Zero Trust Lensing for Inline Cloud Traffic Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The traditional enterprise network model, with a well-defined perimeter, is no longer effective as applications move to the cloud, leading to increased security risks due to unsecured and unmanaged devices accessing the Internet, necessitating a new approach to secure access and data protection.
Innovation Solution
Implementing a cloud-based system that intercepts and filters client-initiated traffic through a zero trust lensing mechanism, using a repository of lenses to process sessions in-line without the user or destination being aware, providing adaptive access control and threat prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional enterprise network perimeter model is used, then users within the perimeter have secure access to resources, but mobile users and cloud applications face increased security risks due to unsecured devices and extended Internet exposure
Solution Approach 1:
The patent segments the network perimeter into multiple virtual perimeters using VRFs (Virtual Routing and Forwarding instances). Each VRF instance creates an isolated routing domain that can be assigned to specific applications or users, allowing secure segmentation of traffic while maintaining flexible access. This resolves the contradiction by providing both security through isolation and adaptability through customizable VRF assignments.
Solution Approach 2:
The patent introduces a cloud-based gateway as an intermediary between users and enterprise resources. This gateway enforces security policies, performs authentication, and manages VRF routing without requiring users to be physically within the traditional network perimeter. This intermediary enables secure remote access while maintaining the security boundaries of the original network, resolving the contradiction between security and access flexibility.
2Ease of operation
If applications are exposed to the Internet for cloud access, then user accessibility improves, but the attack surface increases and security risks are amplified
Solution Approach 1:
The patent extracts the security enforcement function from the traditional network perimeter and relocates it to a cloud-based gateway. This allows applications to remain accessible via the Internet while the gateway extracts and enforces security policies separately, preventing direct exposure of applications to Internet threats. The attack surface is reduced by removing unnecessary exposure while maintaining accessibility.
Solution Approach 2:
The patent applies different security policies and VRF configurations to different applications based on their specific requirements. Each application can have customized security rules, authentication methods, and routing configurations tailored to its needs. This local quality approach allows maximum accessibility for each application while applying appropriate security measures specific to that application's risk profile.
3Reliability
If VPN is used for remote access, then secure connectivity is maintained, but network complexity and configuration overhead increase
Solution Approach 1:
The patent implements a universal cloud-based gateway that handles multiple functions: authentication, VRF routing, policy enforcement, and secure connectivity management. This single gateway replaces the need for complex VPN configurations on individual devices and networks, providing secure connectivity through a unified platform. The gateway's multi-functionality reduces overall network complexity while maintaining security.
Data Source
AI summary
Systems and methods for zero trust lensing of cloud-based traffic. Various embodiments include intercepting a plurality of requests from one or more users in a cloud-based system, wherein the requests are for connectivity to one or more destination workloads; determining a request of the plurality of requests requires lensing; identifying an appropriate lens for rendering the request; and initiating and utilizing a lens workload for processing a session associated with the request, wherein the session is processed in-line between the user and the workload destination without the user nor the workload destination being aware of the lens.


