Zero Trust Network Access Connector Cloud Offloading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved techniques for deploying and managing zero trust network access applications with a cloud-based security infrastructure, as well as for improved connectors to couple end users to the zero trust network access applications.

Innovation Solution

A zero trust network access (ZTNA) system is modified to facilitate distributed and/or cloud-based deployments of components for a control plane and a data plane that cooperate to support a network-accessible front end for locally hosted applications. The ZTNA components for secure tunneling, authorization, and authentication are moved into the cloud-based infrastructure, and the deployment and configuration of the connector are managed through a threat management facility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If ZTNA components for secure tunneling, authorization, and authentication are moved into cloud-based infrastructure, then the connector size and complexity are reduced, but the dependency on cloud infrastructure increases

Engineering Contradiction:
Improveconnector complexityVSAvoidcloud infrastructure dependency
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent extracts complex ZTNA components (secure tunneling, authorization, and authentication) from the local connector and relocates them to cloud-based infrastructure. This extraction reduces the connector's size and complexity while maintaining full ZTNA functionality through cloud services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based infrastructure is designed to provide multiple ZTNA functions (secure tunneling, authorization, authentication) through a unified service platform. This multi-functional approach allows the simplified connector to leverage comprehensive security capabilities without incorporating complex local components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If connector deployment is simplified by moving ZTNA components to cloud, then ease of deployment is improved, but control and management flexibility may be reduced

Engineering Contradiction:
Improvedeployment simplicityVSAvoidmanagement flexibility
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based control plane as an intermediary between the simplified connector and the ZTNA functionality. This mediator handles complex operations like authorization and authentication, while providing management interfaces that maintain operational flexibility for administrators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the cloud-based infrastructure continuously monitors and manages connector operations. This allows automated deployment and configuration while maintaining management flexibility through centralized control and real-time policy updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250080503A1Zero trust network access connector for customer premises
Publication Date: 2025.03.06 SOPHOS LTD
  • US20250080503A1 patent drawing
  • US20250080503A1 patent drawing
  • US20250080503A1 patent drawing

AI summary

A zero trust network access (ZTNA) system provides secure access to applications hosted on a customer premises. The ZTNA system is modified to facilitate distributed and/or cloud-based deployments of components for a control plane and a data plane that cooperate to support a network-accessible front end for the customer's locally hosted applications. A customer-side connector can be further simplified for deployment by moving ZTNA components for, e.g., secure tunneling, authorization, and authentication into the cloud-based infrastructure, and by managing deployment and configuration of the connector through a threat management facility for the customer premises.