Path Attestation for Zero Trust Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies, such as Zero Trust Network Access (ZTNA), often complicate application deployment and fail to reliably control insider threats and credential theft, leading to potential unauthorized access to resources.

Innovation Solution

A path attestation system that monitors and assesses the risk of paths to resources in a computing environment, providing digital authorization data based on the threat posture of applications, which is used to authorize access requests from client devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Zero Trust Network Access (ZTNA) is implemented to control access to resources, then security is improved, but deployment complexity increases and insider threats are not reliably controlled

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary assessment of the attack path and threat posture before granting access. The path monitoring subsystem evaluates potential attack paths and the path attestation subsystem verifies threat posture metrics in advance, so that access decisions are based on pre-computed security assessments rather than complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary subsystems (path monitoring subsystem and path attestation subsystem) that mediate between the client device and the protected resource. These intermediaries handle the complex security assessments and provide simplified access control decisions, reducing the complexity burden on the overall system deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If traditional access control is used, then deployment is simple, but unauthorized access from insider threats and credential theft cannot be prevented

Engineering Contradiction:
Improvedeployment simplicityVSAvoidprotection against unauthorized access
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The security system is segmented into distinct functional components: path monitoring subsystem that identifies attack paths, path attestation subsystem that evaluates threat posture, and access control subsystem that makes decisions. This segmentation allows each component to be implemented independently with clear interfaces, maintaining deployment simplicity while enhancing protection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements continuous feedback loops where the path monitoring subsystem constantly monitors for changes in the attack path, and the path attestation subsystem re-evaluates threat posture metrics. This feedback mechanism enables the system to dynamically respond to insider threats and credential theft attempts without requiring complete redeployment.

Inventive Principle:
Principle #23Feedback

3Speed

If access is granted without threat posture assessment, then access speed is fast, but unauthorized access cannot be detected

Engineering Contradiction:
Improveaccess speedVSAvoidthreat detection accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

Threat posture assessment is performed in advance before access requests are processed. The path monitoring subsystem pre-identifies potential attack paths and the path attestation subsystem pre-evaluates threat posture metrics, so that when access requests arrive, the system can make rapid decisions based on already-computed security assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the depth and scope of threat posture assessment based on the specific context of each access request. For trusted paths with low risk, the assessment can be minimized for fast access. For suspicious paths or high-value resources, more comprehensive assessment is performed, optimizing the balance between access speed and detection accuracy.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250141870A1Path attestation for use in authorizing access based on threat posture
Publication Date: 2025.05.01 VIAVI SOLUTIONS INC(US)
  • US20250141870A1 patent drawing
  • US20250141870A1 patent drawing
  • US20250141870A1 patent drawing

AI summary

In some implementations, a device may receive, from a path monitoring subsystem, an indication of a path risk associated with a path to a resource in a computing environment. The device may transmit, to a client device, digital authorization data based on a threat posture associated with an application in the computing environment, wherein the threat posture is based on the path risk associated with the path, and an access request by the client device to access the resource is based on the digital authorization data.