Access Gateway Isolation for Zero-Trust Application Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional remote access solutions provide device-to-network access first, leading to security risks as unauthenticated users can exploit application vulnerabilities, and migrating to Zero Trust Network Access (ZTNA) solutions introduces significant friction and requires replacing existing VPN architectures.
Innovation Solution
Implement an Application Isolation System with an Access Gateway Engine that denies access to applications by default, authenticating and authorizing users before allowing communication, using an Access Controller to generate and manage access control policies based on user authentication and authorization data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional VPN architectures are used to provide device-to-network access first, then ease of operation is improved, but network security deteriorates as unauthenticated users can exploit application vulnerabilities
Solution Approach 1:
The patent implements authentication and authorization before allowing network access to applications. The Access Gateway Engine performs user verification and generates access control policies that define which applications each authenticated user can access, ensuring security is established before any network communication occurs
Solution Approach 2:
The patent introduces an Access Gateway Engine as an intermediary component between users and applications. This gateway sits in the network path and enforces access control policies, mediating all communication between authenticated users and protected applications without requiring replacement of existing VPN infrastructure
2Reliability
If Zero Trust Network Access (ZTNA) solutions are implemented to provide authentication and authorization first, then network security is improved, but device complexity increases and migration friction occurs
Solution Approach 1:
The Access Gateway Engine is designed to work with existing VPN architectures and can be integrated into current network infrastructures without requiring complete replacement. It provides ZTNA functionality by enforcing authentication and authorization policies while coexisting with legacy VPN solutions, reducing migration complexity
Solution Approach 2:
The patent segments the network access control function into a separate Access Gateway Engine that can be independently deployed and managed. This modular approach allows organizations to implement ZTNA for specific applications without reconfiguring entire network infrastructures, reducing implementation complexity
3Ease of operation
If device-to-network access is provided first without application-level authentication, then ease of operation is improved, but lateral movement within the network increases security risks
Solution Approach 1:
The patent implements application-specific access control policies that are tailored to each user's authorization level. The Access Gateway Engine evaluates destination application information against stored authorization data, allowing each user to access only the specific applications they are authorized for, preventing lateral movement to unauthorized applications
Data Source
AI summary
A method for isolating applications on a network, the method including: denying network traffic access to applications sitting behind an Access Gateway Engine; receiving a username of a user that logs onto the network; extracting a source address associated with the username; retrieving a list of applications with which the username is permitted to communicate; extracting application destination information for each application of the list of applications; generating an access control policy for the username, the access control policy allowing the username having the source address to communicate with the list of application each of which having respective the destination information; the Access Gateway Engine allowing or denying the network traffic, originating from the username source address, access to the applications, according to the access control policy for the user.


