Zero-Trust Access Server for Internal Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN solutions are inadequate for secure access to internal applications in cloud environments, as they rely on perimeter security, are susceptible to attacks, and expose endpoints to security risks, lacking the 'zero trust' standards and scalability needed for mobile-cloud use.

Innovation Solution

A system and method for zero-trust access to internal applications using an enterprise mobility management (EMM) system, where a user device enrolls in EMM, and an access server acts as a proxy, allowing access to internal applications while hiding the internal application's address, using single packet authentication (SPA) and randomized access ports open briefly to mitigate detection and exploitation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN is used to provide access to internal applications, then access over the internet is enabled, but security controls are insufficient and endpoints are exposed to security risks

Engineering Contradiction:
Improveaccess to internal applicationsVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an access server as an intermediary component between the endpoint and internal applications. The access server receives access requests, authenticates users, and forwards requests to internal applications through randomized access ports. This intermediary architecture enables internet access to internal applications while maintaining security by preventing direct endpoint exposure and implementing zero-trust authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If perimeter security features like firewalls and VPN gateways are used, then access control is provided, but they rely on known managed devices and internal networks

Engineering Contradiction:
Improveaccess controlVSAvoidmobile-cloud use
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional perimeter security model by implementing zero-trust access control. Instead of trusting devices within the perimeter and blocking external access, the system authenticates every access request from any device anywhere. The access server verifies user identity and device compliance before granting access to internal applications, enabling secure mobile-cloud usage without relying on traditional perimeter boundaries.

Inventive Principle:
Principle #13The other way round (Inversion)

3Ease of operation

If VPN extends datacenter subnet to endpoint, then access to internal resources is enabled, but malware on endpoint can affect cloud network resources

Engineering Contradiction:
Improveaccess to internal resourcesVSAvoidmalware impact
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The access server acts as a security intermediary that prevents direct network connectivity between endpoints and internal applications. By using randomized access ports and authentication mechanisms, the system enables resource access while isolating the cloud network from endpoint malware. The intermediary architecture ensures that even if an endpoint is compromised, the malware cannot directly access or affect cloud network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If reverse proxy solution is implemented, then security features like multi-factor authentication are improved, but internal applications must be modified which is costly and not scalable

Engineering Contradiction:
Improvesecurity featuresVSAvoidapplication modification cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the security functionality from the internal applications by introducing a separate access server component. The access server handles authentication, authorization, and access control independently, while internal applications remain unchanged. This segmentation allows advanced security features like multi-factor authentication to be implemented without modifying internal applications, reducing costs and improving scalability.

Inventive Principle:
Principle #1Segmentation

5Ease of operation

If reverse proxy is used, then user experience is improved compared to VPN, but the solution is still susceptible to attacks at open ports in the proxy server

Engineering Contradiction:
Improveuser experienceVSAvoidattacks at open ports
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic port management where the access server opens randomized access ports temporarily for authenticated users and closes them afterward. Instead of maintaining permanently open ports that are vulnerable to attacks, the system dynamically creates and destroys ports based on authentication events. This dynamic approach maintains good user experience while significantly reducing the attack surface by minimizing the time ports are open.

Inventive Principle:
Principle #15Dynamics

6Ease of operation

If access port is opened for extended period, then access to internal application is maintained, but detection and exploitation by malicious processes increases

Engineering Contradiction:
Improveaccess continuityVSAvoiddetection and exploitation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic re-authentication and temporary port opening mechanisms. Instead of opening access ports for extended periods, the system opens ports briefly for each access request or authentication event, then closes them. This periodic action maintains access continuity for legitimate users while minimizing the window of opportunity for malicious processes to detect and exploit open ports.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11647003B2Concealing internal applications that are accessed over a network
Publication Date: 2023.05.09 OMNISSA LLC
  • US11647003B2 patent drawing
  • US11647003B2 patent drawing
  • US11647003B2 patent drawing

AI summary

Examples herein describe systems and methods for concealing internal applications that are accessed over the internet. A user device can select a remote internal application to access using a client. The user device can send an access request to an open listening port of an access server. The access server can be a gateway and proxy to the internal application, which can reside elsewhere. The access server can open a different randomized access port for establishing the connection by proxy to the internal application. The port number for the access port can be identified in the access request at the listening port. The access server can open the access port for a short time interval. The connection can be made through the access port during that time interval. A firewall can then close the access port but maintain an established connection between the user device and the internal application.