Alias Domains for ZTNA Application Access via Service Proxies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved techniques for deploying and managing zero trust network access applications with a cloud-based security infrastructure.

Innovation Solution

A zero trust network access (ZTNA) system is modified to facilitate distributed and/or cloud-based deployments of components for a control plane and a data plane, supporting a network-accessible front end for customer-hosted applications, with an abstraction layer that maps alias domains to network load balancers, simplifying service proxy configuration and reducing administrative burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If service proxies are directly mapped to applications without an abstraction layer, then network access control is achieved, but configuration complexity and administrative burden increase when clusters are reconfigured

Engineering Contradiction:
Improveservice proxy configurationVSAvoidnetwork access management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an abstraction layer that acts as an intermediary between service proxies and applications. This abstraction layer decouples the direct mapping relationship, allowing service proxies to be reconfigured without directly impacting application access. The abstraction layer translates and manages the mappings dynamically, reducing administrative burden when clusters are reconfigured to adjust to varying user traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If service proxy clusters are periodically reconfigured to adjust to varying user traffic, then service quality is improved, but administrative burden increases

Engineering Contradiction:
Improveservice quality adjustmentVSAvoidadministrative time for reconfiguration
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The abstraction layer enables self-service capabilities by automatically managing the mappings between alias domains and service proxies. When service proxy clusters need reconfiguration to adjust to varying user traffic, the system can perform these adjustments without requiring manual administrative intervention for each change. The abstraction layer handles the reconfiguration automatically, reducing the administrative time and effort required.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If direct mapping between service proxies and applications is used, then network access control is achieved, but flexibility in cluster reconfiguration is reduced

Engineering Contradiction:
Improvecluster reconfiguration flexibilityVSAvoidnetwork access control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network access control architecture into distinct layers: the abstraction layer and the service proxy layer. This segmentation allows the service proxy clusters to be reconfigured independently without affecting the overall network access control functionality. The abstraction layer maintains the control policies while the service proxies can be dynamically adjusted, achieving both flexibility and reliability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12418512B2Alias domains for accessing ZTNA applications
Publication Date: 2025.09.16 SOPHOS LTD
  • US12418512B2 patent drawing
  • US12418512B2 patent drawing
  • US12418512B2 patent drawing

AI summary

A cloud computing platform provides zero trust network access as a service to customers that maintain applications on-premises. In this context, the cloud computing platform may associate customers and/or applications with specific service proxies, and add an abstraction layer for network access that maps an alias domain for each customer and/or application to a network load balancer associated with the specific service proxies associated with the corresponding application(s). This approach advantageously simplifies the configuration of service proxies at the cloud computing platform by permitting dedicated relationships among network load balancers, specific service proxies, and specific applications, while concurrently reducing or avoiding the administrative burden on customers of updating network pointers when the clusters of service proxies are periodically reconfigured to adjust to varying user traffic.