Zero Trust Network Branch with Cloud Security Edge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional perimeter security models for branch offices are inefficient and complex, leading to latency and inadequate control over local network traffic, which falls outside the scope of Secure Service Edge (SSE) solutions.

Innovation Solution

A zero-trust (ZT) network branch approach utilizing a minimally featured edge switch on-premises, with all additional security services hosted in the cloud, eliminating the need for on-prem firewalls and complex Ethernet switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional perimeter security models with on-prem firewalls and complex Ethernet switches are used, then local network traffic can be managed, but device complexity and operational complexity increase significantly

Engineering Contradiction:
Improvenetwork security managementVSAvoidon-prem equipment
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts security services from on-premises equipment and relocates them to cloud-based services. Specifically, firewall services, intrusion prevention, and other security functions are moved from physical appliances to virtualized cloud services, leaving only a minimal edge switch on-premises. This extraction reduces device complexity while maintaining security functionality through cloud-delivered services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a universal cloud-based security service platform that provides multiple security functions (firewall, intrusion prevention, threat intelligence) through a single cloud service infrastructure. This multi-functional cloud platform replaces multiple specialized on-premises appliances, reducing overall system complexity while providing comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If all network traffic is routed through centralized data centers for inspection, then security inspection is performed, but latency increases and routing efficiency decreases

Engineering Contradiction:
Improvesecurity inspectionVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements local quality by deploying security services closer to the network edge through cloud-based security edge appliances. Instead of routing all traffic through centralized data centers, security inspection is performed at distributed edge locations, reducing the distance traffic must travel and thereby minimizing latency while maintaining comprehensive security inspection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the network architecture into multiple distributed edge locations that independently perform security inspection. Rather than a single centralized inspection point, multiple edge security services handle traffic locally, dividing the inspection workload and reducing congestion at any single point, thereby improving overall routing efficiency and reducing latency.

Inventive Principle:
Principle #1Segmentation

3Reliability

If on-prem firewalls and security appliances are deployed, then security control is provided, but operational complexity and IT management burden increase

Engineering Contradiction:
Improvesecurity controlVSAvoidIT management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by providing automated cloud-based security services that manage their own operations, updates, and configuration. The cloud platform automatically handles threat intelligence updates, service provisioning, and system maintenance, eliminating the need for manual IT intervention. This self-managing approach maintains robust security control while dramatically reducing operational complexity and IT management burden.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates continuous feedback loops where cloud-based security services automatically monitor network traffic, analyze threats, and adjust security policies in real-time. This automated feedback mechanism enables the system to adapt to emerging threats without manual intervention, maintaining high security control while reducing operational complexity through intelligent automation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250071143A1Zero Trust Network Branch
Publication Date: 2025.02.27 ZSCALER INC
  • US20250071143A1 patent drawing
  • US20250071143A1 patent drawing
  • US20250071143A1 patent drawing

AI summary

Systems and methods for a zero trust (ZT) network branch, which includes an edge switch on premises (on prem) with other services being offered in the cloud, include plurality of endpoints on the branch network each of which is configured in a network of one; and route east-west and north-south traffic flows associated with the plurality of endpoints through a cloud for security processing thereon. The security processing is based on one or more security applications selectively configured for the east-west and north-south traffic flows.