User Identity Correlation for Granular Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enforcing granular policies across a diverse and increasing number of devices in an enterprise network is challenging, as existing technologies struggle to accurately identify user identities and apply policies consistently, especially when devices do not directly communicate with the directory service provider.

Innovation Solution

A data appliance is configured to determine user identities based on events, such as login information from various sources, and enforce policies by correlating log data from servers with directory service provider information, allowing it to manage user access across all devices, including those that do not directly communicate with the directory service provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall-based access control is used, then basic security is maintained, but granular policy enforcement becomes difficult as device diversity increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidpolicy enforcement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that correlates log data from multiple sources (firewalls, directory service providers, servers) to identify user identities associated with devices. This intermediary correlation process enables granular policy enforcement without requiring direct communication between all devices and the directory service provider, thus maintaining reliability while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the policy enforcement function into multiple components: log collection from various sources, user identity determination through correlation, and policy application. This segmentation allows each component to handle specific tasks independently, making the overall system more manageable despite device diversity.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If user identity identification is simplified, then ease of operation improves, but measurement precision of user identities deteriorates

Engineering Contradiction:
Improveuser identification easeVSAvoiduser identity accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent creates a universal user identification system that works across multiple device types and communication protocols. By correlating log data from firewalls, directory service providers, and various servers, the system achieves accurate user identification universally across diverse devices without requiring device-specific implementation, thus maintaining both ease of operation and precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If all devices communicate directly with the directory service provider, then user identity accuracy improves, but device complexity and network overhead increase

Engineering Contradiction:
Improveuser identity accuracyVSAvoidnetwork communication complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces log data correlation as an intermediary mechanism that achieves accurate user identification without requiring direct communication between all devices and the directory service provider. The system collects log data from multiple sources, correlates it to determine user identities, and applies policies based on this correlated information, thus maintaining accuracy while reducing network complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10637863B1User-ID information propagation among appliances
Publication Date: 2020.04.28 PALO ALTO NETWORKS INC
  • US10637863B1 patent drawing
  • US10637863B1 patent drawing
  • US10637863B1 patent drawing

AI summary

Enforcing a policy is described. A mapping between an IP address of a device and a user identity is identified at a first appliance, at least in part by correlating event information. The mapping is transmitted to a second appliance. A policy is applied by the second appliance to the device based at least in part on the user identity.