Cloud VPN Brokering for Zero-Trust Enterprise Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise network architectures, which rely on well-defined perimeters and site-to-site VPNs, struggle to secure and manage access for mobile users and cloud-based applications, leading to increased security risks and complex network administration.

Innovation Solution

A cloud-based system that brokers VPN access by creating secure tunnels between third-party networks and enterprise resources, using a zero-trust approach to authenticate and authorize access on a per-user, per-application basis, decoupling applications from the network and providing access through lightweight connectors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If site-to-site VPNs are configured to enable system-to-system access from third parties, then data transfer capability is provided, but device complexity and administration overhead increase significantly

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based VPN broker as an intermediary that mediates between third-party networks and enterprise resources. Instead of direct site-to-site VPN connections requiring complex network configuration, the broker receives connections from third parties, authenticates them, and creates secure tunnels to appropriate resources. This intermediary approach simplifies the network architecture while maintaining data transfer capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the VPN brokering functionality from the enterprise network infrastructure and places it in a cloud-based system. This separation removes the complexity of VPN configuration, authentication, and tunnel management from the enterprise network devices, centralizing these functions in a dedicated cloud service that handles third-party access requests.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If traditional VPN perimeters are extended to the Internet for cloud applications, then access capability is improved, but security risks increase due to unsecured devices

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The cloud-based VPN broker acts as a security intermediary between unsecured external devices and enterprise resources. It implements zero-trust authentication and authorization, verifying each user's identity and permissions before allowing access. This mediator approach enables Internet access for cloud applications while preventing direct exposure of resources to potentially unsecured devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements differentiated access control where each user receives customized security policies and permissions based on their specific needs and authorization level. Instead of a blanket security perimeter, the system applies local security measures tailored to each user-session, allowing secure access for authorized users while blocking unauthorized access attempts.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If mobile users are allowed access to enterprise networks, then user accessibility is improved, but network security and management complexity increase

Engineering Contradiction:
Improveuser accessibilityVSAvoidnetwork management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The cloud-based VPN broker provides a universal access platform that handles multiple types of users (mobile users, third parties, contractors) through a single system. It implements unified authentication, authorization, and tunnel management that works across different device types and network locations, simplifying network management while maintaining broad accessibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables mobile users to self-authenticate and establish secure connections without requiring manual network configuration or administrator intervention. The broker automatically authenticates users, determines appropriate access rights, and provisions secure tunnels as needed, reducing the administrative burden while maintaining ease of access for users.

Inventive Principle:
Principle #25Self-service

4Device complexity

If cloud-based VPN brokering is implemented, then configuration complexity is reduced, but system infrastructure requirements increase

Engineering Contradiction:
Improveconfiguration complexityVSAvoidsystem infrastructure requirements
Core Design Contradiction:
Device complexityVSEase of manufacture

Solution Approach 1:

The patent leverages existing cloud infrastructure and services as intermediaries to implement VPN brokering functionality. By building on top of established cloud platforms, the system avoids the need for extensive custom infrastructure while providing sophisticated VPN management capabilities. The cloud environment provides the necessary computing, networking, and security resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud-based broker utilizes multi-functional cloud services that can handle authentication, encryption, tunneling, and resource management through integrated platforms. This approach consolidates multiple infrastructure requirements into unified cloud services, reducing the overall system complexity while maintaining comprehensive VPN brokering functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12355589B2Systems and methods for Virtual Private Network (VPN) brokering to enterprise resources
Publication Date: 2025.07.08 ZSCALER INC
  • US12355589B2 patent drawing
  • US12355589B2 patent drawing
  • US12355589B2 patent drawing

AI summary

Systems and methods for Virtual Private Network (VPN) brokering to enterprise resources include receiving a connection from a Virtual Private Network (VPN) device associated with a third party network; receiving a request from the third party network to access a resource, wherein the resource is in one of a public cloud, a private cloud, and an enterprise network; determining if an entity associated with the request is permitted to access the resource; and responsive to the determining, creating secure tunnels between the third party network and the resource.