Private Service Edge Nodes for Zero-Trust Cloud Application Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The traditional enterprise network model, with a well-defined perimeter, is no longer effective as mobile users access applications in the cloud, leading to increased security risks due to unsecured devices and extended network perimeters, necessitating a new approach for secure access to private applications.
Innovation Solution
A cloud-based system with private service edge nodes that dynamically create secure tunnels between endpoints and on-premises proxies, allowing access to applications without exposing them to the network, using lightweight connectors and central authority policies to ensure secure, application-specific access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional perimeter defense with firewalls and VPNs is used, then security control is maintained, but it cannot effectively protect against cloud-based applications and mobile users accessing from unsecured devices
Solution Approach 1:
The system segments access to applications by creating individual secure tunnels between users and specific applications, rather than providing broad network access. Each tunnel is independently managed and can be selectively opened or closed based on user credentials and application requirements, enabling fine-grained security control that adapts to cloud-based deployment models.
Solution Approach 2:
The patent introduces a cloud-based intermediary system that sits between users and applications, managing authentication and tunnel creation dynamically. This intermediary handles the complexity of securing connections to cloud applications without requiring changes to the application infrastructure itself, thereby maintaining security effectiveness while adapting to modern access patterns.
2Adaptability or versatility
If network perimeter is extended to include cloud access, then mobile user access is enabled, but security risks increase due to unsecured and unmanaged devices
Solution Approach 1:
The system extracts the security function from the network perimeter and places it in the cloud-based intermediary. Instead of relying on secured network boundaries, the system uses cloud-based authentication and tunnel management to secure access, thereby enabling mobile user access while mitigating risks from unsecured devices by not requiring them to be part of a trusted network.
Solution Approach 2:
Traditional VPNs push traffic into a secured network perimeter. This patent inverts the approach by having the cloud-based intermediary push secure tunnels outward to specific applications. The intermediary actively manages and terminates tunnels at application-level, reversing the conventional flow and eliminating the need for unsecured devices to join a network while maintaining strong security controls.
3Reliability
If applications are made invisible to unauthorized users via zero trust access, then security is improved, but access configuration complexity increases
Solution Approach 1:
The cloud-based intermediary provides self-service capabilities for access management, automatically handling authentication, credential verification, and tunnel creation based on pre-defined policies. This eliminates the need for manual configuration of access controls at the application level, as the intermediary autonomously manages the complexity of securing invisible applications while maintaining strong zero-trust security.
4Ease of operation
If cloud-based service edge nodes are deployed to provide seamless access, then access flexibility is improved, but system architecture complexity increases
Solution Approach 1:
The cloud-based intermediary is designed as a universal platform that handles multiple functions: authentication, authorization, tunnel creation, traffic routing, and security policy enforcement. By consolidating these functions into a single multi-functional system rather than separate components, the patent simplifies the overall architecture while enabling flexible seamless access to applications from any location.
Data Source
AI summary
Systems and methods include, connecting to a first service edge node in a cloud-based system and obtaining one or more addresses each for one or more service edge nodes in the cloud-based system, wherein the one or more service edge nodes include public service edge nodes and private service edge nodes; connecting to a second service edge node of the one or more service edge nodes using the corresponding address; providing a request for an application to the second service edge node; and responsive to policy and accessibility determined via the cloud-based system, receiving access to the application via a connector adjacent to the application.


