Stateful User Device Identification for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewall systems face challenges in identifying and managing user devices, especially Bring-Your-Own-Device (BYOD) devices, and distinguishing between personal and business purposes when accessing cloud-based services, due to the lack of registration and mixed user populations.

Innovation Solution

A method and system that utilize a network gateway and an analytic engine to extract hardware identities and decode user credentials from network session traffic, linking MAC addresses and user credentials to identify users across multiple devices and credentials, creating stateful records for enhanced visibility and policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the firewall system relies on device registration for identification, then corporate devices can be reliably identified, but BYOD devices remain unidentified and unmanageable

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidsupport for unregistered BYOD devices
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism (the analytic engine with stateful records) that mediates between network traffic and device identification. Instead of relying solely on pre-registered devices, the system creates intermediate stateful records that link hardware identities to user credentials, enabling identification of BYOD devices through their network behavior patterns rather than pre-registration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical registration system with a software-based stateful record mechanism. Rather than relying on physical device registration databases, the system uses software-generated stateful records that dynamically track and associate hardware identities with user credentials, allowing flexible identification of both registered and unregistered devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If the firewall system treats all users uniformly, then implementation is simple, but it cannot distinguish between personal and business purposes

Engineering Contradiction:
Improvesystem implementation simplicityVSAvoiduser purpose differentiation capability
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent segments users into different categories (personal vs. business) by creating separate stateful records for each user credential. The system maintains distinct stateful records that track different user populations, enabling differentiated policy enforcement while maintaining a unified system architecture. This segmentation allows the firewall to distinguish between personal and business purposes without complex rearchitecture.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If the system tracks multiple devices and credentials per user, then user identification accuracy improves, but system complexity increases

Engineering Contradiction:
Improveuser identification accuracyVSAvoidstateful record management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple device tracking and credential verification functions into a single stateful record management system. By combining hardware identity tracking, user credential verification, and session state management into unified stateful records, the system achieves accurate multi-device user identification without proportionally increasing complexity. The stateful records serve as a consolidated data structure that handles all identification needs simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9825954B2Stateful user device identification and binding for cloud application security
Publication Date: 2017.11.21 HOLONET SECURITY INC
  • US9825954B2 patent drawing
  • US9825954B2 patent drawing
  • US9825954B2 patent drawing

AI summary

At least one embodiment relates to a method and a system for cloud application visibility of network traffic. The method includes: receiving, from a network gateway, hardware identity extracted from network session traffic for accessing cloud-based application services, wherein the hardware identities correspond to user devices that initiate the network session traffic; receiving, from an application processing engine, user credentials decoded from the network session traffic, wherein the user credentials authorize the network session traffic to access the cloud-based application services; and matching the hardware identities with the user credential to identify a user who uses multiple user devices or multiple user credentials to access the cloud-based application services.