Private Service Edge Nodes for Zero-Trust Cloud Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional enterprise network model, with a well-defined perimeter, is no longer effective as mobile users access applications in the cloud, leading to increased security risks due to unsecured devices and extended network perimeters, necessitating a new approach for secure access to private applications.

Innovation Solution

A cloud-based system with private service edge nodes that dynamically create secure tunnels between endpoints and on-premises proxies, allowing access to applications without exposing them to the network, using lightweight connectors and central authority policies to ensure secure, application-specific access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter defense with firewalls and VPNs is used, then security control is maintained, but it cannot effectively protect against cloud-based applications and mobile users accessing from unsecured devices

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidadaptability to cloud and mobile access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments access to applications by creating individual secure tunnels between users and specific applications, rather than providing broad network access. Each tunnel is independently managed and can be selectively opened or closed based on user credentials and application requirements, enabling fine-grained security control that adapts to cloud-based deployment models.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud-based intermediary system that sits between users and applications, managing authentication and tunnel creation dynamically. This intermediary handles the complexity of securing connections to cloud applications without requiring changes to the application infrastructure itself, thereby maintaining security effectiveness while adapting to modern access patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network perimeter is extended to include cloud access, then mobile user access is enabled, but security risks increase due to unsecured and unmanaged devices

Engineering Contradiction:
Improveaccess capability for mobile usersVSAvoidsecurity risks from unsecured devices
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system extracts the security function from the network perimeter and places it in the cloud-based intermediary. Instead of relying on secured network boundaries, the system uses cloud-based authentication and tunnel management to secure access, thereby enabling mobile user access while mitigating risks from unsecured devices by not requiring them to be part of a trusted network.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Traditional VPNs push traffic into a secured network perimeter. This patent inverts the approach by having the cloud-based intermediary push secure tunnels outward to specific applications. The intermediary actively manages and terminates tunnels at application-level, reversing the conventional flow and eliminating the need for unsecured devices to join a network while maintaining strong security controls.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If applications are made invisible to unauthorized users via zero trust access, then security is improved, but access configuration complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidaccess control configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud-based intermediary provides self-service capabilities for access management, automatically handling authentication, credential verification, and tunnel creation based on pre-defined policies. This eliminates the need for manual configuration of access controls at the application level, as the intermediary autonomously manages the complexity of securing invisible applications while maintaining strong zero-trust security.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If cloud-based service edge nodes are deployed to provide seamless access, then access flexibility is improved, but system architecture complexity increases

Engineering Contradiction:
Improveseamless access experienceVSAvoidcloud architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The cloud-based intermediary is designed as a universal platform that handles multiple functions: authentication, authorization, tunnel creation, traffic routing, and security policy enforcement. By consolidating these functions into a single multi-functional system rather than separate components, the patent simplifies the overall architecture while enabling flexible seamless access to applications from any location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12368697B2Private service edge nodes in a cloud-based system for private application access
Publication Date: 2025.07.22 ZSCALER INC
  • US12368697B2 patent drawing
  • US12368697B2 patent drawing
  • US12368697B2 patent drawing

AI summary

Systems and methods include, connecting to a first service edge node in a cloud-based system and obtaining one or more addresses each for one or more service edge nodes in the cloud-based system, wherein the one or more service edge nodes include public service edge nodes and private service edge nodes; connecting to a second service edge node of the one or more service edge nodes using the corresponding address; providing a request for an application to the second service edge node; and responsive to policy and accessibility determined via the cloud-based system, receiving access to the application via a connector adjacent to the application.