Zero-Trust Control Layer for Internet-Isolated Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Applications and websites hosted on shared networks are vulnerable to attacks due to direct exposure to the internet, necessitating a solution for zero trust protection and control to isolate and protect destination services.
Innovation Solution
A cloud-based system that enforces zero trust policies by creating ephemeral connections to destination services on a per-session basis, using a control layer to authorize and manage access, thereby preventing direct internet exposure and ensuring secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If applications and websites are made available in a shared network over the open internet, then accessibility to the destination service is improved, but vulnerability to attacks increases
Solution Approach 1:
The patent introduces a cloud-based system that acts as an intermediary between users and destination services. This system creates ephemeral connections on behalf of users, allowing access to services without direct exposure. The intermediary controls and manages connections, enabling services to remain isolated from the open internet while still being accessible to authorized users.
Solution Approach 2:
The patent segments the connection path into distinct components: user devices, cloud-based system, destination services, and isolated network. By dividing the network architecture into separate segments with controlled interaction points, the system allows accessibility while preventing direct attack vectors. Each segment operates independently with defined access rules.
2Ease of operation
If direct connection is allowed to destination service, then ease of access is improved, but attack surface is increased
Solution Approach 1:
The cloud-based system serves as a mediator that handles all connection management. Instead of allowing direct connections that expose the attack surface, the intermediary creates controlled ephemeral connections, managing the complexity of access control while keeping the destination service simple and isolated.
Solution Approach 2:
The patent extracts the connection management functionality from the destination service itself and places it in a separate cloud-based system. This extraction removes the complexity of access control and connection management from the service, reducing its attack surface while maintaining ease of access through the external management system.
3Reliability
If service is isolated from direct internet connection, then security is improved, but accessibility is reduced
Solution Approach 1:
The cloud-based system acts as a bridge that reconciles the contradiction between isolation and accessibility. It maintains security by keeping services isolated from direct internet connections while simultaneously providing accessibility through managed ephemeral connections that users can establish without direct exposure.
Solution Approach 2:
The cloud-based system performs multiple functions: it acts as a DNS authority, creates ephemeral connections, enforces security policies, and manages access control. This multi-functionality allows a single system to provide both security isolation and universal accessibility to multiple destination services simultaneously.
Data Source
AI summary
Systems and methods for active exposure and unwanted connection protection. In various embodiments, steps include receiving a request from a user to access a destination service; directing the request to a control layer; enforcing one or more controls, via the control layer, on the request based on a configuration provided by an owner of the destination service; and creating a connection from the destination service to the control layer based on the one or more controls, thereby providing access to the destination service without exposing the destination service to a direct connection.


