Zero Trust Network Branch with Cloud Security Edge
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional perimeter security models for branch offices are inefficient and complex, leading to latency and inadequate control over local network traffic, which falls outside the scope of Secure Service Edge (SSE) solutions.
Innovation Solution
A zero-trust (ZT) network branch approach utilizing a minimally featured edge switch on-premises, with all additional security services hosted in the cloud, eliminating the need for on-prem firewalls and complex Ethernet switches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional perimeter security models with on-prem firewalls and complex Ethernet switches are used, then local network traffic can be managed, but device complexity and operational complexity increase significantly
Solution Approach 1:
The patent extracts security services from on-premises equipment and relocates them to cloud-based services. Specifically, firewall services, intrusion prevention, and other security functions are moved from physical appliances to virtualized cloud services, leaving only a minimal edge switch on-premises. This extraction reduces device complexity while maintaining security functionality through cloud-delivered services.
Solution Approach 2:
The patent implements a universal cloud-based security service platform that provides multiple security functions (firewall, intrusion prevention, threat intelligence) through a single cloud service infrastructure. This multi-functional cloud platform replaces multiple specialized on-premises appliances, reducing overall system complexity while providing comprehensive security coverage.
2Reliability
If all network traffic is routed through centralized data centers for inspection, then security inspection is performed, but latency increases and routing efficiency decreases
Solution Approach 1:
The patent implements local quality by deploying security services closer to the network edge through cloud-based security edge appliances. Instead of routing all traffic through centralized data centers, security inspection is performed at distributed edge locations, reducing the distance traffic must travel and thereby minimizing latency while maintaining comprehensive security inspection.
Solution Approach 2:
The patent segments the network architecture into multiple distributed edge locations that independently perform security inspection. Rather than a single centralized inspection point, multiple edge security services handle traffic locally, dividing the inspection workload and reducing congestion at any single point, thereby improving overall routing efficiency and reducing latency.
3Reliability
If on-prem firewalls and security appliances are deployed, then security control is provided, but operational complexity and IT management burden increase
Solution Approach 1:
The patent implements self-service by providing automated cloud-based security services that manage their own operations, updates, and configuration. The cloud platform automatically handles threat intelligence updates, service provisioning, and system maintenance, eliminating the need for manual IT intervention. This self-managing approach maintains robust security control while dramatically reducing operational complexity and IT management burden.
Solution Approach 2:
The patent incorporates continuous feedback loops where cloud-based security services automatically monitor network traffic, analyze threats, and adjust security policies in real-time. This automated feedback mechanism enables the system to adapt to emerging threats without manual intervention, maintaining high security control while reducing operational complexity through intelligent automation.
Data Source
AI summary
Systems and methods for a zero trust (ZT) network branch, which includes an edge switch on premises (on prem) with other services being offered in the cloud, include plurality of endpoints on the branch network each of which is configured in a network of one; and route east-west and north-south traffic flows associated with the plurality of endpoints through a cloud for security processing thereon. The security processing is based on one or more security applications selectively configured for the east-west and north-south traffic flows.


