Cloud-Based Virtual Private Access System for Secure Application Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPN solutions struggle to provide seamless and secure access to applications across internal networks, private clouds, and public clouds, leading to increased bandwidth, administrative complexity, and security vulnerabilities, especially for nomadic users and branch offices.

Innovation Solution

A cloud-based virtual private access system that dynamically creates secure tunnels between user devices, cloud nodes, and enterprise resources, using lightweight connectors and central authorities to enforce authentication and security policies, eliminating the need for dedicated hardware and reducing network exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional VPN solutions are used to provide access to applications across internal networks, private clouds, and public clouds, then access capability is achieved, but administrative complexity and security vulnerabilities increase

Engineering Contradiction:
Improveaccess capabilityVSAvoidadministrative complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based VPN intermediary that acts as a mediator between users and enterprise resources. Instead of requiring direct connections through complex network configurations, the cloud VPN server establishes secure tunnels and manages connectivity, simplifying administrative complexity while maintaining versatile access capability across multiple network domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud-based VPN solution provides universal access capability through a single system that can connect users to applications in internal networks, private clouds, and public clouds simultaneously. This multi-functional approach eliminates the need for separate VPN configurations for each network domain, reducing administrative complexity while maintaining broad adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If conventional VPN solutions are used to provide access to applications across internal networks, private clouds, and public clouds, then access capability is achieved, but security vulnerabilities increase

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The cloud-based VPN server acts as a secure intermediary that establishes encrypted tunnels between users and enterprise resources. This intermediary approach centralizes security management and enables sophisticated authentication and authorization mechanisms, reducing security vulnerabilities associated with direct network connections while maintaining versatile access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical network access methods with cloud-based virtualized connections. By substituting physical network infrastructure with software-defined cloud VPN tunnels, the system achieves enhanced security through flexible encryption and centralized control while maintaining the adaptability of cloud-based access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If traditional VPN solutions are used to connect users to network resources, then network access is provided, but bandwidth consumption increases linearly with every new branch or nomadic user

Engineering Contradiction:
Improvenetwork accessVSAvoidbandwidth consumption
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The cloud-based VPN solution merges multiple network access paths through a single cloud infrastructure. Instead of creating separate dedicated VPN connections for each branch or user, the system combines traffic through shared cloud resources, reducing redundant bandwidth consumption while maintaining ease of network access for all users.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent transitions from traditional two-dimensional network topology (point-to-point connections) to a three-dimensional cloud-based architecture. By routing traffic through cloud infrastructure, the system optimizes bandwidth utilization by leveraging cloud resources and reducing direct point-to-point connectivity requirements, thereby reducing overall bandwidth consumption.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Adaptability or versatility

If Firewalls and VPN servers are installed in every private cloud to enable application routing, then application connectivity is achieved, but administrative complexity and security weaknesses increase

Engineering Contradiction:
Improveapplication connectivityVSAvoidadministrative complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cloud-based VPN server serves as a central intermediary that manages application routing across all private clouds. Instead of installing and configuring Firewalls and VPN servers in each private cloud, the system uses a centralized cloud-based controller that establishes secure connections and manages traffic routing, significantly reducing administrative complexity while maintaining application connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent inverts the traditional approach by instead of pushing connectivity infrastructure into each private cloud, it pulls connectivity management to the cloud. The cloud-based system initiates connections to private cloud resources, reversing the conventional model and eliminating the need for complex local infrastructure deployment while maintaining versatile application connectivity.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11425097B2Cloud-based virtual private access systems and methods for application access
Publication Date: 2022.08.23 ZSCALER INC
  • US11425097B2 patent drawing
  • US11425097B2 patent drawing
  • US11425097B2 patent drawing

AI summary

Systems and methods include receiving a request, in a cloud system from a user device, to access an application, wherein the application is in one of a public cloud, a private cloud, and an enterprise network, and wherein the user device is remote over the Internet; determining if the user device is permitted to access the application; if the user device is not permitted to access the application, notifying the user device the application does not exist; and if the user device is permitted to access the application, stitching together connections between the cloud system, the application, and the user device to provide access to the application.