Zero Trust Network Testing via Intermediary Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a zero trust network environment, test equipment and probes face challenges in accessing encrypted communications, hindering troubleshooting and testing activities due to their positioning outside the secure tunnels.

Innovation Solution

The implementation of a method and system that places probes within each microsegment of a zero trust network, allowing them to collect unencrypted data and establish independent secure tunnels with test equipment, enabling fine-grained access control and secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If test equipment is positioned outside secure tunnels in a zero trust network, then network security is maintained through encrypted communications, but troubleshooting and testing activities are hindered due to inability to access communications

Engineering Contradiction:
Improvenetwork securityVSAvoidtroubleshooting and testing capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces probes as intermediary devices positioned within microsegments that can access both encrypted communications and test equipment. These probes act as mediators by receiving test commands from external test equipment, executing them within the secure microsegment, and returning results without compromising the encrypted tunnel architecture. This resolves the contradiction by providing testing capability while maintaining security through the intermediary probe layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If probes are placed within microsegments to enable testing, then troubleshooting capability is improved, but network complexity increases due to additional components and tunnel establishment

Engineering Contradiction:
Improvetroubleshooting capabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The probes are designed as multi-functional devices that can execute various testing activities, collect different types of data, and communicate with multiple microsegments. They serve universal purposes including command reception, data collection, analysis, and result transmission. This reduces overall network complexity by consolidating multiple testing functions into single versatile probe units rather than requiring separate specialized devices for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure tunnels are established between test equipment and probes, then data transmission security is improved, but communication overhead and establishment time increase

Engineering Contradiction:
Improvedata transmission securityVSAvoidtunnel establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes secure tunnels between test equipment and probes in advance before actual testing operations begin. By performing the tunnel establishment action preliminarily, the system avoids repeated authentication and encryption setup during active testing, thereby reducing time loss during operational phases while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12341817B2Testing network communication within a zero trust security model
Publication Date: 2025.06.24 T MOBILE INNOVATIONS LLC
  • US12341817B2 patent drawing
  • US12341817B2 patent drawing
  • US12341817B2 patent drawing

AI summary

A method of testing a communication system implementing a zero trust architecture. The method comprises sending a request by a test equipment platform to access a microsegment to a policy enforcement point (PEP); sending an authorization request by the PEP to a policy decision point (PDP); authorizing access of the test equipment platform to the microsegment by the PDP; sending authorization of access of the test equipment platform to the microsegment by the PDP to the PEP; establishing a secure tunnel by the PEP between the test equipment platform and the microsegment; sending a command to provide test data by the test equipment platform via the secure tunnel to a probe in the microsegment; analyzing the test data by the test equipment platform; and producing a test result by the test equipment platform based on analyzing the test data.