Cloud WAAP System for API Security and Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional enterprise network security model is inadequate for the modern cloud-based environment, where applications are moved to the cloud and users access them from unsecured devices, increasing the risk of data breaches and unauthorized access.

Innovation Solution

The implementation of a cloud-based Web Application and API Protection (WAAP) system that combines with Zero Trust Network Access (ZTNA) to secure applications by not exposing them directly to the Internet, using customizable security rules, real-time threat intelligence, and secure access through a cloud-based system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications are exposed to the Internet for direct access, then user accessibility is improved, but security risk increases

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based WAAP system as an intermediary between users and applications. This intermediary layer inspects, filters, and monitors all traffic before it reaches the applications, allowing users to access applications while the WAAP system blocks malicious traffic and enforces security policies without exposing applications directly to the Internet

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a traditional perimeter security model is used, then internal network security is maintained, but cloud-based access security deteriorates

Engineering Contradiction:
Improveinternal network securityVSAvoidcloud-based access security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from traditional two-dimensional perimeter security (network layer) to a three-dimensional security model that includes application layer inspection through WAAP. This adds a new dimension of security inspection at the application level, enabling deep packet inspection, API security monitoring, and web application firewall protection for cloud-based access while maintaining internal network security

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-affected harmful factors

If applications are protected from direct Internet access, then security is improved, but access complexity increases

Engineering Contradiction:
Improveapplication exposureVSAvoidaccess complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The WAAP system provides self-service security features including automatic threat intelligence updates, real-time anomaly detection, and automated policy enforcement. The system autonomously monitors traffic patterns, detects security threats, and applies corrective actions without requiring manual intervention, thereby maintaining strong application protection while simplifying the access experience for users

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12238070B2Cloud-based web application and API protection from untrusted users and devices
Publication Date: 2025.02.25 ZSCALER INC
  • US12238070B2 patent drawing
  • US12238070B2 patent drawing
  • US12238070B2 patent drawing

AI summary

Systems and methods include, responsive to determining a user can access an application via a cloud-based system, wherein the application is in one of a public cloud, a private cloud, and an enterprise network, and wherein the user is remote over the Internet, obtaining a predetermined inspection profile for the user with the inspection profile including a plurality of rules evaluated in an order; performing inspection of the access using the plurality of rules in the order; and responsive to results of any of the plurality of rules, one or more of monitoring, allowing, blocking, and redirecting the access, via the cloud-based system.