User-Device Security Policy Management via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access security systems fail to dynamically adjust security policies when users switch between different devices, despite maintaining the same identity, as they do not account for the unique characteristics and vulnerabilities of various devices, leading to potential security threats.

Innovation Solution

A system and method for user-device access security policy management, where user and device credentials are used to retrieve and combine user and device security policies, generating a user-device security policy that dynamically adjusts security settings based on device type, model, configuration, and class, ensuring appropriate security measures for each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If generic security policies are applied to all users regardless of device type, then policy management is simplified, but security effectiveness deteriorates because device-specific vulnerabilities are not addressed

Engineering Contradiction:
Improvepolicy management complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The security policy is segmented into two independent components: user-based policy (identifying user credentials and roles) and device-based policy (identifying device type, model, configuration). This segmentation allows each component to be managed separately while combining them for enforcement, reducing overall complexity while improving security effectiveness through device-specific rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically determines the applicable security policy by first identifying the user, then identifying the device, and combining both factors to select the appropriate policy. This dynamic approach allows the system to adapt to different device types in real-time while maintaining consistent user identity recognition, resolving the contradiction between simplicity and effectiveness.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If user identity alone is used for security policy determination, then authentication is simplified, but security adaptability deteriorates when users switch between different devices

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity adaptability to device changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The authentication and policy determination process is segmented into distinct phases: user identification phase (using user credentials) and device identification phase (using device credentials). This segmentation maintains simple user authentication while adding device-awareness in a separate, manageable phase, enabling the system to adapt to device changes without complicating the authentication process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts the security policy based on the combination of user identity and device identity. When a user switches devices, the system maintains the same user identity recognition but updates the device identity, thereby dynamically adapting the security policy to the new device while preserving authentication simplicity.

Inventive Principle:
Principle #15Dynamics

3Reliability

If device-specific security policies are implemented for each device type, then security effectiveness is improved, but system complexity increases due to multiple policy configurations

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex device-specific policies are segmented into standardized policy templates organized by device type, model, and configuration categories. Instead of creating unique policies for each device, the system uses a hierarchical template structure that can be selectively applied, reducing configuration complexity while maintaining security effectiveness through device-aware policy selection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements a universal policy framework that can accommodate multiple device types through a common architecture. The same policy engine and enforcement mechanisms handle all device types by selectively applying different policy templates, thereby achieving device-specific security effectiveness without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8856890B2System and method of network access security policy management by user and device
Publication Date: 2014.10.07 ALCATEL LUCENT SA
  • US8856890B2 patent drawing
  • US8856890B2 patent drawing
  • US8856890B2 patent drawing

AI summary

A system and method are provided for management of access security by user and device. A security policy enforcement point is provided with a user policy module to receive user credentials from an access device of the user and a point for setting device dependent security policy to receive device credentials from the access device. A user policy is retrieved from a user database with use of the user credentials while a device policy is retrieved from a device database with use of the device credentials. The user policy and device policy are combined and used in the SPEP to enforce a user and device based security policy.