Zero Trust Network Access for Mobile Banking Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional enterprise network security models are inadequate in protecting sensitive mobile applications, such as banking services, from Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, especially when infrastructure is hosted on the internet and users access applications from unmanaged devices, leading to service outages and financial losses.

Innovation Solution

Implementing a Zero Trust Network Access (ZTNA) approach with a cloud-based system using a Software Defined Perimeter (SDP) and Zero Trust architecture, where the bank's infrastructure is not exposed to the internet, and user authentication steers traffic through a secure tunnel, ensuring only authorized access and preventing DDoS attacks by embedding ZTNA support within mobile banking applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the bank's infrastructure is exposed to the internet for accessibility, then user access to banking applications is improved, but the system becomes vulnerable to DDoS attacks and service outages

Engineering Contradiction:
Improveuser access to banking applicationsVSAvoidDDoS attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Zero Trust Network Access (ZTNA) service as an intermediary between users and the bank's infrastructure. This ZTNA service acts as a mediator that provides secure access to applications while keeping the actual infrastructure hidden and protected from direct internet exposure, thereby preventing DDoS attacks from reaching the core banking systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the banking infrastructure into separate components: a publicly accessible ZTNA service layer and the private banking application infrastructure layer. This segmentation allows the access layer to be exposed while the core infrastructure remains isolated and invisible to the internet, resolving the contradiction between accessibility and security

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional VPN perimeter security is used, then network defense is improved, but it cannot protect mobile users accessing applications from unmanaged devices

Engineering Contradiction:
Improvenetwork defense capabilityVSAvoidmobile device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional network access model by moving from 'extending the network to users' to 'users connecting to applications through a cloud-based ZTNA service'. This inversion allows mobile users on unmanaged devices to access banking applications securely without requiring them to be part of the traditional network perimeter, thereby improving both security and mobile device compatibility

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The ZTNA service provides universal access to banking applications across multiple device types and network conditions. It works with both managed and unmanaged devices, supporting various operating systems and network environments, thereby achieving broad adaptability while maintaining strong security through the zero trust architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If cloud-based infrastructure is used for banking applications, then service availability is improved, but DDoS attacks can still reach and disrupt the infrastructure

Engineering Contradiction:
Improveservice availabilityVSAvoidDDoS attack exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The ZTNA service functions as a protective intermediary that sits between the internet and the cloud-based banking infrastructure. It allows legitimate users to access applications while filtering out and blocking DDoS attack traffic before it can reach the cloud infrastructure, thereby maintaining service availability while preventing attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20210377222A1ZTNA approach to secure sensitive mobile applications and prevent attacks
Publication Date: 2021.12.02 ZSCALER INC
  • US20210377222A1 patent drawing
  • US20210377222A1 patent drawing
  • US20210377222A1 patent drawing

AI summary

Systems and methods for protecting sensitive mobile applications from attack include incorporating private application access software in a mobile application that operates on a user device to provide functionality to an end user, the functionality is separate from the private application access; deploying application connectors in front of a private application that is accessed by the mobile application; responsive to a request to access the private application, authenticating the end user through the mobile application; and, responsive to authentication, providing access to the private application through the mobile application via a plurality of secure tunnels. The application connectors are configured to only provide outbound connections, thereby protecting the private application from the attack. The request to access is received via a cloud-based system which is configured to drop any invalid request, thereby protecting the private application from the attack.