Cloud-Based ZTNA Service for Firewall-Free Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved techniques for deploying and managing zero trust network access applications with a cloud-based security infrastructure.

Innovation Solution

A zero trust network access (ZTNA) system is modified to facilitate distributed and/or cloud-based deployments of components for a control plane and a data plane, supporting a network-accessible front end for customer-hosted applications, allowing secure access through a cloud-based service without exposing the customer premises to public networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cloud-based ZTNA system is deployed to provide secure access to customer-hosted applications, then security is improved and attack surfaces are reduced, but network connectivity and access complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork connectivity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based ZTNA service as an intermediary between external users and customer-hosted applications. This service includes a service proxy that mediates all access requests, establishing secure tunnels through protocols like WebSocket or HTTP long-polling. The intermediary handles authentication, authorization, and secure communication, improving security while managing network complexity through standardized interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The ZTNA system is segmented into distinct functional components: a control plane for management and configuration, a data plane for actual data transmission, and a service proxy for access mediation. This segmentation allows each component to be optimized independently and deployed flexibly in the cloud, reducing overall system complexity while maintaining strong security controls.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If distributed and cloud-based deployments are used for control plane and data plane components, then deployment flexibility and scalability are improved, but system complexity increases

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system is divided into a control plane (for management, configuration, and authentication) and a data plane (for actual application data transmission). These planes can be deployed independently in different cloud environments or on-premises, providing deployment flexibility while managing complexity through clear separation of concerns and standardized communication protocols between planes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service proxy is designed as a universal component that can handle multiple functions: authentication, authorization, secure tunnel establishment, and application brokering. This multi-functional design reduces the need for multiple specialized components, thereby reducing system complexity while maintaining high adaptability to different deployment scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure tunnels are established through cloud-based services, then security and protection from attack surfaces are improved, but connection establishment time and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing secure tunnels and maintaining them in a ready state before actual data transmission begins. The service proxy can pre-authenticate users and pre-set up communication channels, reducing the time required for connection establishment when actual access is needed while maintaining strong security controls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Secure tunnels are maintained in a continuous, active state rather than being established and torn down for each access request. The service proxy keeps encryption contexts and authentication states alive, allowing for rapid resumption of secure communication while minimizing connection establishment time and maintaining security throughout the session.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12413558B2Cloud-based zero trust network access service
Publication Date: 2025.09.09 SOPHOS LTD
  • US12413558B2 patent drawing
  • US12413558B2 patent drawing
  • US12413558B2 patent drawing

AI summary

Infrastructure for zero trust network access (ZTNA) is deployed as a cloud-based service remotely from a customer premises where user applications are hosted. By connecting an appliance on the customer premises to the cloud-based service through a secure tunnel or the like, an application hosted on the customer premises can then be accessed externally as a ZTNA application without the customer premises opening a firewall to public networks or otherwise exposing potential attack surfaces to the customer premises.