Zero Trust Access Architecture With Context-Based Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional enterprise network security models, which rely on a well-defined perimeter, are inadequate in the era of cloud-based applications and mobile users, leading to increased security risks due to unsecured devices and unmanaged access to the Internet.
Innovation Solution
Implementing a zero trust system architecture that initially blocks access attempts, verifies entity identity and context, and enforces policies to grant trust only when specific criteria are met, using a cloud-based system with inline monitoring and granular context-based policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a well-defined network perimeter is used with traditional security appliances, then network security is maintained for users within the perimeter, but security risks increase when users access resources outside the perimeter or when applications move to the cloud
Solution Approach 1:
The patent segments the network perimeter concept into multiple virtual perimeters using VRFs (Virtual Routing and Forwarding) and VLANs (Virtual Local Area Networks). Each VRF instance creates an isolated routing table and network segment, allowing multiple logical networks to coexist on physical infrastructure. This enables secure segmentation of cloud-based applications and mobile user access while maintaining traditional perimeter security for on-premises resources.
Solution Approach 2:
The patent introduces a VRF gateway as an intermediary device that sits between mobile users accessing cloud applications and the enterprise network. The gateway performs authentication, authorization, and traffic routing functions, mediating access requests and enforcing security policies. This intermediary approach allows flexible cloud access while maintaining security boundaries through the gateway's control plane.
2Adaptability or versatility
If mobile users are allowed to access cloud applications directly, then access flexibility is improved, but security risks increase due to unsecured and unmanaged devices
Solution Approach 1:
The patent implements preliminary authentication and device registration actions before allowing mobile users to access cloud applications. The VRF gateway performs pre-authentication checks, device compliance verification, and security policy enforcement before establishing connections. This preliminary action ensures that only authorized devices with proper security configurations can access the network, reducing security risks while maintaining mobile access flexibility.
Solution Approach 2:
The patent applies different security policies and access controls to different mobile devices based on their specific characteristics, security posture, and user roles. Each device receives customized security treatment through the VRF gateway, which can enforce device-specific authentication methods, application allowlists, and data protection policies. This local quality approach allows secure access for compliant devices while blocking or restricting non-compliant devices.
3Area of stationary object
If cloud-based security solutions are implemented, then security coverage is extended to cloud applications, but the traditional perimeter defense model becomes inadequate
Solution Approach 1:
The patent creates a universal security architecture where the VRF gateway performs multiple security functions including authentication, authorization, encryption, traffic routing, and policy enforcement across both on-premises and cloud environments. This multi-functional gateway consolidates security operations into a single platform that can protect traditional network resources and cloud-based applications uniformly, reducing the need for separate security solutions and simplifying the overall architecture.
Solution Approach 2:
The patent implements nested virtualization where VRFs are nested within the gateway's control plane, which itself is nested within the broader cloud infrastructure. Multiple VRF instances can be nested to create hierarchical network segments, with each layer providing additional security and isolation. This nesting approach allows complex multi-tenant cloud environments to be secured through layered virtual perimeters managed by a single gateway instance.
Data Source
AI summary
Systems and methods for a zero trust architecture are provided. A method, according to one implementation, includes detecting an initial attempt by an entity to connect, access, or communicate with a network resource and blocking the entity from initially connecting, accessing, or communicating with the network resource. The method also includes performing a verification procedure to verify one or more of an identity of the entity and a context of the initial attempt. The method also performs a control procedure to control one or more of malicious content and sensitive data. In addition, the method includes performing an enforcement procedure in response to results of the verification procedure and control procedure to determine how to handle the initial attempt.


