Cloud Intermediary Layer for Zero Trust Service Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking technologies lack effective methods to provide zero trust protection and control to internet-facing services, exposing them to risks of attack and compromising security.

Innovation Solution

A cloud-based system that receives a destination service definition from a customer, performs an assessment to determine policies, and enforces controls on requests through a control layer, providing access only based on defined policies and configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are made available in a shared network or over the open internet to deliver services to target audience, then service accessibility and delivery capability are improved, but security risk and exposure to attacks increase

Engineering Contradiction:
Improveservice delivery capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service intermediary layer positioned between the internet and destination services. This intermediary receives, inspects, and forwards requests while blocking malicious traffic, enabling services to be delivered to target audiences without direct internet exposure. The intermediary acts as a mediator that maintains service accessibility while filtering out security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network architecture into distinct layers: the internet layer, the intermediary inspection layer, and the protected services layer. By segmenting the network path and isolating destination services from direct internet connectivity, the system enables service delivery while reducing security risk through architectural separation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If zero trust protection and control are implemented to completely isolate and protect destination services, then security protection is improved, but network complexity and system overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediary layer consolidates zero trust control functions in a single centralized component, simplifying the overall system architecture. Rather than implementing distributed security controls at multiple points, the intermediary serves as a unified mediation point that enforces security policies, reducing system complexity while maintaining strong protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary assessment and policy determination before requests reach destination services. By pre-establishing security policies and conducting initial request validation at the intermediary layer, the system simplifies subsequent processing and reduces the complexity of real-time security decisions at the service level.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If policies and controls are enforced on all requests through a control layer, then security control capability is improved, but request processing time and system overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidrequest processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The intermediary layer applies partial inspection and control actions based on request characteristics. Rather than performing full security validation on every single request, the system applies targeted controls based on assessed risk levels and policy requirements, reducing processing time while maintaining effective security control for critical requests.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Security policies are determined and cached in advance through preliminary assessment. Once policies are established for destination services, subsequent requests benefit from pre-computed security rules, reducing the time required for real-time policy evaluation and control enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250159022A1Systems and methods for intelligent application definition and protection
Publication Date: 2025.05.15 ZSCALER INC
  • US20250159022A1 patent drawing
  • US20250159022A1 patent drawing
  • US20250159022A1 patent drawing

AI summary

Systems and methods for intelligent application definition and protection. In various embodiments, steps include receiving a destination service definition from a customer; performing an assessment of the destination service to determine one or more policies to use for the destination service; responsive to receiving a request from a user to access the destination service, directing the request to a control layer, and enforcing one or more controls on the request based on the one or more policies; and providing access to the destination service to the user based on the one or more controls.