Zero Trust Control Layer for Destination Service Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing networking technologies lack effective mechanisms to enforce zero trust controls on requests to destination services, leaving them vulnerable to attacks from the open internet.

Innovation Solution

A cloud-based system that directs and enforces zero trust controls by becoming the authoritative name server for destination services, using a control layer to manage requests based on preconfigured policies, and providing access through a private access system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If destination services are made available in a shared network or over the open internet, then accessibility to the service is improved, but security and vulnerability to attacks worsen

Engineering Contradiction:
ImproveaccessibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a control layer as an intermediary between users and destination services. This control layer acts as a mediator that intercepts, authenticates, and authorizes all requests before they reach the destination service, thereby enabling accessibility while preventing direct exposure to attacks. The control layer includes authentication modules, authorization engines, and request routing components that facilitate secure access without compromising service availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If zero trust control is enforced on all requests, then security is improved, but system complexity worsens

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the zero trust control system into distinct functional modules including authentication modules, authorization engines, request routing components, and policy enforcement points. This segmentation allows each component to handle specific security tasks independently, making the overall complex zero trust architecture more manageable and implementable while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control layer is designed as a universal platform that handles multiple functions including authentication, authorization, request routing, and policy enforcement through a single integrated system. This multi-functionality reduces the need for separate security systems and simplifies deployment, thereby managing complexity while providing comprehensive zero trust protection across diverse services and protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If destination services are completely isolated from the internet, then security is improved, but accessibility and connectivity worsen

Engineering Contradiction:
Improveprotection from internet risksVSAvoidaccessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The control layer serves as a secure intermediary that enables isolated destination services to maintain connectivity with users. It intercepts requests, performs authentication and authorization, and routes only validated requests to the isolated services. This mediator approach allows services to remain isolated from direct internet exposure while still providing accessible functionality to authenticated users through the control layer's secure channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250158989A1Systems and methods for directing and enforcing zero trust control on requests to destination services
Publication Date: 2025.05.15 ZSCALER INC
  • US20250158989A1 patent drawing
  • US20250158989A1 patent drawing
  • US20250158989A1 patent drawing

AI summary

Systems and methods for directing and enforcing zero trust control on requests to destination services. In various embodiments, steps include receiving a request from a user to access a destination service; directing the request to a control layer; enforcing one or more controls, via the control layer, on the request based on a configuration provided by an owner of the destination service; and providing access to the destination service to the user based on the one or more controls.