Cloud Intermediary Layer for Zero Trust Service Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing networking technologies lack effective methods to provide zero trust protection and control to internet-facing services, exposing them to risks of attack and compromising security.
Innovation Solution
A cloud-based system that receives a destination service definition from a customer, performs an assessment to determine policies, and enforces controls on requests through a control layer, providing access only based on defined policies and configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If applications are made available in a shared network or over the open internet to deliver services to target audience, then service accessibility and delivery capability are improved, but security risk and exposure to attacks increase
Solution Approach 1:
The patent introduces a service intermediary layer positioned between the internet and destination services. This intermediary receives, inspects, and forwards requests while blocking malicious traffic, enabling services to be delivered to target audiences without direct internet exposure. The intermediary acts as a mediator that maintains service accessibility while filtering out security threats.
Solution Approach 2:
The system segments the network architecture into distinct layers: the internet layer, the intermediary inspection layer, and the protected services layer. By segmenting the network path and isolating destination services from direct internet connectivity, the system enables service delivery while reducing security risk through architectural separation.
2Reliability
If zero trust protection and control are implemented to completely isolate and protect destination services, then security protection is improved, but network complexity and system overhead increase
Solution Approach 1:
The intermediary layer consolidates zero trust control functions in a single centralized component, simplifying the overall system architecture. Rather than implementing distributed security controls at multiple points, the intermediary serves as a unified mediation point that enforces security policies, reducing system complexity while maintaining strong protection.
Solution Approach 2:
The system performs preliminary assessment and policy determination before requests reach destination services. By pre-establishing security policies and conducting initial request validation at the intermediary layer, the system simplifies subsequent processing and reduces the complexity of real-time security decisions at the service level.
3Reliability
If policies and controls are enforced on all requests through a control layer, then security control capability is improved, but request processing time and system overhead increase
Solution Approach 1:
The intermediary layer applies partial inspection and control actions based on request characteristics. Rather than performing full security validation on every single request, the system applies targeted controls based on assessed risk levels and policy requirements, reducing processing time while maintaining effective security control for critical requests.
Solution Approach 2:
Security policies are determined and cached in advance through preliminary assessment. Once policies are established for destination services, subsequent requests benefit from pre-computed security rules, reducing the time required for real-time policy evaluation and control enforcement.
Data Source
AI summary
Systems and methods for intelligent application definition and protection. In various embodiments, steps include receiving a destination service definition from a customer; performing an assessment of the destination service to determine one or more policies to use for the destination service; responsive to receiving a request from a user to access the destination service, directing the request to a control layer, and enforcing one or more controls on the request based on the one or more policies; and providing access to the destination service to the user based on the one or more controls.


