IP Library › Granted Patent US 12,549,607
Granted Patent B2
US 12,549,607 · App. 18/544,306 · Granted Feb 10, 2026

Zero trust policy recommendation system through entity and relationship similarity

Inventors: Thais Luca Marques de Almeida (São Gonçalo, BR); David Burth Kurka (Campinas, BR); Diego Vrague Noble (Pelotas, BR); Ítalo Gomes Santana (Rio de Janeiro, BR); Karen Braga Enes (Belo Horizonte, BR)
Assignee: Dell Products L.P.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,607
App. No.
18/544,306
Granted
Feb 10, 2026
Kind
B2
Abstract

One example method includes transforming a structured data file into a graph structure that represents a zero trust (ZT) environment, where entities in the ZT environment are represented as nodes in the graph structure, and connections between the entities are represented in the graph structure as edges, performing a community detection process on the graph structure to identify a community of entities, performing a community characterization process that comprises identifying the ZT policies that are most commonly applied to the entities in the community, and based on the ZT policies identified, generating a recommendation as to whether one of the ZT policies should be applied to one of the entities in the community and, if so, which ZT policy or ZT policies should be applied.

Claims (28)

1 . A method, comprising:

transforming a structured data file into a graph structure that represents a zero trust (ZT) environment, wherein entities in the ZT environment are represented as nodes in the graph structure, and connections between the entities are represented in the graph structure as edges;

performing a community detection process on the graph structure to identify a community of entities, and the community detection process comprises partitioning the graph structure into sub-graphs that each define a respective community;

performing a community characterization process that comprises identifying ZT policies that are most relevant, or most commonly applied, to the entities in the community; and

based on the ZT policies identified, generating a recommendation that one of the ZT policies should be applied to one of the entities in the community and, identifying which ZT policy or ZT policies should be applied.

2 . The method as recited in claim 1 , wherein the community detection process comprises partitioning the graph structure into sub-graph portions that each represent a respective group of the entities in the ZT environment.

3 . The method as recited in claim 1 , wherein the recommendation comprises a recommendation that a particular one of the most relevant policies be applied to an entity to which that particular policy has not yet been applied, and the particular one of the most relevant policies is identified by application of specified criteria.

4 . The method as recited in claim 1 , wherein one of the entities comprises any one or more of a user, a device, a network, and an application.

5 . The method as recited in claim 1 , wherein entities within the community are more densely connected to each other than to other entities in a different community.

6 . The method as recited in claim 1 , wherein entities within the community have one or more relationships with each other that comprise one or more system connections, interactions, shared information, and service usage patterns.

7 . The method as recited in claim 1 , wherein a check is performed of the identified ZT policies to determine whether all of the identified ZT policies are in effect across the entities in the community.

8 . The method as recited in claim 1 , wherein the ZT environment represented by the graph structure comprises a network.

9 . The method as recited in claim 1 , wherein, in the structured data file, the nodes are declared before the edges.

10 . The method as recited in claim 1 , wherein the community characterization process comprises visiting the community and one or more other communities represented in the graph structure, and then applying a ranking function to identify the most relevant, or most commonly applied, ZT policies.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

transforming a structured data file into a graph structure that represents a zero trust (ZT) environment, wherein entities in the ZT environment are represented as nodes in the graph structure, and connections between the entities are represented in the graph structure as edges;

performing a community detection process on the graph structure to identify a community of entities, and the community detection process comprises partitioning the graph structure into sub-graphs that each define a respective community;

performing a community characterization process that comprises identifying ZT policies that are most relevant, or most commonly applied, to the entities in the community; and

based on the ZT policies identified, generating a recommendation that one of the ZT policies should be applied to one of the entities in the community and, identifying which ZT policy or ZT policies should be applied.

12 . The non-transitory storage medium as recited in claim 11 , wherein the community detection process comprises partitioning the graph structure into sub-graph portions that each represent a respective group of the entities in the ZT environment.

13 . The non-transitory storage medium as recited in claim 11 , wherein the recommendation comprises a recommendation that a particular one of the most relevant, or most commonly applied, policies be applied to an entity to which that particular policy has not yet been applied.

14 . The non-transitory storage medium as recited in claim 11 , wherein one of the entities comprises any one or more of a user, a device, a network, and an application.

15 . The non-transitory storage medium as recited in claim 11 , wherein entities within the community are more densely connected to each other than to other entities in a different community.

16 . The non-transitory storage medium as recited in claim 11 , wherein entities within the community have one or more relationships with each other that comprise one or more system connections, interactions, shared information, and service usage patterns.

17 . The non-transitory storage medium as recited in claim 11 , wherein a check is performed of the identified ZT policies to determine whether all of the identified ZT policies are in effect across the entities in the community.

18 . The non-transitory storage medium as recited in claim 11 , wherein the ZT environment represented by the graph structure comprises a network.

19 . The non-transitory storage medium as recited in claim 11 , wherein, in the structured data file, the nodes are declared before the edges.

20 . The non-transitory storage medium as recited in claim 11 , wherein the community characterization process comprises visiting the community and one or more other communities represented in the graph structure, and then applying a ranking function to identify the most relevant, or most commonly applied, ZT policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2023
From: LUCA MARQUES DE ALMEIDA, THAIS; KURKA, DAVID BURTH; NOBLE, DIEGO VRAGUE; SANTANA, ÍTALO GOMES; ENES, KAREN BRAGA
To: DELL PRODUCTS L.P.
Reel/Frame 065903/0176 →
Continuity (1)
Related Publication 20250202949A1 · Jun 19, 2025
References Cited (9)
US 11880452B1 · Guha · 2024 [cited by examiner]
US 11943195B1 · Jain · 2024 [cited by examiner]
US 12153948B2 · Kaimal · 2024 [cited by examiner]
US 20210168150A1 · Ross · 2021 [cited by examiner]
US 20220109701A1 · Zeng · 2022 [cited by examiner]
US 20230254318A1 · Hu · 2023 [cited by examiner]
He et al “A survey on zero trust architecture: Challenges and future trends,” Wireless Communications and Mobile Computing, 2022. [cited by applicant]
S. Fortunato, “Community detection in graphs,” Physics Reports, No. 3-5, pp. 75-174, 2010. [cited by applicant]
Su et al., “A Comprehensive Survey on Community Detection With Deep Learning,” IEEE Transactions on Neural Networks and Learning Systems, pp. 1-21, 2022. [cited by applicant]