Software defined remote access for zero-trust support
Various embodiments of the teachings herein include an automated method for data access to a device by an external client, allowing the device to communicate with an internal communication network while the external client communicates with an external communication network. An example method includes: sending a communication access request from the external client for the device to a software implemented application access point; configuring a corresponding software implemented connector using the application access point, so the connector acts as an endpoint for a communication tunnel to the device; configuring a corresponding software implemented policy decision point using the application access point as an interface to the external network for arriving of application data traffic of the external client, so the policy decision point is set up to validate, accept, and forward the access request of the external client to the connector; and accessing the device via the communication tunnel.
1 . A method for data access to a device by an external client, allowing the device to communicate with an internal communication network while the external client communicates with an external communication network, the method comprising:
sending a communication access request from the external client for the device to a software implemented application access point to check and authorize or reject access requests from external clients to devices;
configuring a corresponding software implemented connector using the application access point, so the connector acts as an endpoint for a communication tunnel to the device;
configuring a corresponding software implemented policy decision point using the application access point as an interface to the external network for arriving of application data traffic of the external client, so the policy decision point is set up to validate, accept, and forward the access request of the external client to the connector; and
accessing the device via the communication tunnel using the external client;
wherein checking the access request the application access point includes performing a context matching with a device digital twin of the device.
2 . A method according to claim 1 , wherein the device digital twin is set up with process related data of the device, configuration data of the device, and operational technology (OT) parameters of the device.
3 . A method according to claim 1 , wherein the device digital twin is set up to:
interact with the application access point to validate external clients' connection requests; and
in case of a successful request-validation to notify the device and to schedule the configuration, setup, and activation of a software implemented policy enforcement point on the device.
4 . A method according claim 3 , wherein the policy enforcement point acts as a communication tunnel endpoint, created on-demand, and locally on the device after prior validation of the access request of the external client.
5 . A communication network system, the system comprising:
an internal communication network;
an external communication network;
an external client communicating with the external network;
a device communicating with the internal network;
a software implemented application access point to check and authorize or reject a connection access requests from the external clients to the device;
a software implemented connector of the internal network to be configured by the application access point, so the connector acts as an endpoint for a communication tunnel to the device;
a software implemented policy decision point of the internal network to be configured by the application access point as an interface to the external network for arriving of application data traffic of the external client, and to validate, accept, and forward access requests of the external client to the connector; and
a device digital twin of the device;
wherein the application access point is further set up to check the access request by performing a context matching with the device digital twin.
6 . A system according to claim 5 , wherein the device digital twin is set up with process related data of the device, configuration data of the device, and operational technology (OT) parameters of the device.
7 . A system according to claim 5 , further comprising:
a software implemented policy enforcement point (PEP) on the device;
wherein the device digital twin is set up to interact with the application access point to validate external clients' connection requests, and in case of a successful request validation to notify the device and to schedule the configuration, setup, and activation of the policy enforcement point.
8 . A system according claim 7 , wherein the policy enforcement point acts as a communication tunnel endpoint, created on-demand, and locally on the device after prior validation of the access request of the external client.