ZTNA Domain Ownership Verification for On-Premises Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for improved techniques for deploying and managing zero trust network access applications with a cloud-based security infrastructure.
Innovation Solution
A zero trust network access (ZTNA) system is modified to facilitate distributed and/or cloud-based deployments of components for a control plane and a data plane, supporting a network-accessible front end for customer-hosted applications, with domain ownership verification required for access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If domain ownership verification is implemented for ZTNA service platform, then security is improved, but deployment complexity increases
Solution Approach 1:
The patent implements domain ownership verification as a preliminary action before providing ZTNA service. The customer must verify ownership of the domain they wish to use before the cloud-based ZTNA platform will allow access to their on-premises applications. This advance verification prevents unauthorized domain usage and establishes trust before service deployment begins.
Solution Approach 2:
The patent introduces an intermediary verification mechanism between the customer and the ZTNA service platform. A domain verification service acts as the intermediary, checking domain ownership through DNS record validation or other verification methods. This intermediary layer ensures security requirements are met without requiring complex direct integration between the customer's infrastructure and the ZTNA platform.
2Ease of operation
If distributed cloud-based deployment is implemented for control plane and data plane, then accessibility is improved, but system complexity increases
Solution Approach 1:
The patent divides the ZTNA system into two separate planes: a control plane deployed in the cloud and a data plane deployed at the customer's on-premises infrastructure. This segmentation allows each plane to be optimized for its specific function and deployed independently, improving accessibility while managing complexity through clear separation of concerns.
Solution Approach 2:
The patent introduces a service proxy as an intermediary component that connects the cloud-based control plane with the on-premises data plane. This service proxy facilitates communication and coordination between the two distributed components, enabling seamless operation while abstracting the underlying complexity from end users accessing the applications.
Data Source
AI summary
A cloud computing platform provides zero trust network access as a service to a customer that maintains an application on-premises. In this context, the customer may be required to demonstrate ownership of a domain before the cloud computing platform will provide access to the on-premises application via the domain.


