Automated Zero Trust Policy Generation via Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Zero Trust Architecture (ZTA) systems rely on manually crafted policies for each Policy Enforcement Point (PEP), which is time-consuming, lacks scalability, and prone to human errors, making them unsuitable for online environments and complex network activities.
Innovation Solution
A policy engine and automation device that automatically generates policies based on analytics, using knowledge graphs and machine learning to process network activities and telemetry data, enabling dynamic policy generation and deployment across various ZT pillars.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manually crafted policies are used for each PEP, then policy accuracy and security control are improved, but time consumption and lack of scalability worsen
Solution Approach 1:
The system enables automated policy generation where the policy engine autonomously creates policies for new activities without requiring manual intervention. The engine analyzes activity data, determines missing policies, and generates appropriate policy rules automatically, allowing the system to serve itself in policy creation tasks.
Solution Approach 2:
The patent replaces the manual mechanical process of policy crafting with an automated computational system. The policy engine uses algorithmic analysis of activity data and automated rule generation to substitute human specialists in creating policies, thereby increasing speed while maintaining accuracy through systematic analysis.
2Reliability
If manually crafted policies are used for each PEP, then policy security control is improved, but scalability and adaptability to complex networks worsen
Solution Approach 1:
The policy engine serves multiple PEPs across different ZT pillars (user, device, network, application, data) with a single automated system. It universally handles policy generation for various activity types and network contexts, making the system adaptable to complex multi-pillar Zero Trust architectures without requiring separate manual policy crafting for each PEP.
Solution Approach 2:
The system autonomously adapts to new activities and network conditions by automatically generating policies on-demand. When new activities are detected, the engine self-services by analyzing the activity data and creating appropriate policies without external intervention, enabling continuous adaptation to evolving network complexity.
3Reliability
If pre-existing policies are required for online access, then security verification is improved, but access speed and user experience worsen
Solution Approach 1:
The system performs preliminary policy generation by proactively creating policies for new activities before access decisions are required. The policy engine analyzes activity patterns and generates policies in advance, so when access requests occur, verified policies are already available, eliminating delays while maintaining security verification.
Solution Approach 2:
The policy engine autonomously generates policies on-demand during online operations without requiring pre-existing policies. It self-services by rapidly analyzing new activity data and creating verified policies in real-time, enabling both fast access decisions and continuous security verification through automated policy creation.
Data Source
AI summary
Architectures and techniques are described that can automatically (as opposed to manually) generate a new policy in a zero trust architecture (ZTA) or environment, for instance, when it is determined that a current network activity does not have a suitable policy that can be applied, which can be determined by a policy enforcement point (PEP) of a ZTA. To comply with ZTA principles, the new policy can be determined based on data-driven analytics of network activities and can therefore be suitable for online use.


