Zero Trust Network Access Control via Distributed Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing zero trust network access systems rely heavily on centralized control, making them difficult to scale for larger network implementations, and there is a need for more advanced approaches to provide scalable network access processing.

Innovation Solution

The implementation of a system that uses endpoint agents, endpoint management systems, and access nodes to perform scalable zero trust network access control, integrating UTM, threat, and malware scans, and generating device records based on security postures to manage network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized control is used for zero trust network access processing, then security control is improved, but scalability deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the centralized zero trust processing system into distributed components: endpoint agents on individual devices, local policy enforcement points in the network, and a decentralized policy management architecture. This segmentation allows security policies to be enforced locally while maintaining centralized coordination, resolving the contradiction between centralized security control and scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as policy decision points and policy enforcement points that act as mediators between the centralized policy management system and endpoint devices. These intermediaries enable distributed policy enforcement while maintaining the benefits of centralized policy definition, thus improving scalability without compromising security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device characteristics and user characteristics are both considered for network access determination, then security is improved, but processing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-evaluating device characteristics and user characteristics before network access requests are processed. Device posture assessment, user authentication, and policy matching are performed in advance, creating pre-computed security contexts that simplify real-time access decisions and reduce processing complexity during actual network operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies parameter changes by dynamically adjusting the weight and relevance of different device and user characteristics based on context. The system can modify which characteristics are most important for access decisions depending on the network resource being accessed, the user role, and the device state, thereby improving security without requiring complex processing of all possible characteristics in every scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240333772A1Systems and methods for secure, scalable zero trust security processing
Publication Date: 2024.10.03 FORTINET INC
  • US20240333772A1 patent drawing
  • US20240333772A1 patent drawing
  • US20240333772A1 patent drawing

AI summary

Various approaches for providing scalable network access processing. In some cases, approaches discussed relate to systems and methods for providing scalable zero trust network access control.