Zero-Trust Access Server for Internal Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN solutions are inadequate for secure access to internal applications in cloud environments, as they rely on perimeter security, are susceptible to attacks, and expose endpoints to security risks, lacking the 'zero trust' standards and scalability needed for mobile-cloud use.
Innovation Solution
A system and method for zero-trust access to internal applications using an enterprise mobility management (EMM) system, where a user device enrolls in EMM, and an access server acts as a proxy, allowing access to internal applications while hiding the internal application's address, using single packet authentication (SPA) and randomized access ports open briefly to mitigate detection and exploitation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN is used to provide access to internal applications, then access over the internet is enabled, but security controls are insufficient and endpoints are exposed to security risks
Solution Approach 1:
The patent introduces an access server as an intermediary component between the endpoint and internal applications. The access server receives access requests, authenticates users, and forwards requests to internal applications through randomized access ports. This intermediary architecture enables internet access to internal applications while maintaining security by preventing direct endpoint exposure and implementing zero-trust authentication mechanisms.
2Reliability
If perimeter security features like firewalls and VPN gateways are used, then access control is provided, but they rely on known managed devices and internal networks
Solution Approach 1:
The patent inverts the traditional perimeter security model by implementing zero-trust access control. Instead of trusting devices within the perimeter and blocking external access, the system authenticates every access request from any device anywhere. The access server verifies user identity and device compliance before granting access to internal applications, enabling secure mobile-cloud usage without relying on traditional perimeter boundaries.
3Ease of operation
If VPN extends datacenter subnet to endpoint, then access to internal resources is enabled, but malware on endpoint can affect cloud network resources
Solution Approach 1:
The access server acts as a security intermediary that prevents direct network connectivity between endpoints and internal applications. By using randomized access ports and authentication mechanisms, the system enables resource access while isolating the cloud network from endpoint malware. The intermediary architecture ensures that even if an endpoint is compromised, the malware cannot directly access or affect cloud network resources.
4Reliability
If reverse proxy solution is implemented, then security features like multi-factor authentication are improved, but internal applications must be modified which is costly and not scalable
Solution Approach 1:
The patent segments the security functionality from the internal applications by introducing a separate access server component. The access server handles authentication, authorization, and access control independently, while internal applications remain unchanged. This segmentation allows advanced security features like multi-factor authentication to be implemented without modifying internal applications, reducing costs and improving scalability.
5Ease of operation
If reverse proxy is used, then user experience is improved compared to VPN, but the solution is still susceptible to attacks at open ports in the proxy server
Solution Approach 1:
The patent implements dynamic port management where the access server opens randomized access ports temporarily for authenticated users and closes them afterward. Instead of maintaining permanently open ports that are vulnerable to attacks, the system dynamically creates and destroys ports based on authentication events. This dynamic approach maintains good user experience while significantly reducing the attack surface by minimizing the time ports are open.
6Ease of operation
If access port is opened for extended period, then access to internal application is maintained, but detection and exploitation by malicious processes increases
Solution Approach 1:
The patent implements periodic re-authentication and temporary port opening mechanisms. Instead of opening access ports for extended periods, the system opens ports briefly for each access request or authentication event, then closes them. This periodic action maintains access continuity for legitimate users while minimizing the window of opportunity for malicious processes to detect and exploit open ports.
Data Source
AI summary
Examples herein describe systems and methods for concealing internal applications that are accessed over the internet. A user device can select a remote internal application to access using a client. The user device can send an access request to an open listening port of an access server. The access server can be a gateway and proxy to the internal application, which can reside elsewhere. The access server can open a different randomized access port for establishing the connection by proxy to the internal application. The port number for the access port can be identified in the access request at the listening port. The access server can open the access port for a short time interval. The connection can be made through the access port during that time interval. A firewall can then close the access port but maintain an established connection between the user device and the internal application.


