Hardware Zero Trust Network Access Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Zero Trust Network Access (ZTNA) solutions are vulnerable to malicious OS-level attacks due to their software-based implementation, which limits their effectiveness on unmanaged devices and those with unsupported operating systems, and they expose applications to the internet, increasing security risks.

Innovation Solution

Implementing a hardware-based ZTNA agent that operates below the operating system, utilizing platform hardware resources such as NICs and secure elements to provide application-level access control, reducing the digital attack surface and eliminating the need for public-facing services like VPNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a software-based ZTNA agent is implemented, then the system is easier to deploy and operate, but the system becomes vulnerable to OS-level attacks and malicious software

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the software-based ZTNA agent with a hardware-based agent implemented in dedicated circuitry (ASIC, FPGA, or other hardware). This substitution moves the security enforcement from the software layer to the hardware layer, making it immune to OS-level attacks and malicious software while maintaining deployment capability through hardware integration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the ZTNA functionality into a dedicated hardware component separate from the main system operations. The hardware agent is implemented as a distinct security module that operates independently from the OS and application layers, creating a isolated security enforcement point that cannot be compromised by software attacks.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a hardware-based ZTNA agent is implemented, then security against OS attacks is improved, but device compatibility and ease of deployment are reduced

Engineering Contradiction:
Improvesecurity against OS attacksVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent designs the hardware agent to be universally applicable across different device types and operating systems. The agent can be implemented as a standalone hardware module or integrated into various device architectures (smartphones, tablets, computers, IoT devices), making it adaptable to diverse platforms while maintaining consistent security enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent moves the security enforcement to a different layer (hardware dimension) that is independent of the software dimension. This dimensional shift allows the security agent to operate below the OS layer, making it compatible with any device regardless of the operating system installed, as it enforces security at the hardware level before software can interfere.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If public-facing services like VPNs are used, then remote access is enabled, but the digital attack surface is increased

Engineering Contradiction:
Improveremote access capabilityVSAvoiddigital attack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the public-facing service layer (VPN, reverse proxy, or tunneling server) and replaces it with direct hardware-based authentication and access control. Instead of routing traffic through exposed network services, the hardware agent performs authentication and establishes secure connections directly, eliminating the need for public-facing services and their associated attack surfaces.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware agent acts as an intermediary between the device and network resources, performing authentication and authorization at the hardware level. This intermediary function replaces the need for public-facing VPN services, as the hardware agent can directly establish secure authenticated connections without requiring exposed network entry points.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240348660A1Hardware-based Zero Trust Network Access Agent for Improved Security
Publication Date: 2024.10.17 INTEL CORP
  • US20240348660A1 patent drawing
  • US20240348660A1 patent drawing
  • US20240348660A1 patent drawing

AI summary

Hardware-based Zero Trust Network Access Agents for Improved Security are disclosed herein. An example apparatus includes network interface circuitry; machine-readable instructions; and first processor circuitry programmable by the instructions to detect, via firmware execution, a request from a device to access a resource via a zero trust network access interface; determine, via the firmware execution, a security state of the device; and based on the security state of the device, transmit the request to a host operating system (OS) via a virtual network interface, the operating system executed via second processor circuitry different than the first processor circuitry.