Agentless File Transfer in Zero Trust Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing file transfer solutions in zero trust cloud environments either require agents installed at endpoints or silo applications that are opaque to zero trust policies, failing to dynamically evaluate context and enforce secure access, especially for third-party users and untrusted networks.

Innovation Solution

Implementing a policy-based agentless file transfer mechanism that uses a browser-based interface to initiate and control file transfers, integrating with zero trust network access systems to enforce authentication and authorization, and utilizing a sandbox for file inspection to ensure secure file handling and compliance with zero trust principles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If agents are installed at endpoints for file transfer, then file transfer functionality is achieved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvefile transfer operationVSAvoidendpoint configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the file transfer functionality from the endpoint device by implementing an agentless architecture. File transfers are initiated and managed through cloud-based services (ZIA and ZPA) rather than requiring local agents on endpoint devices. This extraction eliminates the need for endpoint configuration while maintaining full file transfer capability through the cloud intermediary.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based system provides universal file transfer capabilities that work across multiple devices and platforms without requiring device-specific agents. The ZIA and ZPA services handle file transfers for various endpoint types (desktops, mobile devices, tablets) through a unified cloud interface, making the system universally applicable without increasing individual device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If silo applications are used for file transfer, then file transfer capability is provided, but security and policy enforcement deteriorate

Engineering Contradiction:
Improvesecure accessVSAvoidzero trust policy evaluation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges file transfer functionality with zero trust security policies by integrating the file transfer service into the ZIA and ZPA cloud platforms. This combination ensures that all file transfers automatically undergo zero trust evaluation, including user identity verification, device posture assessment, and contextual policy checks. The unified architecture eliminates the security gaps present in silo applications while maintaining adaptability to dynamic policy requirements.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If file inspection is performed in real-time, then security is improved, but processing time and productivity deteriorate

Engineering Contradiction:
Improvefile securityVSAvoidfile transfer speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary file inspection by sandboxing files before allowing transfers to proceed. Files are submitted to the sandbox environment for execution and analysis, and only after successful inspection do transfers continue. This preliminary action ensures security validation occurs upfront, preventing malicious files from compromising the system while maintaining productivity through automated parallel processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The sandbox environment acts as an intermediary between file upload and file transfer completion. Rather than blocking transfers for security inspection, the sandbox mediates the process by isolating and analyzing files in a controlled environment. This intermediary approach maintains security rigor while preserving transfer productivity, as the sandbox operates in parallel and does not block the transfer pipeline.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If cloud-based security services are implemented, then security coverage is improved, but network bandwidth and energy consumption worsen

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by performing security evaluations in the cloud rather than requiring all file data to traverse the network repeatedly. User identity, device posture, and file metadata are evaluated by cloud-based zero trust policies, while only essential file data transfers occur. This localized security evaluation approach minimizes network bandwidth consumption compared to traditional models that require continuous local security scanning of all transferred data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11811855B1Policy based agentless file transfer in zero trust private networks
Publication Date: 2023.11.07 ZSCALER INC
  • US11811855B1 patent drawing
  • US11811855B1 patent drawing
  • US11811855B1 patent drawing

AI summary

Systems and methods for policy based agentless file transfer in zero trust private networks. Various systems and methods include receiving a request for a file transfer; determining a file transfer protocol; evaluating one or more criteria associated with the request, the criteria being associated with any of an end user and the contents of the file; and allowing or denying the file transfer based on the evaluating. Responsive to an end user's policy including a requirement for file inspection, the steps can further include sending the file to a sandbox for inspection, and receiving a result of the inspection from the sandbox.