ZTNA Cloud Access Through Secure Tunnels for Legacy Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices, particularly legacy devices, struggle to access cloud environments using Zero Trust Network Access (ZTNA) without requiring a software client for direct communication with an identity broker.

Innovation Solution

A preconfigured access device establishes a secure tunnel with an identity broker, allowing network devices to communicate through this tunnel and apply policies without needing a software client, enabling legacy devices and transient network devices to access cloud environments securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices communicate directly with the identity broker, then access control and security policies can be enforced, but legacy devices and transient network devices cannot access the cloud environment without a software client

Engineering Contradiction:
Improvecompatibility with legacy devicesVSAvoidrequirement for software client
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an access device as an intermediary between network devices and the identity broker. The access device establishes a secure tunnel with the identity broker and forwards communications between network devices and the broker through this tunnel. This allows legacy devices without software clients to access the cloud environment while maintaining security policy enforcement through the identity broker.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a software client is installed on each network device for direct communication with the identity broker, then secure access control is achieved, but the cost and complexity of client premise equipment increases

Engineering Contradiction:
Improvesecure access controlVSAvoidclient premise equipment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access device serves as a mediator that consolidates the software client functionality at a single location rather than requiring it on every network device. The access device establishes the secure tunnel with the identity broker and handles authentication and policy enforcement, while network devices can communicate through this tunnel without having their own software clients.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges the software client functionality into a single access device that serves multiple network devices. Instead of each device having its own client, the access device combines the tunnel establishment, authentication, and policy enforcement functions, reducing overall system complexity and equipment costs while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If legacy devices are allowed to access the cloud environment without a software client, then compatibility is improved, but direct security policy enforcement becomes difficult

Engineering Contradiction:
Improvelegacy device compatibilityVSAvoidsecurity policy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The access device acts as an intermediary that enables legacy devices to access the cloud environment without software clients while maintaining security policy enforcement. The access device forwards communications between legacy devices and the identity broker through a secure tunnel, allowing the identity broker to enforce security policies on traffic from legacy devices even though they cannot run software clients themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250267130A1Accessing cloud environment with zero trust network access
Publication Date: 2025.08.21 CHARTER COMM OPERATING LLC
  • US20250267130A1 patent drawing
  • US20250267130A1 patent drawing
  • US20250267130A1 patent drawing

AI summary

Disclosed herein are embodiments that provide for accessing a cloud environment with Zero Trust Network Access (ZTNA). In particular, the embodiments provide managing communications via an identity broker through a secure tunnel between at least one network device and a cloud environment via an access device. The access device is preconfigured to contact the identity broker to establish the secure tunnel. At least one policy may then be applied to the at least one network device via the access device. In such a configuration, the at least one network device, such as a legacy device or a plurality of network devices, does not require a software client to communicate directly with the identity broker.