Automated Zero Trust Policy Generation via Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Zero Trust Architecture (ZTA) systems rely on manually crafted policies for each Policy Enforcement Point (PEP), which is time-consuming, lacks scalability, and prone to human errors, making them unsuitable for online environments and complex network activities.

Innovation Solution

A policy engine and automation device that automatically generates policies based on analytics, using knowledge graphs and machine learning to process network activities and telemetry data, enabling dynamic policy generation and deployment across various ZT pillars.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manually crafted policies are used for each PEP, then policy accuracy and security control are improved, but time consumption and lack of scalability worsen

Engineering Contradiction:
Improvepolicy accuracyVSAvoidpolicy generation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables automated policy generation where the policy engine autonomously creates policies for new activities without requiring manual intervention. The engine analyzes activity data, determines missing policies, and generates appropriate policy rules automatically, allowing the system to serve itself in policy creation tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of policy crafting with an automated computational system. The policy engine uses algorithmic analysis of activity data and automated rule generation to substitute human specialists in creating policies, thereby increasing speed while maintaining accuracy through systematic analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manually crafted policies are used for each PEP, then policy security control is improved, but scalability and adaptability to complex networks worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidscalability to complex networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The policy engine serves multiple PEPs across different ZT pillars (user, device, network, application, data) with a single automated system. It universally handles policy generation for various activity types and network contexts, making the system adaptable to complex multi-pillar Zero Trust architectures without requiring separate manual policy crafting for each PEP.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system autonomously adapts to new activities and network conditions by automatically generating policies on-demand. When new activities are detected, the engine self-services by analyzing the activity data and creating appropriate policies without external intervention, enabling continuous adaptation to evolving network complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If pre-existing policies are required for online access, then security verification is improved, but access speed and user experience worsen

Engineering Contradiction:
Improvesecurity verificationVSAvoidaccess decision speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary policy generation by proactively creating policies for new activities before access decisions are required. The policy engine analyzes activity patterns and generates policies in advance, so when access requests occur, verified policies are already available, eliminating delays while maintaining security verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The policy engine autonomously generates policies on-demand during online operations without requiring pre-existing policies. It self-services by rapidly analyzing new activity data and creating verified policies in real-time, enabling both fast access decisions and continuous security verification through automated policy creation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240370551A1Automated online policy generation for zero-trust architectures
Publication Date: 2024.11.07 DELL PROD LP
  • US20240370551A1 patent drawing
  • US20240370551A1 patent drawing
  • US20240370551A1 patent drawing

AI summary

Architectures and techniques are described that can automatically (as opposed to manually) generate a new policy in a zero trust architecture (ZTA) or environment, for instance, when it is determined that a current network activity does not have a suitable policy that can be applied, which can be determined by a policy enforcement point (PEP) of a ZTA. To comply with ZTA principles, the new policy can be determined based on data-driven analytics of network activities and can therefore be suitable for online use.