Modified VPN Server Zero Trust Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing Zero Trust security in networks is challenging due to the need for expensive modifications of software applications, which can increase latency and risk data loss or corruption, especially for legacy applications that cannot be easily modified.

Innovation Solution

A modified Virtual Private Network (VPN) that controls access by establishing separate connection tunnels for each software application, requiring frequent authentication and using an active directory to manage access, thereby limiting lateral movement of malicious entities and reducing the need for application modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software applications are modified to implement Zero Trust security, then network security is improved, but latency increases and data loss or corruption risk increases

Engineering Contradiction:
Improvenetwork securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network access control by creating separate connection tunnels for each software application. Each tunnel is independently managed and authenticated, allowing Zero Trust security to be implemented at the tunnel level rather than requiring modifications to the applications themselves. This segmentation enables security controls to be applied without impacting application performance or introducing latency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a VPN server as an intermediary between client devices and software applications. The server establishes and manages authenticated connection tunnels that route traffic to specific applications. This intermediary handles the security authentication and access control functions, eliminating the need to modify applications while maintaining strong security without performance penalties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software applications are modified to implement Zero Trust security, then network security is improved, but data loss or corruption risk increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddata loss or corruption
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

By segmenting access through separate connection tunnels for each application, the patent isolates data streams and prevents unauthorized access or data corruption. The tunnel-level segmentation ensures that even if one application is compromised, other applications remain protected, reducing the overall risk of data loss while maintaining security without application modifications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The VPN server acts as a secure intermediary that authenticates and authorizes access to applications before data transmission. This intermediary layer protects data by verifying credentials and managing access rights centrally, preventing data loss or corruption without requiring modifications to the applications that handle the data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If legacy software applications are modified to implement Zero Trust security, then network security is improved, but modification difficulty increases

Engineering Contradiction:
Improvenetwork securityVSAvoidmodification difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Instead of modifying legacy applications to implement Zero Trust security, the patent inverts the approach by modifying the network infrastructure (VPN server and connection tunnels) to provide security controls. This inversion allows legacy applications to remain unchanged while still achieving Zero Trust security through the tunnel-level access control mechanism.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The VPN server serves as an intermediary that provides Zero Trust security functions without requiring changes to legacy applications. The server handles authentication, authorization, and traffic routing for applications through secure connection tunnels, enabling security implementation on legacy systems that cannot be modified.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If frequent authentication is required for Zero Trust security, then network security is improved, but access speed decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary authentication when the connection tunnel is initially established. Once authenticated, the tunnel maintains secure access without requiring frequent re-authentication for subsequent data transmissions. This preliminary action approach ensures strong security while maintaining fast access speeds for authorized communications.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240291803A1Zero Trust Support for Secure Networks Via Modified Virtual Private Network
Publication Date: 2024.08.29 RED HAT INC
  • US20240291803A1 patent drawing
  • US20240291803A1 patent drawing
  • US20240291803A1 patent drawing

AI summary

Zero trust support for secure networks can be provided via a modified virtual private network (VPN) server. For example, the VPN server may receive, from a VPN client executing on a client device, a first access request for a first software application in a computing environment that is accessible via the VPN server. The first access request can include authentication credentials for the VPN server. The VPN server can authenticate the first access request based on the authentication credentials. In response, a first connection tunnel can be provided between the client device and the first software application. The client device can access the first software application via the first connection tunnel. The VPN server can also deny a second access request received via the first connection tunnel for a second software application in the computing environment.