ZTNA Client Application Authentication for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current ZTNA solutions fail to implement least privilege principles based on client applications, leading to security gaps and vulnerabilities, as they primarily focus on user and device authentication without considering the client application initiating the connection.

Innovation Solution

Implementing an endpoint agent that monitors the software install base and encapsulates connections through a mTLS HTTPS tunnel, allowing real-time application identification and authentication, enabling granular access control based on client applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ZTNA solutions implement strong authentication and least privilege principles for users and devices, then security is improved, but the solution remains incomplete because client application authentication is not addressed

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication process into distinct components: user authentication, device authentication, and client application authentication. By implementing separate authentication mechanisms for each component, the system achieves comprehensive security coverage without compromising the existing user and device authentication frameworks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to the authentication model by introducing client application identity and authentication as a separate layer. This transforms the traditional two-dimensional authentication (user-device) into a three-dimensional framework (user-device-application), enabling more granular and complete security enforcement.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of manufacture

If ZTNA solutions focus on user and device authentication, then implementation is simpler, but security gaps and vulnerabilities arise due to lack of client application control

Engineering Contradiction:
Improveimplementation complexityVSAvoidsecurity gaps
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing client application authentication and identification mechanisms before access decisions are made. The system pre-configures application identities, authentication methods, and access policies, so that when access requests occur, the complete authentication framework is already in place to prevent security gaps.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If granular access control based on client applications is implemented, then network visibility and control are enhanced, but system complexity increases

Engineering Contradiction:
Improvenetwork visibilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces intermediary components such as application proxies and identity services that mediate between client applications and backend resources. These intermediaries handle the complexity of application identification, authentication, and access control enforcement, allowing the system to achieve granular visibility and control without directly complicating the core ZTNA architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260039658A1Endpoint client application authentication and access control on zero-trust networks
Publication Date: 2026.02.05 FORTINET INC
  • US20260039658A1 patent drawing
  • US20260039658A1 patent drawing
  • US20260039658A1 patent drawing

AI summary

Approaches to endpoint client application authentication and access control in Zero-Trust Network Access (ZTNA) environments are described. A request for an application to access a remote secure resource via a network connection is processed. The request comprises at least an application identifier assigned by a security device. A secure network connection is opened to allow the application to access the remote secure resource. A verification of establishment of the network connection is received to allow access to the remote secure resource. Application data is transmitted over the network connection to access the remote secure resource. The presented approaches have a benefit that the ZTNA gateways gain full visibility about which application accesses the remote resource based on the client-app-ID. The ZTNA gateway can enforce access control rules based on the app-IDs of the network connection headers.