Cloud Connector Selection for Zero Trust Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional enterprise network security models are inadequate for modern cloud-based environments, where mobile users and unsecured devices increase the risk of data exposure and access vulnerabilities, as they extend beyond traditional perimeters and require more sophisticated access control mechanisms.
Innovation Solution
The implementation of a cloud-based system that provides Zero Trust Network Access (ZTNA) through sub-clouds, connector selection processes, and Client to Client and Server to Client communication, enabling secure access to private applications without exposing them to the internet, using a cloud-based system with distributed data centers and lightweight connectors for secure tunnel creation and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional perimeter-based security models are used, then network security is maintained through defined perimeters and firewalls, but the system cannot provide secure access to cloud-based applications and mobile users beyond the perimeter
Solution Approach 1:
The patent segments the network access into distinct zones: trusted network zone, untrusted network zone, and cloud service zone. This segmentation allows the system to maintain security through controlled perimeter definitions while enabling versatile access to cloud applications through zone-based routing and security policies, resolving the contradiction between security and access capability.
Solution Approach 2:
The patent introduces a cloud-based security service as an intermediary between users and cloud applications. This intermediary provides zero-trust access control, application-level security policies, and traffic routing without requiring users to directly access the cloud network perimeter, thus maintaining security while enabling secure access to cloud services.
2Adaptability or versatility
If cloud-based security solutions are implemented to provide secure access, then access to cloud applications is enabled, but the system complexity increases due to distributed data centers and connector selection processes
Solution Approach 1:
The patent implements self-service mechanisms where the cloud-based security service automatically selects optimal connectors, establishes secure tunnels, and routes traffic without requiring manual configuration. The system autonomously manages connector selection based on user location, application requirements, and security policies, reducing operational complexity while maintaining access capability.
Solution Approach 2:
The patent dynamically changes system parameters such as connector selection, routing paths, and security policies based on real-time conditions including user location, network status, and application requirements. This dynamic parameter adjustment allows the system to adapt to changing conditions without increasing operational complexity, as adjustments are made automatically by the security service.
3Reliability
If zero trust access is implemented to make applications invisible to unauthorized users, then security is improved, but the complexity of connector selection and connection stitching increases
Solution Approach 1:
The patent uses the cloud-based security service as an intermediary that handles all connection management tasks. The service automatically selects connectors, establishes secure tunnels, and stitches connections between users and applications without requiring complex manual configuration. This intermediary approach maintains zero-trust security while simplifying connection management through automated policies.
Solution Approach 2:
The patent implements feedback mechanisms where the security service continuously monitors connection status, user location, and network conditions to dynamically adjust connector selection and routing. This feedback loop enables the system to maintain security through automated connector selection while reducing management complexity by adapting to changing conditions without manual intervention.
4Reliability
If data center locations are limited for data residency regulations, then compliance is improved, but the availability and performance of application access may be reduced
Solution Approach 1:
The patent segments the cloud service into multiple data center zones with different access characteristics. The system can route traffic through specific compliant data centers for regulated applications while using other data centers for performance-critical access. This segmentation enables the system to meet compliance requirements without sacrificing overall access performance through intelligent routing.
Solution Approach 2:
The patent dynamically adjusts data center selection based on application requirements, user location, and compliance needs. The system can switch between different data center locations in real-time to optimize performance while maintaining compliance, rather than being statically constrained to specific locations. This dynamic approach balances compliance and performance requirements.
Data Source
AI summary
Systems and methods include obtaining criteria for selecting connectors for private application access in a cloud-based system; responsive to a request to access an application, by a user device, located in any of a public cloud, a private cloud, and an enterprise network, wherein the user device is remote over the Internet, determining a connector coupled to the application based on the criteria; and, responsive to a user of the user device being permitted to access the application, stitching together connections between the cloud-based system, the application, and the user device to provide access to the application.


