Firewall Connector Provisioning for Zero Trust Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy firewalls and VPNs face performance, manageability, and security limitations in managing hybrid networks, leading to increased vulnerability and compliance issues, especially with the rise of cloud-based services and remote workforces.

Innovation Solution

A system that integrates a centralized management platform with a firewall connector to provide dynamic route provisioning, leveraging Zero Trust Network Access (ZTNA) and Security Services Edge (SSE) for secure, scalable access to cloud resources, using a unified management portal and software-defined networking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy firewalls and VPNs are used to manage hybrid networks, then network security is provided, but performance, manageability, and security limitations occur

Engineering Contradiction:
Improvenetwork securityVSAvoidmanageability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a firewall connector as an intermediary component that bridges the legacy firewall and the cloud-based access control service. This connector handles complex authentication, authorization, and device evaluation tasks, offloading them from the legacy firewall infrastructure. The connector acts as a mediator that translates between traditional network security protocols and modern cloud-based Zero Trust policies, thereby improving manageability while maintaining security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions network security management from a traditional on-premises dimension to a cloud-based dimension. By moving the access control service to the cloud, the system gains enhanced scalability, automated provisioning, and improved manageability. The firewall connector enables this dimensional shift by maintaining compatibility with legacy firewalls while connecting to cloud-based services, allowing organizations to evolve their security architecture without completely replacing existing infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If cloud-based services and remote access are increased, then organizational competitiveness is improved, but security vulnerabilities and compliance issues increase

Engineering Contradiction:
Improvecloud-based service accessVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security actions by evaluating device characteristics and enforcing access policies before granting access to cloud resources. The access control service performs device evaluation, authentication, and authorization checks in advance, ensuring that only compliant devices can connect to private networks. This preliminary verification prevents security vulnerabilities from being introduced into the network, allowing organizations to safely increase cloud-based service access and remote work capabilities.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional firewall infrastructure is used, then network security is maintained, but scalability and performance are limited

Engineering Contradiction:
Improvenetwork securityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network security functionality into distinct components: the legacy firewall handles traditional packet filtering and network segmentation, while the firewall connector and cloud-based access control service handle authentication, authorization, and device evaluation. This segmentation allows each component to specialize in specific tasks, improving overall performance and scalability without compromising the security functions that the legacy firewall performs reliably.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If hybrid network architecture is implemented, then access to cloud resources is enabled, but connectivity complexity and security requirements increase

Engineering Contradiction:
Improvehybrid network connectivityVSAvoidconnectivity complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The firewall connector is designed as a universal component that performs multiple functions: it acts as a network gateway, authentication server, policy enforcement point, and device evaluation system. By consolidating these diverse functions into a single connector, the patent simplifies the hybrid network architecture and reduces connectivity complexity while enabling comprehensive access to cloud resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260025364A1Triggering provisioning of cloud-based security through firewall
Publication Date: 2026.01.22 SONICWALL INC
  • US20260025364A1 patent drawing
  • US20260025364A1 patent drawing
  • US20260025364A1 patent drawing

AI summary

This disclosure is related to methods and apparatus for triggering provisioning of cloud-based security through a network firewall. Triggering provisioning includes an access control service verifying authorization of the end-user device to access the private network and evaluating device characteristics of the end-user device, applying configured application control policies based on the device characteristics, evaluating Zero Trust Network Access (ZTNA) policies based on the device characteristics and application configured application control policies, generating a unique session token when the request is approved, providing the unique session token to the firewall connector, and forming a connector tunnel that establishes a secure connection between the end-user device and the private network.