Cloud VPN Brokering for Zero-Trust Enterprise Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional enterprise network architectures, which rely on well-defined perimeters and site-to-site VPNs, struggle to secure and manage access for mobile users and cloud-based applications, leading to increased security risks and complex network administration.
Innovation Solution
A cloud-based system that brokers VPN access by creating secure tunnels between third-party networks and enterprise resources, using a zero-trust approach to authenticate and authorize access on a per-user, per-application basis, decoupling applications from the network and providing access through lightweight connectors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If site-to-site VPNs are configured to enable system-to-system access from third parties, then data transfer capability is provided, but device complexity and administration overhead increase significantly
Solution Approach 1:
The patent introduces a cloud-based VPN broker as an intermediary that mediates between third-party networks and enterprise resources. Instead of direct site-to-site VPN connections requiring complex network configuration, the broker receives connections from third parties, authenticates them, and creates secure tunnels to appropriate resources. This intermediary approach simplifies the network architecture while maintaining data transfer capability.
Solution Approach 2:
The patent extracts the VPN brokering functionality from the enterprise network infrastructure and places it in a cloud-based system. This separation removes the complexity of VPN configuration, authentication, and tunnel management from the enterprise network devices, centralizing these functions in a dedicated cloud service that handles third-party access requests.
2Adaptability or versatility
If traditional VPN perimeters are extended to the Internet for cloud applications, then access capability is improved, but security risks increase due to unsecured devices
Solution Approach 1:
The cloud-based VPN broker acts as a security intermediary between unsecured external devices and enterprise resources. It implements zero-trust authentication and authorization, verifying each user's identity and permissions before allowing access. This mediator approach enables Internet access for cloud applications while preventing direct exposure of resources to potentially unsecured devices.
Solution Approach 2:
The patent implements differentiated access control where each user receives customized security policies and permissions based on their specific needs and authorization level. Instead of a blanket security perimeter, the system applies local security measures tailored to each user-session, allowing secure access for authorized users while blocking unauthorized access attempts.
3Ease of operation
If mobile users are allowed access to enterprise networks, then user accessibility is improved, but network security and management complexity increase
Solution Approach 1:
The cloud-based VPN broker provides a universal access platform that handles multiple types of users (mobile users, third parties, contractors) through a single system. It implements unified authentication, authorization, and tunnel management that works across different device types and network locations, simplifying network management while maintaining broad accessibility.
Solution Approach 2:
The system enables mobile users to self-authenticate and establish secure connections without requiring manual network configuration or administrator intervention. The broker automatically authenticates users, determines appropriate access rights, and provisions secure tunnels as needed, reducing the administrative burden while maintaining ease of access for users.
4Device complexity
If cloud-based VPN brokering is implemented, then configuration complexity is reduced, but system infrastructure requirements increase
Solution Approach 1:
The patent leverages existing cloud infrastructure and services as intermediaries to implement VPN brokering functionality. By building on top of established cloud platforms, the system avoids the need for extensive custom infrastructure while providing sophisticated VPN management capabilities. The cloud environment provides the necessary computing, networking, and security resources.
Solution Approach 2:
The cloud-based broker utilizes multi-functional cloud services that can handle authentication, encryption, tunneling, and resource management through integrated platforms. This approach consolidates multiple infrastructure requirements into unified cloud services, reducing the overall system complexity while maintaining comprehensive VPN brokering functionality.
Data Source
AI summary
Systems and methods for Virtual Private Network (VPN) brokering to enterprise resources include receiving a connection from a Virtual Private Network (VPN) device associated with a third party network; receiving a request from the third party network to access a resource, wherein the resource is in one of a public cloud, a private cloud, and an enterprise network; determining if an entity associated with the request is permitted to access the resource; and responsive to the determining, creating secure tunnels between the third party network and the resource.


