Protected Resource Discovery Tokens for Zero Trust Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Zero Trust access models, resources are discoverable from public networks and not-yet-trusted devices, raising security concerns, as existing systems rely solely on authentication to protect resources.

Innovation Solution

Implementing a Discovery Token Service that requires endpoint devices to establish a minimum level of trust through multi-factor authentication before allowing discovery of protected resources, using tokens signed with asymmetric or symmetric keys to verify identity and enforce access policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If resources are made discoverable from public networks in a Zero Trust access model, then accessibility and ease of operation are improved, but security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improveresource discoverabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway as an intermediary component that sits between public networks and protected resources. This gateway enforces multi-factor authentication and token validation, allowing resources to remain discoverable while preventing unauthorized access. The gateway mediates all discovery requests, verifying device trustworthiness before permitting access to resource location information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and authorization checks before allowing resource discovery. Devices must complete multi-factor authentication and receive valid tokens beforehand. This preliminary action ensures that only trusted devices can discover resources, preventing unauthorized access while maintaining discoverability for authenticated users.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If multi-factor authentication and token validation are implemented before resource discovery, then security is improved, but device complexity and authentication overhead increase

Engineering Contradiction:
Improvereconnaissance protectionVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The gateway serves multiple functions: it acts as an authentication enforcement point, a token validation service, a discovery controller, and a policy enforcement mechanism. By consolidating these functions into a single universal component, the system reduces overall complexity while maintaining strong security controls for resource discovery.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If resource discovery is limited to authenticated devices only, then security is improved, but accessibility and ease of operation for legitimate users may deteriorate

Engineering Contradiction:
Improveuntrusted device accessVSAvoidresource accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically changes the trust parameter based on authentication state. Unauthenticated devices receive no discovery information, while authenticated devices receive appropriate resource location data. This parameter change approach maintains security by controlling access based on authentication status while ensuring legitimate users can access resources seamlessly.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12452253B2Limiting discovery of a protected resource in a zero trust access model
Publication Date: 2025.10.21 CISCO TECHNOLOGY INC
  • US12452253B2 patent drawing
  • US12452253B2 patent drawing
  • US12452253B2 patent drawing

AI summary

According to an embodiment, a system comprises one or more processors and one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations. The operations comprise determining that an endpoint device has requested to discover a location of a protected resource that is protected by a gateway, determining whether the endpoint device has provided a token that is valid, and permitting the endpoint device to discover the location of the protected resource based on determining that the endpoint device has provided the token that is valid. The token indicates that the endpoint device successfully completed a first multi-factor authentication procedure in connection with accessing an authentication enforcement resource.