Secure Access Gateway Stream Prioritization for ZTNA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Zero Trust Network Access (ZTNA) solutions lack the ability to prioritize traffic within multiplexed streams and have a large attack surface that can be exploited by malicious users, while deploying deceptions at scale is difficult and resource-intensive.

Innovation Solution

Implementing a secure access gateway that utilizes authorization chains to prioritize individual channels within multiplexed streams and deploys deceptions at scale by using a deception service to emulate multiple hosts with a small number of deception devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ZTNA solutions use a single gateway to enforce access policies, then access control is simplified, but the attack surface increases and security is compromised

Engineering Contradiction:
Improveaccess control enforcementVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the single gateway into multiple authorization nodes arranged in a chain topology. Each node enforces a specific authorization requirement, segmenting the monolithic gateway function into distributed, specialized components that collectively provide the same access control while reducing the attack surface through architectural distribution.

Inventive Principle:
Principle #1Segmentation

2Productivity

If ZTNA solutions multiplex multiple traffic types in a single connection, then network efficiency improves, but the ability to prioritize critical traffic is lost

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidtraffic prioritization capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent assigns different priority levels to different streams within the multiplexed connection based on their specific requirements. Critical streams (e.g., real-time traffic) are given higher priority while less critical streams (e.g., web traffic) receive lower priority, allowing differentiated quality of service within the unified multiplexed connection.

Inventive Principle:
Principle #3Local quality

3Reliability

If deception nodes are deployed at scale to enhance network security, then security posture improves, but compute resource consumption increases excessively

Engineering Contradiction:
Improvenetwork securityVSAvoidcompute resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent deploys deception hostnames that are virtual representations or copies of actual network hosts. These deception hostnames are advertised on the network to attract and dilute attack traffic, but they do not require full functional deception nodes for each hostname, significantly reducing the compute resources needed while maintaining the security benefits of deception at scale.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12418578B2Prioritization of individual channels within multiplexed streams for zero trust network access (ZTNA)
Publication Date: 2025.09.16 CISCO TECHNOLOGY INC
  • US12418578B2 patent drawing
  • US12418578B2 patent drawing
  • US12418578B2 patent drawing

AI summary

Techniques for using a secure access gateway to signal compute and/or network prioritization to individual streams within multiplexed sessions for zero-trust network access (ZTNA). A secure access gateway may be configured to identify weighting data and/or prioritization data associated with individual streams within the multiplexed session comprising various protocols (e.g., HTTP/2 and/or HTTP/3) and determine a gateway priority value. That is, the secure access gateway may be configured to prioritize certain types of traffic (user roles, resource types, etc.) over others, regardless of the protocol employed by the individual stream. The secure access gateway may then prioritize the processing (e.g., networking and/or computational resources) of a first stream having a more favorable gateway priority value than a second stream. Additionally, the secure access gateway may be configured to transmit indications of the gateway priority value to a target resource, such that the streams may be prioritized in the reverse direction.