Zero-Trust Control Layer for Internet-Isolated Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Applications and websites hosted on shared networks are vulnerable to attacks due to direct exposure to the internet, necessitating a solution for zero trust protection and control to isolate and protect destination services.

Innovation Solution

A cloud-based system that enforces zero trust policies by creating ephemeral connections to destination services on a per-session basis, using a control layer to authorize and manage access, thereby preventing direct internet exposure and ensuring secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications and websites are made available in a shared network over the open internet, then accessibility to the destination service is improved, but vulnerability to attacks increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based system that acts as an intermediary between users and destination services. This system creates ephemeral connections on behalf of users, allowing access to services without direct exposure. The intermediary controls and manages connections, enabling services to remain isolated from the open internet while still being accessible to authorized users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the connection path into distinct components: user devices, cloud-based system, destination services, and isolated network. By dividing the network architecture into separate segments with controlled interaction points, the system allows accessibility while preventing direct attack vectors. Each segment operates independently with defined access rules.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If direct connection is allowed to destination service, then ease of access is improved, but attack surface is increased

Engineering Contradiction:
Improveease of accessVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The cloud-based system serves as a mediator that handles all connection management. Instead of allowing direct connections that expose the attack surface, the intermediary creates controlled ephemeral connections, managing the complexity of access control while keeping the destination service simple and isolated.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the connection management functionality from the destination service itself and places it in a separate cloud-based system. This extraction removes the complexity of access control and connection management from the service, reducing its attack surface while maintaining ease of access through the external management system.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If service is isolated from direct internet connection, then security is improved, but accessibility is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cloud-based system acts as a bridge that reconciles the contradiction between isolation and accessibility. It maintains security by keeping services isolated from direct internet connections while simultaneously providing accessibility through managed ephemeral connections that users can establish without direct exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud-based system performs multiple functions: it acts as a DNS authority, creates ephemeral connections, enforces security policies, and manages access control. This multi-functionality allows a single system to provide both security isolation and universal accessibility to multiple destination services simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12506786B2Systems and methods for active exposure and unwanted connection protection
Publication Date: 2025.12.23 ZSCALER INC
  • US12506786B2 patent drawing
  • US12506786B2 patent drawing
  • US12506786B2 patent drawing

AI summary

Systems and methods for active exposure and unwanted connection protection. In various embodiments, steps include receiving a request from a user to access a destination service; directing the request to a control layer; enforcing one or more controls, via the control layer, on the request based on a configuration provided by an owner of the destination service; and creating a connection from the destination service to the control layer based on the one or more controls, thereby providing access to the destination service without exposing the destination service to a direct connection.