IP Library Granted Patent US 12664504
Granted Patent B2
US 12664504 · App. 18/731,725 · Granted Jun 23, 2026

Systems and methods to protect shared privileged remote access (PRA) sessions based on user risk

Inventors: Digambar Sawant (Bangalore, IN); Vivek Bhatt (Bangalore, IN); Dejan Mihajlovic (Sunnyvale, CA); Mithun A S (Bangalore, IN); Simhadri Raju Avula (Hyderabad, IN)
Assignee: Zscaler, Inc.
G06Q10/0635G06Q10/06393
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12664504
App. No.
18/731,725
Granted
Jun 23, 2026
Kind
B2
Abstract

Systems and methods to protect shared Privileged Remote Access (PRA) sessions based on user risk include receiving, at a Privileged Remote Access (PRA) system, one or more invitations from a host, the one or more invitations being for one or more users to join a PRA session; responsive to receiving the one or more invitations, determining a risk score of each of the one or more users associated with the one or more invitations; and rejecting or allowing each of the one or more invitations based on the risk score of each of the one or more users.

Claims (40)

1 . A method comprising steps of:

receiving, at a Privileged Remote Access (PRA) system, one or more invitations from a host, the one or more invitations being for one or more users to join a PRA session;

responsive to receiving the one or more invitations, determining a risk score of each of the one or more users associated with the one or more invitations; and

rejecting or allowing each of the one or more invitations based on the risk score of each of the one or more users,

wherein, responsive to allowing an invitation of the one or more invitations, the PRA system creates the PRA session and brokers, via a service edge acting as a broker, a connection between a user device of the allowed user and an application through a lightweight connector that establishes an inside-out outbound connection to the service edge without accepting inbound connections,

wherein the PRA system enforces, for the PRA session, a security and access policy that includes selectively blocking commands from the user device from reaching the application to provide read-only access based on the risk score;

responsive to allowing one or more invitations, creating a PRA session, and brokering a connection between one or more users associated with the one or more allowed invitations and an application through a lightweight connector, and enabling the one or more users to send commands to the application;

continuously monitoring risk scores of the one or more users during the PRA session, including receiving, at an exporter associated with the PRA system, an asynchronous notification responsive to an updated risk score stored in a user risk database, and automatically updating a security and access policy applied to the PRA session based on the updated risk score; and

responsive to detecting an updated risk score for a user of the one or more users, enforcing read-only policy on the user during the PRA session,

wherein enforcing the read-only policy comprises, at an exporter handling the PRA session, blocking relaying of session instructions from the user device to a protocol daemon associated with the lightweight connector such that the protocol daemon does not receive the user's commands, while continuing to transmit pixels associated with the PRA session to the user device.

2 . The method of claim 1 , wherein the determining includes referencing the user risk database for determining a risk score of each of the one or more users associated with the one or more invitations.

3 . The method of claim 1 , wherein the rejecting or allowing is based on the risk score of each of the one or more users being below or above a threshold.

4 . The method of claim 1 , wherein the steps comprise:

(i) rejecting an invitation of the one or more invitations based on a user associated with the invitation being in a high-risk category based on their risk score, (ii) allowing an invitation of the one or more invitations based on a user associated with the invitation being in a low-risk category based on their risk score, and (iii) allowing an invitation of the one or more invitations with read-only access based on a user associated with the invitation being in a medium-risk category based on their risk score.

5 . The method of claim 1 , wherein the steps further comprise:

enforcing read-only policy on any of the one or more users during the PRA session based on the risk score of each of the one or more users.

6 . The method of claim 1 , wherein the steps further comprise:

responsive to detecting an updated risk score for a user of the one or more users, kicking the user from the PRA session.

7 . The method of claim 1 , wherein the steps further comprise:

responsive to detecting an updated risk score for a user of the one or more users, notifying the host of the updated risk score.

8 . A non-transitory computer-readable medium comprising instructions, wherein the instructions are executable by a cloud-based system to perform steps of:

receiving, at a Privileged Remote Access (PRA) system, one or more invitations from a host, the one or more invitations being for one or more users to join a PRA session;

responsive to receiving the one or more invitations, determining a risk score of each of the one or more users associated with the one or more invitations; and

rejecting or allowing each of the one or more invitations based on the risk score of each of the one or more users,

wherein, responsive to allowing an invitation of the one or more invitations, the PRA system creates the PRA session and brokers, via a service edge acting as a broker, a connection between a user device of the allowed user and an application through a lightweight connector that establishes an inside-out outbound connection to the service edge without accepting inbound connections,

wherein the PRA system enforces, for the PRA session, a security and access policy that includes selectively blocking commands from the user device from reaching the application to provide read-only access based on the risk score;

responsive to allowing one or more invitations, creating a PRA session, and brokering a connection between one or more users associated with the one or more allowed invitations and an application through a lightweight connector, and enabling the one or more users to send commands to the application;

continuously monitoring risk scores of the one or more users during the PRA session, including receiving, at an exporter associated with the PRA system, an asynchronous notification responsive to an updated risk score stored in a user risk database, and automatically updating a security and access policy applied to the PRA session based on the updated risk score; and

responsive to detecting an updated risk score for a user of the one or more users, enforcing read-only policy on the user during the PRA session,

wherein enforcing the read-only policy comprises, at an exporter handling the PRA session, blocking relaying of session instructions from the user device to a protocol daemon associated with the lightweight connector such that the protocol daemon does not receive the user's commands, while continuing to transmit pixels associated with the PRA session to the user device.

9 . The non-transitory computer-readable medium of claim 8 , wherein the determining includes referencing the user risk database for determining a risk score of each of the one or more users associated with the one or more invitations.

10 . The non-transitory computer-readable medium of claim 8 , wherein the rejecting or allowing is based on the risk score of each of the one or more users being below or above a threshold.

11 . The non-transitory computer-readable medium of claim 8 , wherein the steps comprise:

(i) rejecting an invitation of the one or more invitations based on a user associated with the invitation being in a high-risk category based on their risk score, (ii) allowing an invitation of the one or more invitations based on a user associated with the invitation being in a low-risk category based on their risk score, and (iii) allowing an invitation of the one or more invitations with read-only access based on a user associated with the invitation being in a medium-risk category based on their risk score.

12 . The non-transitory computer-readable medium of claim 8 , wherein the steps further comprise:

enforcing read-only policy on any of the one or more users during the PRA session based on the risk score of each of the one or more users.

13 . The non-transitory computer-readable medium of claim 8 , wherein the steps further comprise:

responsive to detecting an updated risk score for a user of the one or more users, kicking the user from the PRA session.

14 . The non-transitory computer-readable medium of claim 8 , wherein the steps further comprise:

responsive to detecting an updated risk score for a user of the one or more users, notifying the host of the updated risk score.