Stateful User Device Identification for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewall systems face challenges in identifying and managing user devices, especially Bring-Your-Own-Device (BYOD) devices, and distinguishing between personal and business purposes when accessing cloud-based services, due to the lack of registration and mixed user populations.
Innovation Solution
A method and system that utilize a network gateway and an analytic engine to extract hardware identities and decode user credentials from network session traffic, linking MAC addresses and user credentials to identify users across multiple devices and credentials, creating stateful records for enhanced visibility and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If the firewall system relies on device registration for identification, then corporate devices can be reliably identified, but BYOD devices remain unidentified and unmanageable
Solution Approach 1:
The patent introduces an intermediary mechanism (the analytic engine with stateful records) that mediates between network traffic and device identification. Instead of relying solely on pre-registered devices, the system creates intermediate stateful records that link hardware identities to user credentials, enabling identification of BYOD devices through their network behavior patterns rather than pre-registration.
Solution Approach 2:
The patent replaces the mechanical registration system with a software-based stateful record mechanism. Rather than relying on physical device registration databases, the system uses software-generated stateful records that dynamically track and associate hardware identities with user credentials, allowing flexible identification of both registered and unregistered devices.
2Ease of manufacture
If the firewall system treats all users uniformly, then implementation is simple, but it cannot distinguish between personal and business purposes
Solution Approach 1:
The patent segments users into different categories (personal vs. business) by creating separate stateful records for each user credential. The system maintains distinct stateful records that track different user populations, enabling differentiated policy enforcement while maintaining a unified system architecture. This segmentation allows the firewall to distinguish between personal and business purposes without complex rearchitecture.
3Measurement precision
If the system tracks multiple devices and credentials per user, then user identification accuracy improves, but system complexity increases
Solution Approach 1:
The patent merges multiple device tracking and credential verification functions into a single stateful record management system. By combining hardware identity tracking, user credential verification, and session state management into unified stateful records, the system achieves accurate multi-device user identification without proportionally increasing complexity. The stateful records serve as a consolidated data structure that handles all identification needs simultaneously.
Data Source
AI summary
At least one embodiment relates to a method and a system for cloud application visibility of network traffic. The method includes: receiving, from a network gateway, hardware identity extracted from network session traffic for accessing cloud-based application services, wherein the hardware identities correspond to user devices that initiate the network session traffic; receiving, from an application processing engine, user credentials decoded from the network session traffic, wherein the user credentials authorize the network session traffic to access the cloud-based application services; and matching the hardware identities with the user credential to identify a user who uses multiple user devices or multiple user credentials to access the cloud-based application services.


