Zero Trust Policy Engine with Inline Inspection for Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network security models, which rely on a well-defined perimeter, are inadequate in the era of cloud-based applications and mobile users, leading to increased security risks due to unsecured devices and unmanaged access to the Internet.
Innovation Solution
Implementing a zero trust policy engine with a Zero Trust Architecture (ZTA) that monitors and controls access by verifying user and device identity and context, using enforcement nodes to enforce policies and manage risk through dynamic scoring, and providing inline inspection to prevent data compromise and intrusion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional perimeter-based network security models are used, then network access is simplified and users within the perimeter have easy access to resources, but security risks increase due to unsecured devices and unmanaged access to the Internet
Solution Approach 1:
The patent segments the network into multiple zones with different security levels, creating a hierarchical structure where users and devices are assigned to specific segments based on their trust level. This allows simplified access within segments while maintaining security boundaries between segments, resolving the contradiction between ease of access and security.
Solution Approach 2:
The system performs preliminary security assessments and device evaluations before granting network access. By pre-establishing security credentials, device profiles, and access policies, the system enables users to connect easily to appropriate segments without real-time security checks, while still maintaining strong security controls.
2Reliability
If zero trust policy engine with inline inspection is implemented, then security is enhanced by detecting threats and preventing data loss, but device complexity and system overhead increase
Solution Approach 1:
The patent introduces an intermediary security gateway that performs inline inspection and threat detection. This intermediary component handles the complex security processing, allowing the endpoint devices to remain relatively simple while still benefiting from enhanced security. The gateway acts as a mediator between users and network resources, performing deep packet inspection and threat analysis.
Solution Approach 2:
The system implements automated device profiling, credential verification, and policy enforcement mechanisms that operate autonomously without requiring manual intervention. The zero trust policy engine automatically assesses device trust levels, assigns appropriate security policies, and adjusts access rights dynamically, reducing the operational complexity despite the enhanced security capabilities.
3Measurement precision
If dynamic risk scoring and policy checks are enforced, then access control precision is improved and threats are detected, but processing time and user experience may be degraded
Solution Approach 1:
The system performs risk assessments and policy checks in advance during device onboarding and initial connection attempts. By pre-calculating risk scores and establishing baseline policies, the system reduces real-time processing requirements. Subsequent access requests can be handled more quickly by referencing pre-established policies and risk profiles, maintaining precision while reducing latency.
Solution Approach 2:
The zero trust policy engine dynamically adjusts the depth and intensity of policy checks based on the assessed risk level. For low-risk users and devices, the system applies simplified policies with faster processing. For high-risk scenarios, more comprehensive checks are performed. This dynamic approach maintains access control precision while optimizing processing time based on actual risk conditions.
Data Source
AI summary
Systems and methods are provided for controlling network access in a zero trust environment. A method, according to one implementation, includes the step of monitoring and controlling access between a user device and a network application using a zero trust policy engine having a Zero Trust Architecture (ZTA) in which no user, user device, or network application is inherently trusted. The method further includes the step of granting trust by allowing the user device to access the network application when identity and context information associated with a user of the user device is verified and when policy checks of the zero trust policy engine are enforced.


