Zero Trust Policy Engine with Inline Inspection for Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security models, which rely on a well-defined perimeter, are inadequate in the era of cloud-based applications and mobile users, leading to increased security risks due to unsecured devices and unmanaged access to the Internet.

Innovation Solution

Implementing a zero trust policy engine with a Zero Trust Architecture (ZTA) that monitors and controls access by verifying user and device identity and context, using enforcement nodes to enforce policies and manage risk through dynamic scoring, and providing inline inspection to prevent data compromise and intrusion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional perimeter-based network security models are used, then network access is simplified and users within the perimeter have easy access to resources, but security risks increase due to unsecured devices and unmanaged access to the Internet

Engineering Contradiction:
Improvenetwork accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network into multiple zones with different security levels, creating a hierarchical structure where users and devices are assigned to specific segments based on their trust level. This allows simplified access within segments while maintaining security boundaries between segments, resolving the contradiction between ease of access and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security assessments and device evaluations before granting network access. By pre-establishing security credentials, device profiles, and access policies, the system enables users to connect easily to appropriate segments without real-time security checks, while still maintaining strong security controls.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If zero trust policy engine with inline inspection is implemented, then security is enhanced by detecting threats and preventing data loss, but device complexity and system overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary security gateway that performs inline inspection and threat detection. This intermediary component handles the complex security processing, allowing the endpoint devices to remain relatively simple while still benefiting from enhanced security. The gateway acts as a mediator between users and network resources, performing deep packet inspection and threat analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automated device profiling, credential verification, and policy enforcement mechanisms that operate autonomously without requiring manual intervention. The zero trust policy engine automatically assesses device trust levels, assigns appropriate security policies, and adjusts access rights dynamically, reducing the operational complexity despite the enhanced security capabilities.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If dynamic risk scoring and policy checks are enforced, then access control precision is improved and threats are detected, but processing time and user experience may be degraded

Engineering Contradiction:
Improveaccess control precisionVSAvoidaccess processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs risk assessments and policy checks in advance during device onboarding and initial connection attempts. By pre-calculating risk scores and establishing baseline policies, the system reduces real-time processing requirements. Subsequent access requests can be handled more quickly by referencing pre-established policies and risk profiles, maintaining precision while reducing latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The zero trust policy engine dynamically adjusts the depth and intensity of policy checks based on the assessed risk level. For low-risk users and devices, the system applies simplified policies with faster processing. For high-risk scenarios, more comprehensive checks are performed. This dynamic approach maintains access control precision while optimizing processing time based on actual risk conditions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12381916B2Zero trust policy engine for controlling access to network applications
Publication Date: 2025.08.05 ZSCALER INC
  • US12381916B2 patent drawing
  • US12381916B2 patent drawing
  • US12381916B2 patent drawing

AI summary

Systems and methods are provided for controlling network access in a zero trust environment. A method, according to one implementation, includes the step of monitoring and controlling access between a user device and a network application using a zero trust policy engine having a Zero Trust Architecture (ZTA) in which no user, user device, or network application is inherently trusted. The method further includes the step of granting trust by allowing the user device to access the network application when identity and context information associated with a user of the user device is verified and when policy checks of the zero trust policy engine are enforced.