ZTNA Cloud Access Through Secure Tunnels for Legacy Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network devices, particularly legacy devices, struggle to access cloud environments using Zero Trust Network Access (ZTNA) without requiring a software client for direct communication with an identity broker.
Innovation Solution
A preconfigured access device establishes a secure tunnel with an identity broker, allowing network devices to communicate through this tunnel and apply policies without needing a software client, enabling legacy devices and transient network devices to access cloud environments securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network devices communicate directly with the identity broker, then access control and security policies can be enforced, but legacy devices and transient network devices cannot access the cloud environment without a software client
Solution Approach 1:
The patent introduces an access device as an intermediary between network devices and the identity broker. The access device establishes a secure tunnel with the identity broker and forwards communications between network devices and the broker through this tunnel. This allows legacy devices without software clients to access the cloud environment while maintaining security policy enforcement through the identity broker.
2Reliability
If a software client is installed on each network device for direct communication with the identity broker, then secure access control is achieved, but the cost and complexity of client premise equipment increases
Solution Approach 1:
The access device serves as a mediator that consolidates the software client functionality at a single location rather than requiring it on every network device. The access device establishes the secure tunnel with the identity broker and handles authentication and policy enforcement, while network devices can communicate through this tunnel without having their own software clients.
Solution Approach 2:
The patent merges the software client functionality into a single access device that serves multiple network devices. Instead of each device having its own client, the access device combines the tunnel establishment, authentication, and policy enforcement functions, reducing overall system complexity and equipment costs while maintaining security.
3Adaptability or versatility
If legacy devices are allowed to access the cloud environment without a software client, then compatibility is improved, but direct security policy enforcement becomes difficult
Solution Approach 1:
The access device acts as an intermediary that enables legacy devices to access the cloud environment without software clients while maintaining security policy enforcement. The access device forwards communications between legacy devices and the identity broker through a secure tunnel, allowing the identity broker to enforce security policies on traffic from legacy devices even though they cannot run software clients themselves.
Data Source
AI summary
Disclosed herein are embodiments that provide for accessing a cloud environment with Zero Trust Network Access (ZTNA). In particular, the embodiments provide managing communications via an identity broker through a secure tunnel between at least one network device and a cloud environment via an access device. The access device is preconfigured to contact the identity broker to establish the secure tunnel. At least one policy may then be applied to the at least one network device via the access device. In such a configuration, the at least one network device, such as a legacy device or a plurality of network devices, does not require a software client to communicate directly with the identity broker.


