Scalable Per-Client Private Application Access via TLD+1 Directories
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based Zero Trust Network Access (ZTNA) solutions face scalability issues when handling multiple users and frequent network changes, leading to network congestion and increased computational load on brokers, especially when downloading all private applications per client.
Innovation Solution
Implementing a system that downloads Top-Level Domain (TLD)+1 domains between the user device and the broker, maintaining correlations between TLD+1 domains and application information, reducing the need to download all applications, and optimizing private application support.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the broker downloads all private applications per client to ensure complete application access information, then the client can access all private applications, but the network load on the broker increases and network congestion occurs
Solution Approach 1:
The patent segments the application access information by dividing it into TLD+1 domain prefixes and individual application domains. Instead of transferring the complete application list, the system transfers only the relevant TLD+1 domain information, which segments the data into manageable portions that reduce network load while maintaining access capability through domain-based resolution.
Solution Approach 2:
The patent extracts only the essential TLD+1 domain information from the complete application list and transfers this extracted subset to the client. This extraction approach removes unnecessary application details while preserving the core functionality needed for secure application access, thereby reducing data transfer volume and broker load.
2Adaptability or versatility
If the broker maintains a complete list of all private applications for each client, then all applications are accessible, but the computational load on the broker increases
Solution Approach 1:
The patent segments the application list into TLD+1 domain groups, allowing the broker to maintain and process information in smaller, manageable segments rather than a complete application list. This segmentation reduces the computational complexity of processing and matching applications while preserving access capability through domain-based resolution.
Solution Approach 2:
The patent extracts and transfers only the TLD+1 domain information to the client, eliminating the need for the broker to maintain and process complete application lists for all clients. This extraction reduces the broker's computational burden while maintaining application access capability through the extracted domain information.
3Adaptability or versatility
If the system downloads all private applications per client to ensure comprehensive access, then access completeness is improved, but network congestion increases
Solution Approach 1:
The patent segments the application information into TLD+1 domain prefixes, which are transferred instead of complete application lists. This segmentation reduces the amount of data transmitted over the network, improving throughput efficiency while maintaining access completeness through domain-based application resolution.
Solution Approach 2:
The patent extracts only the necessary TLD+1 domain information from complete application lists and transfers this extracted data to clients. This extraction approach reduces network traffic volume, improving network throughput efficiency while preserving application access capability through the extracted domain information.
4Loss of information
If the broker provides a full list of applications to ensure complete access information, then application visibility is improved, but the network bottleneck increases
Solution Approach 1:
The patent segments application information into TLD+1 domain groups, transferring only these segmented portions to clients. This segmentation maintains application information availability for authorized access while significantly reducing data transmission volume compared to transferring complete application lists.
Solution Approach 2:
The patent extracts and transfers only the TLD+1 domain information needed for application resolution, removing unnecessary application details from the data transmission. This extraction maintains essential application information availability while reducing data transmission volume and network load.
Data Source
AI summary
Systems and methods implemented via a broker in a cloud-based system include steps of, responsive to a user and associated user device executing a client connector being authenticated, receiving a notification from the client connector; determining private applications accessible by the user based on policy, wherein the private applications are located in one of a public cloud, a private cloud, and an enterprise network; and sending a Top-Level Domain+1 (TLD+1) list of the accessible private applications to the user device, wherein the TLD+1 includes a TLD and a domain name.


