Sequence-Based Application Segmentation for Zero-Trust Access Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise networks face challenges in configuring zero-trust policies due to the increased complexity and time required for managing access to cloud-hosted applications, leading to potential security risks from both external and insider threats, with manual policies often lacking fine-grained control.

Innovation Solution

The system automates the generation of zero-trust policies by analyzing user activity and identifying sequential patterns of application access, using machine learning to group users and applications, and providing policy recommendations for seamless access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual zero-trust policies are configured for each user and application, then security control precision is improved, but configuration time and complexity increase significantly

Engineering Contradiction:
Improveaccess control precisionVSAvoidpolicy configuration time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically generates zero-trust policies by analyzing user activity logs and application access patterns without requiring manual configuration. The policy generation engine autonomously creates fine-grained access control rules based on observed usage data, eliminating the time-consuming manual policy creation process while maintaining high precision control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of user behavior patterns and application access sequences before finalizing policies. By pre-processing log data and identifying usage patterns in advance, the system prepares policy recommendations that can be quickly deployed, reducing the overall configuration time while ensuring precise control

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If wildcard rules are used to allow broad application access, then ease of operation is improved, but security risk from external and insider threats increases

Engineering Contradiction:
Improveaccess configuration simplicityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies different levels of access control precision to different user-application pairs based on their specific behavior patterns. Instead of uniform wildcard rules or overly restrictive policies, the system dynamically determines the appropriate granularity of control for each local context, achieving both operational ease and security by applying the minimum necessary restrictions

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts access control parameters based on analyzed user behavior and application usage patterns. By changing the granularity and specificity of access rules based on observed parameters, the system transitions from broad wildcard permissions to precisely tailored policies that maintain operational simplicity while reducing security risks

Inventive Principle:
Principle #35Parameter changes

3Reliability

If fine-grained access control policies are implemented, then security precision is improved, but policy management complexity increases

Engineering Contradiction:
Improvesecurity precisionVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The policy management system automatically maintains fine-grained access control policies by continuously analyzing user activity logs and updating policies based on changing usage patterns. This self-updating mechanism eliminates the need for manual policy management while maintaining high security precision, effectively reducing management complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary analysis of user behavior and application access patterns to pre-generate appropriate policy configurations. By preparing policy recommendations in advance based on observed patterns, the system simplifies the deployment and management of fine-grained controls without requiring complex manual intervention

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12592930B2Generating zero-trust policy for application access based on sequence-based application segmentation
Publication Date: 2026.03.31 ZSCALER INC
  • US12592930B2 patent drawing
  • US12592930B2 patent drawing
  • US12592930B2 patent drawing

AI summary

Systems and methods include obtaining log data for a plurality of users of an enterprise where the log data relates to usage of a plurality of applications by the plurality of users and user metadata; analyzing the log data to determine one or more sequential patterns of application access; determining i) app-segments that are groupings of application of the plurality of applications and ii) user-groups that are groupings of users of the plurality of users, based on the log data and the one or more sequential patterns of application access; and providing access policy of the plurality of applications based on the user-groups and the app-segments. The one or more sequential patterns of application access include a sequence of accessing a plurality of applications in a given time period.