Secure Access Gateway Stream Prioritization for ZTNA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Zero Trust Network Access (ZTNA) solutions lack the ability to prioritize traffic within multiplexed streams and have a large attack surface that can be exploited by malicious users, while deploying deceptions at scale is difficult and resource-intensive.
Innovation Solution
Implementing a secure access gateway that utilizes authorization chains to prioritize individual channels within multiplexed streams and deploys deceptions at scale by using a deception service to emulate multiple hosts with a small number of deception devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ZTNA solutions use a single gateway to enforce access policies, then access control is simplified, but the attack surface increases and security is compromised
Solution Approach 1:
The patent divides the single gateway into multiple authorization nodes arranged in a chain topology. Each node enforces a specific authorization requirement, segmenting the monolithic gateway function into distributed, specialized components that collectively provide the same access control while reducing the attack surface through architectural distribution.
2Productivity
If ZTNA solutions multiplex multiple traffic types in a single connection, then network efficiency improves, but the ability to prioritize critical traffic is lost
Solution Approach 1:
The patent assigns different priority levels to different streams within the multiplexed connection based on their specific requirements. Critical streams (e.g., real-time traffic) are given higher priority while less critical streams (e.g., web traffic) receive lower priority, allowing differentiated quality of service within the unified multiplexed connection.
3Reliability
If deception nodes are deployed at scale to enhance network security, then security posture improves, but compute resource consumption increases excessively
Solution Approach 1:
The patent deploys deception hostnames that are virtual representations or copies of actual network hosts. These deception hostnames are advertised on the network to attract and dilute attack traffic, but they do not require full functional deception nodes for each hostname, significantly reducing the compute resources needed while maintaining the security benefits of deception at scale.
Data Source
AI summary
Techniques for using a secure access gateway to signal compute and/or network prioritization to individual streams within multiplexed sessions for zero-trust network access (ZTNA). A secure access gateway may be configured to identify weighting data and/or prioritization data associated with individual streams within the multiplexed session comprising various protocols (e.g., HTTP/2 and/or HTTP/3) and determine a gateway priority value. That is, the secure access gateway may be configured to prioritize certain types of traffic (user roles, resource types, etc.) over others, regardless of the protocol employed by the individual stream. The secure access gateway may then prioritize the processing (e.g., networking and/or computational resources) of a first stream having a more favorable gateway priority value than a second stream. Additionally, the secure access gateway may be configured to transmit indications of the gateway priority value to a target resource, such that the streams may be prioritized in the reverse direction.


