User Identity Correlation for Granular Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enforcing granular policies across a diverse and increasing number of devices in an enterprise network is challenging, as existing technologies struggle to accurately identify user identities and apply policies consistently, especially when devices do not directly communicate with the directory service provider.
Innovation Solution
A data appliance is configured to determine user identities based on events, such as login information from various sources, and enforce policies by correlating log data from servers with directory service provider information, allowing it to manage user access across all devices, including those that do not directly communicate with the directory service provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall-based access control is used, then basic security is maintained, but granular policy enforcement becomes difficult as device diversity increases
Solution Approach 1:
The patent introduces an intermediary system that correlates log data from multiple sources (firewalls, directory service providers, servers) to identify user identities associated with devices. This intermediary correlation process enables granular policy enforcement without requiring direct communication between all devices and the directory service provider, thus maintaining reliability while managing complexity.
Solution Approach 2:
The system segments the policy enforcement function into multiple components: log collection from various sources, user identity determination through correlation, and policy application. This segmentation allows each component to handle specific tasks independently, making the overall system more manageable despite device diversity.
2Ease of operation
If user identity identification is simplified, then ease of operation improves, but measurement precision of user identities deteriorates
Solution Approach 1:
The patent creates a universal user identification system that works across multiple device types and communication protocols. By correlating log data from firewalls, directory service providers, and various servers, the system achieves accurate user identification universally across diverse devices without requiring device-specific implementation, thus maintaining both ease of operation and precision.
3Measurement precision
If all devices communicate directly with the directory service provider, then user identity accuracy improves, but device complexity and network overhead increase
Solution Approach 1:
The patent introduces log data correlation as an intermediary mechanism that achieves accurate user identification without requiring direct communication between all devices and the directory service provider. The system collects log data from multiple sources, correlates it to determine user identities, and applies policies based on this correlated information, thus maintaining accuracy while reducing network complexity.
Data Source
AI summary
Enforcing a policy is described. A mapping between an IP address of a device and a user identity is identified at a first appliance, at least in part by correlating event information. The mapping is transmitted to a second appliance. A policy is applied by the second appliance to the device based at least in part on the user identity.


