Access Gateway Isolation for Zero-Trust Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional remote access solutions provide device-to-network access first, leading to security risks as unauthenticated users can exploit application vulnerabilities, and migrating to Zero Trust Network Access (ZTNA) solutions introduces significant friction and requires replacing existing VPN architectures.

Innovation Solution

Implement an Application Isolation System with an Access Gateway Engine that denies access to applications by default, authenticating and authorizing users before allowing communication, using an Access Controller to generate and manage access control policies based on user authentication and authorization data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional VPN architectures are used to provide device-to-network access first, then ease of operation is improved, but network security deteriorates as unauthenticated users can exploit application vulnerabilities

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements authentication and authorization before allowing network access to applications. The Access Gateway Engine performs user verification and generates access control policies that define which applications each authenticated user can access, ensuring security is established before any network communication occurs

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an Access Gateway Engine as an intermediary component between users and applications. This gateway sits in the network path and enforces access control policies, mediating all communication between authenticated users and protected applications without requiring replacement of existing VPN infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Zero Trust Network Access (ZTNA) solutions are implemented to provide authentication and authorization first, then network security is improved, but device complexity increases and migration friction occurs

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Access Gateway Engine is designed to work with existing VPN architectures and can be integrated into current network infrastructures without requiring complete replacement. It provides ZTNA functionality by enforcing authentication and authorization policies while coexisting with legacy VPN solutions, reducing migration complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the network access control function into a separate Access Gateway Engine that can be independently deployed and managed. This modular approach allows organizations to implement ZTNA for specific applications without reconfiguring entire network infrastructures, reducing implementation complexity

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If device-to-network access is provided first without application-level authentication, then ease of operation is improved, but lateral movement within the network increases security risks

Engineering Contradiction:
Improveease of operationVSAvoidlateral movement risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements application-specific access control policies that are tailored to each user's authorization level. The Access Gateway Engine evaluates destination application information against stored authorization data, allowing each user to access only the specific applications they are authorized for, preventing lateral movement to unauthorized applications

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12542760B2System and method for providing application isolation on a physical, virtual or containerized network or host machine
Publication Date: 2026.02.03 ERICOM SOFTWARE
  • US12542760B2 patent drawing
  • US12542760B2 patent drawing
  • US12542760B2 patent drawing

AI summary

A method for isolating applications on a network, the method including: denying network traffic access to applications sitting behind an Access Gateway Engine; receiving a username of a user that logs onto the network; extracting a source address associated with the username; retrieving a list of applications with which the username is permitted to communicate; extracting application destination information for each application of the list of applications; generating an access control policy for the username, the access control policy allowing the username having the source address to communicate with the list of application each of which having respective the destination information; the Access Gateway Engine allowing or denying the network traffic, originating from the username source address, access to the applications, according to the access control policy for the user.