Zero Trust Penetration Testing via Unique Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Penetration testing in zero trust network environments is complicated due to the distributed nature of microsegments and encrypted communications, making it difficult to identify vulnerabilities and enforce security controls across multiple microsegments.

Innovation Solution

A method using a test system that generates unique tokens for penetration test packets, which are transmitted through policy enforcement points to determine if unauthorized access occurs, and logs the results to identify vulnerabilities and recommend corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If penetration testing is performed manually in traditional network environments, then security control coverage can be validated, but the process is time-consuming and difficult to scale to zero trust environments with multiple microsegments

Engineering Contradiction:
Improvesecurity control coverage validationVSAvoidpenetration testing duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent uses test packets as automated copies of attack patterns to simulate penetration scenarios. These standardized test packets can be replicated and sent across multiple microsegments simultaneously, replacing manual penetration testing while maintaining validation accuracy and reducing time consumption.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes the parameters of penetration testing by introducing automated test packets with varying characteristics (source microsegment, target microsegment, communication protocols) to test different security control scenarios across the zero trust network architecture.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the network is partitioned into multiple microsegments with encrypted communications, then security is enhanced, but it becomes difficult to identify vulnerabilities and track unauthorized access paths

Engineering Contradiction:
Improvesecurity control enforcementVSAvoidvulnerability identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces policy enforcement points as intermediaries between microsegments. These PEPs receive, process, and log test packets while enforcing security policies, making them detectable even in encrypted communications. The PEPs serve as observable nodes that track unauthorized access paths without compromising the encrypted communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system makes invisible test packets detectable by injecting unique identifiers and markers into the encrypted test packets. These markers allow the system to track and identify test packets as they traverse through the encrypted microsegment boundaries, enabling vulnerability detection without decrypting communications.

Inventive Principle:
Principle #32Color changes

3Productivity

If automated test packets are sent across microsegments, then penetration testing efficiency improves, but false positives may occur without proper tracking mechanisms

Engineering Contradiction:
Improvepenetration testing efficiencyVSAvoidvulnerability detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements a feedback mechanism where policy enforcement points log and report back on the handling of test packets. This feedback loop provides confirmation of whether test packets were properly blocked or incorrectly allowed through, enabling accurate vulnerability identification and reducing false positives by verifying actual security control behavior.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250023903A1Penetration Testing in Zero Trust Network Environment
Publication Date: 2025.01.16 T MOBILE INNOVATIONS LLC
  • US20250023903A1 patent drawing
  • US20250023903A1 patent drawing
  • US20250023903A1 patent drawing

AI summary

A method comprises generating, by a test application in a test system of the zero trust network, a test packet comprising a unique token identifying the penetration test based on a test log, wherein the test log indicates that the penetration test is to be performed on a communication between a source microsegment and a target microsegment, transmitting, by the test application, the test packet to a policy enforcement point in the target microsegment, wherein a result log stores data, in association with the unique token, regarding at least one of a reception or processing of the test packet by the policy enforcement point, and comparing, by a log application in the test system, the test log and the result log to determine that the test packet has impermissibly passed through the policy enforcement point or been processed by the policy enforcement point.