Time bound session management for operational technology (OT) applications
Systems and methods for time bound session management for Operational Technology (OT) applications using Cron expression policies over zero trust. Various embodiments include receiving a request to an end system from a user; determining that the request requires a time-based approval; performing one or more time-based policy checks associated with the request; and allowing or denying the request based on the one or more time-based policy checks. The steps can further include monitoring an active session between the user and the end system; and timing out the active session based on time-based policy checks.
1 . A method comprising steps of:
receiving a request to an end system from a user;
determining that the request requires a time-based approval, wherein the time-based approval is defined using Cron expressions specifying at least one recurring time window for access to the end system and enforced via a zero trust network access (ZTNA) service;
performing one or more time-based policy checks associated with the Cron expressions and performing one or more additional zero trust policy checks related to the request, wherein the additional zero trust policy checks include evaluating at least user identity, and at least one of endpoint posture, device context, and least-privileged access; and
allowing or denying the request based on the one or more time-based policy checks and results of the one or more additional zero trust policy checks, wherein the end system comprises an Operational Technology (OT) device or application, and wherein allowing the request comprises dynamically establishing an on-demand outbound secure tunnel from a connector application associated with the OT device or application to the ZTNA service without requiring inbound firewall openings to an OT network hosting the OT device or application.
2 . The method of claim 1 , wherein the one or more time-based policy checks are associated with any of the user and the requested end system.
3 . The method of claim 1 , wherein the one or more time-based policy checks include looking up approval tables based on an identity of the user.
4 . The method of claim 3 , wherein responsive to no match being found in the approval tables, or if an appropriate approval table does not exist, the request is denied.
5 . The method of claim 1 , wherein the steps further include displaying one or more end systems to the user through a portal.
6 . The method of claim 5 , wherein the one or more end systems are marked as active, inactive, or expired based on time-based policy.
7 . The method of claim 1 , wherein the steps further include configuring time-based policies associated with any of a user, group of users, and specific end systems.
8 . The method of claim 7 , wherein the configuring is performed through calendar-based selections for designating allowed time windows.
9 . The method of claim 1 , wherein the one or more time-based policy checks include comparing a current time against a Coordinated Universal Time (UTC) start and end time of a given time window.
10 . The method of claim 1 , wherein the steps further comprise:
monitoring an active session between the user and the end system;
timing out the active session based on time-based policy checks, and
responsive to timing out the active session due to expiration of the recurring time window defined by the Cron expressions, transmitting a notification to the user explicitly indicating a time-based policy timeout.
11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:
receiving a request to an end system from a user;
determining that the request requires a time-based approval, wherein the time-based approval is defined using Cron expressions specifying at least one recurring time window for access to the end system and enforced via a zero trust network access (ZTNA) service;
performing one or more time-based policy checks associated with the Cron expressions and performing one or more additional zero trust policy checks related to the request, wherein the additional zero trust policy checks include evaluating at least user identity, and at least one of endpoint posture, device context, and least-privileged access; and
allowing or denying the request based on the one or more time-based policy checks and results of the one or more additional zero trust policy checks, wherein the end system comprises an Operational Technology (OT) device or application, and wherein allowing the request comprises dynamically establishing an on-demand outbound secure tunnel from a connector application associated with the OT device or application to the ZTNA service without requiring inbound firewall openings to an OT network hosting the OT device or application.
12 . The non-transitory computer-readable medium of claim 11 , wherein the one or more time-based policy checks are associated with any of the user and the requested end system.
13 . The non-transitory computer-readable medium of claim 11 , wherein the one or more time-based policy checks include looking up approval tables based on an identity of the user.
14 . The non-transitory computer-readable medium of claim 13 , wherein responsive to no match being found in the approval tables, or if an appropriate approval table does not exist, the request is denied.
15 . The non-transitory computer-readable medium of claim 11 , wherein the steps further include displaying one or more end systems to the user through a portal.
16 . The non-transitory computer-readable medium of claim 15 , wherein the one or more end systems are marked as active, inactive, or expired based on time-based policy.
17 . The non-transitory computer-readable medium of claim 11 , wherein the steps further include configuring time-based policies associated with any of a user, group of users, and specific end systems.
18 . The non-transitory computer-readable medium of claim 17 , wherein the configuring is performed through calendar-based selections for designating allowed time windows.
19 . The non-transitory computer-readable medium of claim 11 , wherein the one or more time-based policy checks include comparing a current time against a Coordinated Universal Time (UTC) start and end time of a given time window.
20 . The non-transitory computer-readable medium of claim 11 , wherein the steps further comprise:
monitoring an active session between the user and the end system; and
timing out the active session based on time-based policy checks; and
responsive to timing out the active session due to expiration of the recurring time window defined by the Cron expressions, transmitting a notification to the user explicitly indicating a time-based policy timeout.