Cloud-Based ZTNA Service for Firewall-Free Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for improved techniques for deploying and managing zero trust network access applications with a cloud-based security infrastructure.
Innovation Solution
A zero trust network access (ZTNA) system is modified to facilitate distributed and/or cloud-based deployments of components for a control plane and a data plane, supporting a network-accessible front end for customer-hosted applications, allowing secure access through a cloud-based service without exposing the customer premises to public networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a cloud-based ZTNA system is deployed to provide secure access to customer-hosted applications, then security is improved and attack surfaces are reduced, but network connectivity and access complexity increase
Solution Approach 1:
The patent introduces a cloud-based ZTNA service as an intermediary between external users and customer-hosted applications. This service includes a service proxy that mediates all access requests, establishing secure tunnels through protocols like WebSocket or HTTP long-polling. The intermediary handles authentication, authorization, and secure communication, improving security while managing network complexity through standardized interfaces.
Solution Approach 2:
The ZTNA system is segmented into distinct functional components: a control plane for management and configuration, a data plane for actual data transmission, and a service proxy for access mediation. This segmentation allows each component to be optimized independently and deployed flexibly in the cloud, reducing overall system complexity while maintaining strong security controls.
2Adaptability or versatility
If distributed and cloud-based deployments are used for control plane and data plane components, then deployment flexibility and scalability are improved, but system complexity increases
Solution Approach 1:
The system is divided into a control plane (for management, configuration, and authentication) and a data plane (for actual application data transmission). These planes can be deployed independently in different cloud environments or on-premises, providing deployment flexibility while managing complexity through clear separation of concerns and standardized communication protocols between planes.
Solution Approach 2:
The service proxy is designed as a universal component that can handle multiple functions: authentication, authorization, secure tunnel establishment, and application brokering. This multi-functional design reduces the need for multiple specialized components, thereby reducing system complexity while maintaining high adaptability to different deployment scenarios.
3Reliability
If secure tunnels are established through cloud-based services, then security and protection from attack surfaces are improved, but connection establishment time and latency increase
Solution Approach 1:
The system performs preliminary actions by pre-establishing secure tunnels and maintaining them in a ready state before actual data transmission begins. The service proxy can pre-authenticate users and pre-set up communication channels, reducing the time required for connection establishment when actual access is needed while maintaining strong security controls.
Solution Approach 2:
Secure tunnels are maintained in a continuous, active state rather than being established and torn down for each access request. The service proxy keeps encryption contexts and authentication states alive, allowing for rapid resumption of secure communication while minimizing connection establishment time and maintaining security throughout the session.
Data Source
AI summary
Infrastructure for zero trust network access (ZTNA) is deployed as a cloud-based service remotely from a customer premises where user applications are hosted. By connecting an appliance on the customer premises to the cloud-based service through a secure tunnel or the like, an application hosted on the customer premises can then be accessed externally as a ZTNA application without the customer premises opening a firewall to public networks or otherwise exposing potential attack surfaces to the customer premises.


