Zero Trust Network Proxy for Granular Asset Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN systems lack granular access control, allowing malicious actors to access unauthorized assets and fail to monitor user activities in real-time, relying on dedicated client installations and inadequate authentication methods.
Innovation Solution
A zero trust network system that implements a security policy where users are authenticated at every access step, using a private cloud server with a ZTN proxy server and agent to provide role-based or attribute-based access control, creating secure encrypted channels for single-asset access without a dedicated client, and enabling session recording and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional VPN is used to provide network access, then users can access all assets on the private network, but this allows malicious actors to access unauthorized assets and eliminates granular access control
Solution Approach 1:
The patent segments network access by creating separate virtual network interfaces (vNICs) for different asset classes. Each vNIC is associated with specific access control policies, allowing granular control over which users can access which assets. This divides the monolithic VPN access model into segmented, policy-based access channels.
Solution Approach 2:
The system implements local quality by assigning different access privileges to different virtual network interfaces. Each vNIC has its own access control list (ACL) that defines specific permissions for particular asset types, rather than providing uniform access to all assets. This allows fine-grained differentiation of access rights based on user role and asset sensitivity.
2Productivity
If VPN authentication is performed once at login, then users can access assets, but there is no real-time monitoring of user activities during sessions
Solution Approach 1:
The system implements continuous feedback by monitoring all network traffic passing through the virtual network interface. The monitoring component tracks user actions, resource access patterns, and session characteristics in real-time. This feedback mechanism enables detection of unauthorized activities and provides data for dynamic access control decisions during sessions.
Solution Approach 2:
The patent establishes continuous authentication and monitoring throughout the entire user session rather than performing authentication only at login. The system continuously verifies user identity and monitors activity duration, ensuring security persists throughout the session and enabling detection of prolonged or suspicious activities.
3Ease of operation
If a dedicated VPN client is installed on user devices, then VPN functionality is provided, but this increases device complexity and installation requirements
Solution Approach 1:
The system provides universal access by implementing the VPN functionality through standard web browsers rather than requiring dedicated clients. The virtual network interface is accessed via HTTP/HTTPS protocols, making it compatible with any device that has a web browser. This eliminates the need for platform-specific VPN clients and reduces installation complexity.
Solution Approach 2:
The patent replaces the mechanical installation of dedicated VPN clients with a software-based web interface approach. Instead of installing native applications that require system configuration, users access the virtual network through standard web protocols. This substitution eliminates client installation steps while maintaining secure access functionality.
Data Source
AI summary
A system and method for providing remote zero trust access to a private network. A cloud server provides a user at a remote device with access to the private network. A proxy server interfaces between the remote device and the private network. A web interface initiates a session with the user. The proxy server allows the user to enter login credentials, verifies the entered login credentials, provides a dashboard page for displaying a list of assets available to the user at the private network, establishes a first remote session between a client at the remote device and the proxy server, establishes a second remote session between the proxy server and a proxy agent at the remote server, and informs the proxy agent of a selected asset, and enables the user to access the selected asset via the first remote session, the second remote session, and the proxy agent.

