Granular Private Resource Access Using ZTNA Policy Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large employee workforces accessing cloud resources remotely strain network capacity and security, allowing compromised users/devices to move laterally through corporate networks, compromising security.

Innovation Solution

Implementing Zero Trust Network Access (ZTNA) with a Secure Access Service Edge (SASE) to provide granular user access control based on identities, device types, locations, and resource types, using security clients and engines for authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If employees access company resources directly from the Internet or through VPN connections, then network capacity and security stamps are strained, but employees can still access various local and remote resources

Engineering Contradiction:
Improvenetwork securityVSAvoidresource access capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network access by creating distinct network paths: a first network path for on-premises resources and a second network path for cloud resources. This segmentation allows different security policies to be applied to different resource types, reducing the strain on corporate network security while maintaining access to both local and remote resources through appropriate routing decisions.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If VPN connections are used to access remote resources, then employees can connect to corporate network, but compromised users/devices can move laterally through corporate networks

Engineering Contradiction:
Improveremote access capabilityVSAvoidlateral movement risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network broker as an intermediary component that sits between users and resources. The network broker evaluates security policies and makes routing decisions, acting as a mediator that allows remote access while preventing direct lateral movement through the corporate network. Compromised devices must pass through the broker's security checks rather than having direct network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different security policies and routing behaviors based on the local conditions: devices determined to be on-premises are routed through the first network path with one set of security rules, while devices determined to be off-premises are routed through the second network path with different security rules. This local quality approach allows tailored security responses to different access scenarios.

Inventive Principle:
Principle #3Local quality

3Reliability

If granular security policies are implemented based on user identities, device types, and locations, then security threats are reduced, but system complexity increases

Engineering Contradiction:
Improvesecurity postureVSAvoidsecurity policy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements automatic device determination functionality that enables devices to self-identify whether they are on-premises or off-premises without manual configuration. The system automatically evaluates device location, network path, and security policies, reducing the administrative burden of managing granular security policies while maintaining high security postures through automated decision-making.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12634286B2Granular secure user access to private resources
Publication Date: 2026.05.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12634286B2 patent drawing
  • US12634286B2 patent drawing
  • US12634286B2 patent drawing

AI summary

Methods, systems and computer program products are provided for granular secure user access to private resources. Increased granularity of security policies for user access may reduce security threats to resources. Security policies indicating user access to secure resources may be based on various combinations of user identities, client-side process (e.g., sub-process) identities, device identities, device types, device locations, resource access types, intelligent access (e.g., selective traffic routing), etc. For example, a security policy may indicate user A, using computing device B executing process C with process signature S (e.g., a signing signature thumbprint, etc.) may access private resource D. A process identity may be indicated by at least one of a process name, a code signing signature, a thumbprint, a process version, or a process publisher. Resource access security policy determinations and/or enforcement may be performed by security clients and/or security engines (e.g., SASE providing ZTNA).