ZTNA Domain Ownership Verification for On-Premises Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved techniques for deploying and managing zero trust network access applications with a cloud-based security infrastructure.

Innovation Solution

A zero trust network access (ZTNA) system is modified to facilitate distributed and/or cloud-based deployments of components for a control plane and a data plane, supporting a network-accessible front end for customer-hosted applications, with domain ownership verification required for access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain ownership verification is implemented for ZTNA service platform, then security is improved, but deployment complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements domain ownership verification as a preliminary action before providing ZTNA service. The customer must verify ownership of the domain they wish to use before the cloud-based ZTNA platform will allow access to their on-premises applications. This advance verification prevents unauthorized domain usage and establishes trust before service deployment begins.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism between the customer and the ZTNA service platform. A domain verification service acts as the intermediary, checking domain ownership through DNS record validation or other verification methods. This intermediary layer ensures security requirements are met without requiring complex direct integration between the customer's infrastructure and the ZTNA platform.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If distributed cloud-based deployment is implemented for control plane and data plane, then accessibility is improved, but system complexity increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent divides the ZTNA system into two separate planes: a control plane deployed in the cloud and a data plane deployed at the customer's on-premises infrastructure. This segmentation allows each plane to be optimized for its specific function and deployed independently, improving accessibility while managing complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a service proxy as an intermediary component that connects the cloud-based control plane with the on-premises data plane. This service proxy facilitates communication and coordination between the two distributed components, enabling seamless operation while abstracting the underlying complexity from end users accessing the applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12407656B2Domain ownership verification for a ZTNA service platform
Publication Date: 2025.09.02 SOPHOS LTD
  • US12407656B2 patent drawing
  • US12407656B2 patent drawing
  • US12407656B2 patent drawing

AI summary

A cloud computing platform provides zero trust network access as a service to a customer that maintains an application on-premises. In this context, the customer may be required to demonstrate ownership of a domain before the cloud computing platform will provide access to the on-premises application via the domain.