Virtualized ZTNA Proxy Segmentation for Multi-Region Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Zero Trust Network Access (ZTNA) security solutions are ineffective in virtual environments as they require a proxy near the resource, limiting the ability to distribute resources across multiple geographic regions.
Innovation Solution
Implementing a ZTNA proxy server that performs ZTNA processing and virtual access redirection, using virtual routing and forwarding (VRF) to dynamically route sessions across multiple networks, allowing access to virtual resources without overburdening any single network server and maintaining security through continuous user vetting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a ZTNA proxy is disposed near the resource to be accessed, then security is enhanced, but the ability to distribute resources across multiple geographic regions is limited
Solution Approach 1:
The patent segments the ZTNA proxy functionality into multiple distributed proxy servers located in different geographic regions. Each proxy server handles ZTNA enforcement for resources in its local region, eliminating the need for a single centralized proxy while maintaining security. This allows resources to be distributed across multiple geographic regions while preserving ZTNA security enforcement.
Solution Approach 2:
The patent introduces a control plane as an intermediary that coordinates between multiple data plane proxy servers and the central management system. The control plane distributes policy decisions and resource information to appropriate proxies, enabling centralized security management while allowing distributed resource access. This mediator architecture resolves the conflict between centralized security control and distributed resource placement.
2Reliability
If multiple network servers are used to distribute resources, then resource availability and resilience are improved, but users would need to maintain multiple access credentials
Solution Approach 1:
The patent implements a universal credential system where a single set of user credentials can be used to access multiple distributed resources across different geographic regions. The control plane manages credential validation and policy enforcement centrally, allowing users to access any authorized resource without maintaining separate credentials for each server or location. This multi-functional credential system resolves the conflict between distributed resource access and credential management complexity.
3Ease of operation
If a single network server handles all access requests, then credential management is simplified, but the server becomes overburdened and less resilient
Solution Approach 1:
The patent segments the processing load by separating control plane functions (credential validation, policy management) from data plane functions (actual resource access, traffic forwarding). Multiple proxy servers in the data plane can simultaneously handle user requests, distributing the load while the control plane maintains centralized credential management. This segmentation allows simplified credential management to be maintained while improving server resilience through load distribution.
Data Source
AI summary
Systems, devices, and methods are discussed for providing virtualized ZTNA control across multiple networks.


