Zero Trust Network Proxy for Granular Asset Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN systems lack granular access control, allowing malicious actors to access unauthorized assets and fail to monitor user activities in real-time, relying on dedicated client installations and inadequate authentication methods.

Innovation Solution

A zero trust network system that implements a security policy where users are authenticated at every access step, using a private cloud server with a ZTN proxy server and agent to provide role-based or attribute-based access control, creating secure encrypted channels for single-asset access without a dedicated client, and enabling session recording and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional VPN is used to provide network access, then users can access all assets on the private network, but this allows malicious actors to access unauthorized assets and eliminates granular access control

Engineering Contradiction:
Improveuser access to network resourcesVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network access by creating separate virtual network interfaces (vNICs) for different asset classes. Each vNIC is associated with specific access control policies, allowing granular control over which users can access which assets. This divides the monolithic VPN access model into segmented, policy-based access channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements local quality by assigning different access privileges to different virtual network interfaces. Each vNIC has its own access control list (ACL) that defines specific permissions for particular asset types, rather than providing uniform access to all assets. This allows fine-grained differentiation of access rights based on user role and asset sensitivity.

Inventive Principle:
Principle #3Local quality

2Productivity

If VPN authentication is performed once at login, then users can access assets, but there is no real-time monitoring of user activities during sessions

Engineering Contradiction:
Improveuser access efficiencyVSAvoiduser activity monitoring
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements continuous feedback by monitoring all network traffic passing through the virtual network interface. The monitoring component tracks user actions, resource access patterns, and session characteristics in real-time. This feedback mechanism enables detection of unauthorized activities and provides data for dynamic access control decisions during sessions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes continuous authentication and monitoring throughout the entire user session rather than performing authentication only at login. The system continuously verifies user identity and monitors activity duration, ensuring security persists throughout the session and enabling detection of prolonged or suspicious activities.

Inventive Principle:
Principle #20Continuity of useful action

3Ease of operation

If a dedicated VPN client is installed on user devices, then VPN functionality is provided, but this increases device complexity and installation requirements

Engineering Contradiction:
ImproveVPN client installationVSAvoiddedicated client software
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system provides universal access by implementing the VPN functionality through standard web browsers rather than requiring dedicated clients. The virtual network interface is accessed via HTTP/HTTPS protocols, making it compatible with any device that has a web browser. This eliminates the need for platform-specific VPN clients and reduces installation complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces the mechanical installation of dedicated VPN clients with a software-based web interface approach. Instead of installing native applications that require system configuration, users access the virtual network through standard web protocols. This substitution eliminates client installation steps while maintaining secure access functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11240242B1System and method for providing a zero trust network
Publication Date: 2022.02.01 REVBITS LLC
  • US11240242B1 patent drawing
  • US11240242B1 patent drawing

AI summary

A system and method for providing remote zero trust access to a private network. A cloud server provides a user at a remote device with access to the private network. A proxy server interfaces between the remote device and the private network. A web interface initiates a session with the user. The proxy server allows the user to enter login credentials, verifies the entered login credentials, provides a dashboard page for displaying a list of assets available to the user at the private network, establishes a first remote session between a client at the remote device and the proxy server, establishes a second remote session between the proxy server and a proxy agent at the remote server, and informs the proxy agent of a selected asset, and enables the user to access the selected asset via the first remote session, the second remote session, and the proxy agent.