Zero Trust Access Architecture With Context-Based Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise network security models, which rely on a well-defined perimeter, are inadequate in the era of cloud-based applications and mobile users, leading to increased security risks due to unsecured devices and unmanaged access to the Internet.

Innovation Solution

Implementing a zero trust system architecture that initially blocks access attempts, verifies entity identity and context, and enforces policies to grant trust only when specific criteria are met, using a cloud-based system with inline monitoring and granular context-based policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a well-defined network perimeter is used with traditional security appliances, then network security is maintained for users within the perimeter, but security risks increase when users access resources outside the perimeter or when applications move to the cloud

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network perimeter concept into multiple virtual perimeters using VRFs (Virtual Routing and Forwarding) and VLANs (Virtual Local Area Networks). Each VRF instance creates an isolated routing table and network segment, allowing multiple logical networks to coexist on physical infrastructure. This enables secure segmentation of cloud-based applications and mobile user access while maintaining traditional perimeter security for on-premises resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a VRF gateway as an intermediary device that sits between mobile users accessing cloud applications and the enterprise network. The gateway performs authentication, authorization, and traffic routing functions, mediating access requests and enforcing security policies. This intermediary approach allows flexible cloud access while maintaining security boundaries through the gateway's control plane.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If mobile users are allowed to access cloud applications directly, then access flexibility is improved, but security risks increase due to unsecured and unmanaged devices

Engineering Contradiction:
Improvemobile access capabilityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and device registration actions before allowing mobile users to access cloud applications. The VRF gateway performs pre-authentication checks, device compliance verification, and security policy enforcement before establishing connections. This preliminary action ensures that only authorized devices with proper security configurations can access the network, reducing security risks while maintaining mobile access flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different security policies and access controls to different mobile devices based on their specific characteristics, security posture, and user roles. Each device receives customized security treatment through the VRF gateway, which can enforce device-specific authentication methods, application allowlists, and data protection policies. This local quality approach allows secure access for compliant devices while blocking or restricting non-compliant devices.

Inventive Principle:
Principle #3Local quality

3Area of stationary object

If cloud-based security solutions are implemented, then security coverage is extended to cloud applications, but the traditional perimeter defense model becomes inadequate

Engineering Contradiction:
Improvesecurity coverage areaVSAvoidsecurity architecture complexity
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent creates a universal security architecture where the VRF gateway performs multiple security functions including authentication, authorization, encryption, traffic routing, and policy enforcement across both on-premises and cloud environments. This multi-functional gateway consolidates security operations into a single platform that can protect traditional network resources and cloud-based applications uniformly, reducing the need for separate security solutions and simplifying the overall architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements nested virtualization where VRFs are nested within the gateway's control plane, which itself is nested within the broader cloud infrastructure. Multiple VRF instances can be nested to create hierarchical network segments, with each layer providing additional security and isolation. This nesting approach allows complex multi-tenant cloud environments to be secured through layered virtual perimeters managed by a single gateway instance.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12609939B2Zero trust system architecture
Publication Date: 2026.04.21 ZSCALER INC
  • US12609939B2 patent drawing
  • US12609939B2 patent drawing
  • US12609939B2 patent drawing

AI summary

Systems and methods for a zero trust architecture are provided. A method, according to one implementation, includes detecting an initial attempt by an entity to connect, access, or communicate with a network resource and blocking the entity from initially connecting, accessing, or communicating with the network resource. The method also includes performing a verification procedure to verify one or more of an identity of the entity and a context of the initial attempt. The method also performs a control procedure to control one or more of malicious content and sensitive data. In addition, the method includes performing an enforcement procedure in response to results of the verification procedure and control procedure to determine how to handle the initial attempt.