Dynamic Application Provisioning for Zero Trust and Virtual Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual and zero trust network access (ZTNA) solutions either provide only ZT versions or virtual versions of applications, lacking flexibility and efficiency, leading to latency issues and increased costs, while introducing security risks and maintenance challenges.
Innovation Solution
A flexible architecture that dynamically provisions either a ZT or virtual version of an application based on user device configurations and location, using a computing system to select the appropriate application type based on parameters such as device status and location, and enforce security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If virtual applications are used for secure remote access, then accessibility to corporate resources is improved, but latency increases due to network dependencies
Solution Approach 1:
The system dynamically assigns different application delivery methods based on device characteristics and network conditions. Zero-trust applications are deployed locally to devices meeting security criteria, eliminating network latency for those users, while virtual applications serve other scenarios. This localized optimization resolves the contradiction by making the system responsive to specific device qualities rather than applying a uniform approach.
Solution Approach 2:
The application delivery system transitions from static to dynamic decision-making based on real-time device parameters and security posture. The system continuously evaluates device compliance, network conditions, and application requirements to determine optimal delivery methods, allowing latency to be minimized when conditions permit while maintaining security protocols when needed.
2Reliability
If zero trust applications are deployed locally, then security is improved, but device compatibility and remote access flexibility are reduced
Solution Approach 1:
The system changes the security parameter from binary (trusted/not trusted) to a spectrum of device compliance states. By evaluating multiple device parameters (OS version, security patches, installed agents, network configuration), the system dynamically adjusts the level of trust and corresponding access method. This allows highly compliant devices to run secure local zero-trust applications while less compliant devices access applications virtually, resolving the contradiction between security and compatibility.
Solution Approach 2:
The user base is segmented into different groups based on device compliance and security posture. Instead of applying a uniform security policy to all devices, the system divides access methods into segments: zero-trust local applications for compliant devices, virtual applications for non-compliant devices, and cloud-based alternatives for mobile devices. This segmentation resolves the contradiction by allowing strict security where applicable while maintaining broad compatibility elsewhere.
3Extent of automation
If virtualization servers are used to host applications, then centralized control is improved, but infrastructure cost and maintenance burden increase
Solution Approach 1:
The system extracts applications from the virtualization server environment and deploys them directly to endpoint devices when security criteria are met. This eliminates the need for continuous server mediation for compliant devices, reducing infrastructure utilization and associated costs while maintaining centralized control through policy enforcement. The extraction principle resolves the contradiction by removing unnecessary intermediary infrastructure for scenarios where it adds cost without improving security.
Solution Approach 2:
Instead of requiring all users to access applications through virtualization servers, the system creates and distributes copies of approved applications to compliant endpoint devices. These local copies eliminate ongoing server resource consumption for rendering and transmitting application interfaces, significantly reducing infrastructure costs and energy consumption while maintaining centralized licensing and update control through the delivery system.
4Ease of operation
If third party cloud resources are used for application hosting, then accessibility is improved, but security risks of data breaches and system downtime increase
Solution Approach 1:
The system introduces an intermediary evaluation layer between the user device and application delivery method selection. This intermediary assesses device security posture, network conditions, and application sensitivity to determine the appropriate delivery method. For sensitive applications or non-compliant devices, the intermediary directs traffic through secure virtualization infrastructure rather than direct cloud access, thereby mediating security risks while preserving accessibility. This intermediary mechanism resolves the contradiction by adding security evaluation without eliminating remote access capability.
Data Source
AI summary
Systems and methods described herein may store information about a Zero Trust (ZT) version of an application that is configured for local execution at user devices and a virtual version of the application that is configured for virtual execution in virtualization servers. A request for the application may be received from a user device along with parameters associated with the user device. The parameters may indicate whether the user device has joined a private domain, whether the user device has a certificate associated with the private domain, the physical location of the user device, whether the user device is executing an anti-virus application, etc. Either the ZT version of the application or the virtual version of the application may be selected for the user device based on the parameters provided by the user device.


