Cloud Connectors for Zero-Trust Private Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise network security models are inadequate for modern cloud-based environments, where mobile users and applications extend beyond the traditional perimeter, increasing risks for enterprise data on unsecured and unmanaged devices, and requiring advanced cloud-based security solutions for secure access to private applications.

Innovation Solution

The implementation of a cloud-based system that dynamically creates secure tunnels between user devices, a cloud-based system, and on-premises redirection proxies, allowing for zero-trust access to private applications without exposing them to the internet, using a connector selection process to determine optimal connection paths and ensuring only authorized access, thereby decoupling applications from the network and reducing configuration complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional perimeter-based security models are used, then security is maintained within the network perimeter, but access control for mobile users beyond the perimeter deteriorates

Engineering Contradiction:
Improveaccess control for mobile usersVSAvoidsecurity risks for enterprise data
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Instead of having users connect inward to the corporate network perimeter, the system inverts the connection direction by having the corporate network initiate outbound connections to users through cloud-based connectors. This reversal of the traditional client-server connection model enables secure access for mobile users while maintaining security control, as the enterprise-initiated connections can be properly authenticated and authorized before data exchange occurs.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces cloud-based connectors as intermediary components that sit between the corporate network and mobile users. These connectors act as secure gateways that establish outbound connections to the corporate network on behalf of users, enabling access control for mobile users while filtering and monitoring traffic to mitigate security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If applications are exposed to the internet for cloud access, then accessibility for users is improved, but security risks for enterprise data worsen

Engineering Contradiction:
Improveaccessibility for usersVSAvoidsecurity risks for enterprise data
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The cloud-based connectors serve as intermediary components that enable user access to applications without exposing the applications directly to the internet. The connectors establish secure outbound connections from the corporate network to cloud services, allowing users to access applications through these controlled gateways while the applications remain hidden behind the connectors, thus maintaining accessibility while mitigating security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cloud-based security solutions are implemented, then security for mobile users is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity for mobile usersVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud-based connectors are designed to automatically establish outbound connections to the corporate network without requiring manual configuration on mobile devices. The connectors handle authentication, connection management, and traffic routing autonomously, enabling security for mobile users while minimizing device complexity and configuration requirements.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If traditional VPN approaches are used, then network access is provided, but application-level access control deteriorates

Engineering Contradiction:
Improvenetwork accessVSAvoidapplication-level access control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments access control at the application level rather than providing broad network access. Each cloud-based connector is configured with specific application-level access control policies that define which applications users can access and under what conditions. This segmentation enables fine-grained control over application access while maintaining ease of network access through the connectors.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12155630B2Systems and methods for providing private application access via client to client and server to client communication through a cloud-based system
Publication Date: 2024.11.26 ZSCALER INC
  • US12155630B2 patent drawing
  • US12155630B2 patent drawing
  • US12155630B2 patent drawing

AI summary

Systems and methods include receiving a request, in a cloud system from a first device, to access a second device; determining if the first device is permitted to access the second device; if the first device is not permitted to access the second device, notifying the first device the second device does not exist; and, if the first device is permitted to access the second device, stitching together connections between the cloud system, the first device, and the second device to provide access to the second device for the first device, wherein the connections are implemented through the cloud-based system.