Zero Trust Network Access for Mobile Banking Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional enterprise network security models are inadequate in protecting sensitive mobile applications, such as banking services, from Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, especially when infrastructure is hosted on the internet and users access applications from unmanaged devices, leading to service outages and financial losses.
Innovation Solution
Implementing a Zero Trust Network Access (ZTNA) approach with a cloud-based system using a Software Defined Perimeter (SDP) and Zero Trust architecture, where the bank's infrastructure is not exposed to the internet, and user authentication steers traffic through a secure tunnel, ensuring only authorized access and preventing DDoS attacks by embedding ZTNA support within mobile banking applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the bank's infrastructure is exposed to the internet for accessibility, then user access to banking applications is improved, but the system becomes vulnerable to DDoS attacks and service outages
Solution Approach 1:
The patent introduces a Zero Trust Network Access (ZTNA) service as an intermediary between users and the bank's infrastructure. This ZTNA service acts as a mediator that provides secure access to applications while keeping the actual infrastructure hidden and protected from direct internet exposure, thereby preventing DDoS attacks from reaching the core banking systems
Solution Approach 2:
The patent segments the banking infrastructure into separate components: a publicly accessible ZTNA service layer and the private banking application infrastructure layer. This segmentation allows the access layer to be exposed while the core infrastructure remains isolated and invisible to the internet, resolving the contradiction between accessibility and security
2Reliability
If traditional VPN perimeter security is used, then network defense is improved, but it cannot protect mobile users accessing applications from unmanaged devices
Solution Approach 1:
The patent inverts the traditional network access model by moving from 'extending the network to users' to 'users connecting to applications through a cloud-based ZTNA service'. This inversion allows mobile users on unmanaged devices to access banking applications securely without requiring them to be part of the traditional network perimeter, thereby improving both security and mobile device compatibility
Solution Approach 2:
The ZTNA service provides universal access to banking applications across multiple device types and network conditions. It works with both managed and unmanaged devices, supporting various operating systems and network environments, thereby achieving broad adaptability while maintaining strong security through the zero trust architecture
3Productivity
If cloud-based infrastructure is used for banking applications, then service availability is improved, but DDoS attacks can still reach and disrupt the infrastructure
Solution Approach 1:
The ZTNA service functions as a protective intermediary that sits between the internet and the cloud-based banking infrastructure. It allows legitimate users to access applications while filtering out and blocking DDoS attack traffic before it can reach the cloud infrastructure, thereby maintaining service availability while preventing attacks
Data Source
AI summary
Systems and methods for protecting sensitive mobile applications from attack include incorporating private application access software in a mobile application that operates on a user device to provide functionality to an end user, the functionality is separate from the private application access; deploying application connectors in front of a private application that is accessed by the mobile application; responsive to a request to access the private application, authenticating the end user through the mobile application; and, responsive to authentication, providing access to the private application through the mobile application via a plurality of secure tunnels. The application connectors are configured to only provide outbound connections, thereby protecting the private application from the attack. The request to access is received via a cloud-based system which is configured to drop any invalid request, thereby protecting the private application from the attack.


