for Network Traffic Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In corporate secure data networks, there is a lack of traceability and control over information exchange when employees use public communication services with public user identities, leading to potential security breaches and leaks of proprietary information.

Innovation Solution

A security gateway determines both private and public user identities from data packets during an application session, obtains a security policy, and applies it to the session, including network traffic and document access policies, to ensure secure packet forwarding and generate security reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employees use public communication services with public user identities, then communication convenience and accessibility are improved, but traceability and security control are worsened

Engineering Contradiction:
Improvecommunication convenienceVSAvoidtraceability
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces a security gateway as an intermediary component that sits between the public communication service and the corporate network. This gateway performs identity mapping by correlating public user identities with private corporate identities, enabling traceability of communications without preventing employees from using convenient public services. The gateway logs and monitors traffic, maintaining security control while allowing public service usage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If public user identities are used for communication, then accessibility to public services is improved, but security policy enforcement is worsened

Engineering Contradiction:
Improveaccessibility to public servicesVSAvoidsecurity policy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security gateway implements a universal identity mapping mechanism that works across multiple communication services and protocols. It maintains mapping tables that correlate public identities with private identities, enabling security policies to be enforced uniformly regardless of which public service is being used. This allows the system to adapt to various public services while maintaining consistent security enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If identity mapping and security policy application are implemented, then security control and traceability are improved, but system complexity is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security gateway serves as a centralized intermediary that consolidates identity mapping and security policy enforcement functions. Rather than distributing complexity across multiple systems, the gateway handles all identity correlation and policy application in one place, simplifying the overall system architecture while maintaining strong security control and traceability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9954899B2Applying a network traffic policy to an application session
Publication Date: 2018.04.24 A10 NETWORKS INC
  • US9954899B2 patent drawing
  • US9954899B2 patent drawing
  • US9954899B2 patent drawing

AI summary

Embodiments of the present technology relate to a method for applying a security policy to an application session, comprising: determining, by a security gateway, a first user identity and a second user identity from a data packet for an application session; obtaining, by the security gateway, a security policy for the application session; and applying the security policy to the application session by the security gateway. The user identity may be a network user identity or an application user identity recognized from packets of the application session. The security policy may comprise a network traffic policy mapped and/or a document access policy mapped to the user identity, where the network traffic policy is applied to the application session. The security gateway may further generate a security report concerning the application of the security policy to the application session.