Cloud Connectors for Zero-Trust Private Application Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional enterprise network security models are inadequate for modern cloud-based environments, where mobile users and applications extend beyond the traditional perimeter, increasing risks for enterprise data on unsecured and unmanaged devices, and requiring advanced cloud-based security solutions for secure access to private applications.
Innovation Solution
The implementation of a cloud-based system that dynamically creates secure tunnels between user devices, a cloud-based system, and on-premises redirection proxies, allowing for zero-trust access to private applications without exposing them to the internet, using a connector selection process to determine optimal connection paths and ensuring only authorized access, thereby decoupling applications from the network and reducing configuration complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional perimeter-based security models are used, then security is maintained within the network perimeter, but access control for mobile users beyond the perimeter deteriorates
Solution Approach 1:
Instead of having users connect inward to the corporate network perimeter, the system inverts the connection direction by having the corporate network initiate outbound connections to users through cloud-based connectors. This reversal of the traditional client-server connection model enables secure access for mobile users while maintaining security control, as the enterprise-initiated connections can be properly authenticated and authorized before data exchange occurs.
Solution Approach 2:
The patent introduces cloud-based connectors as intermediary components that sit between the corporate network and mobile users. These connectors act as secure gateways that establish outbound connections to the corporate network on behalf of users, enabling access control for mobile users while filtering and monitoring traffic to mitigate security risks.
2Ease of operation
If applications are exposed to the internet for cloud access, then accessibility for users is improved, but security risks for enterprise data worsen
Solution Approach 1:
The cloud-based connectors serve as intermediary components that enable user access to applications without exposing the applications directly to the internet. The connectors establish secure outbound connections from the corporate network to cloud services, allowing users to access applications through these controlled gateways while the applications remain hidden behind the connectors, thus maintaining accessibility while mitigating security risks.
3Reliability
If cloud-based security solutions are implemented, then security for mobile users is improved, but device complexity increases
Solution Approach 1:
The cloud-based connectors are designed to automatically establish outbound connections to the corporate network without requiring manual configuration on mobile devices. The connectors handle authentication, connection management, and traffic routing autonomously, enabling security for mobile users while minimizing device complexity and configuration requirements.
4Ease of operation
If traditional VPN approaches are used, then network access is provided, but application-level access control deteriorates
Solution Approach 1:
The patent segments access control at the application level rather than providing broad network access. Each cloud-based connector is configured with specific application-level access control policies that define which applications users can access and under what conditions. This segmentation enables fine-grained control over application access while maintaining ease of network access through the connectors.
Data Source
AI summary
Systems and methods include receiving a request, in a cloud system from a first device, to access a second device; determining if the first device is permitted to access the second device; if the first device is not permitted to access the second device, notifying the first device the second device does not exist; and, if the first device is permitted to access the second device, stitching together connections between the cloud system, the first device, and the second device to provide access to the second device for the first device, wherein the connections are implemented through the cloud-based system.


