Zero Trust Broker for Cloud Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise network security models are inadequate for the modern distributed workforce and cloud-based applications, as they rely on a well-defined perimeter that is no longer applicable, leading to increased security risks for data on unsecured and unmanaged devices accessing the internet.

Innovation Solution

A cloud-based system that provides zero-trust access to applications by intercepting client application information, identifying known applications, and using application IDs for policy enforcement, with dynamic application catalog updates and caching, ensuring only necessary information is sent over the network, thereby maintaining security without exposing applications to the internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional perimeter-based network security is used, then network access is simplified, but security risk increases due to unsecured devices accessing applications

Engineering Contradiction:
Improvenetwork accessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a broker as an intermediary component that sits between users and applications. This broker mediates all access requests, providing authentication, authorization, and monitoring capabilities. The broker enables secure access without requiring users to be within the traditional network perimeter, thus maintaining ease of remote access while significantly reducing security risks through centralized control and visibility of all access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If applications are made accessible to remote users, then user productivity improves, but the attack surface increases

Engineering Contradiction:
Improveuser productivityVSAvoidattack surface
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network architecture by separating applications from the traditional network perimeter. Instead of providing broad network access to remote users, the system creates individualized, application-specific access pathways through the broker. This segmentation limits the attack surface because even if one application is compromised, the broker's enforcement of least-privilege access prevents lateral movement to other applications or network resources.

Inventive Principle:
Principle #1Segmentation

3Reliability

If cloud-based security solutions are deployed, then security coverage extends to distributed devices, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions into a single cloud-based broker platform. Instead of deploying separate security appliances at each network perimeter or on individual devices, the broker consolidates authentication, authorization, application delivery, and monitoring capabilities into one unified system. This merging approach extends security coverage to all distributed devices while actually reducing overall system complexity by eliminating redundant security infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240422198A1Systems and methods for providing zero trust access to source applications
Publication Date: 2024.12.19 ZSCALER INC
  • US20240422198A1 patent drawing
  • US20240422198A1 patent drawing
  • US20240422198A1 patent drawing

AI summary

Systems and methods for providing zero trust access to source applications, implemented in a cloud-based system. The method includes steps of, intercepting client application information; identifying if the application is a known application based on an application catalog, and collecting known information of the application from the application catalog; sending the application information to an enforcement node of a cloud-based system in a first packet; and sending only an application Identification (ID) in subsequent packets, wherein the application ID is used for policy enforcement.