IP Library Granted Patent US 12,676,831
Granted Patent B2
US 12,676,831 · App. 18/613,328 · Granted Jul 7, 2026

Systems and methods for uniquely labeling egress traffic from secure service edge (SSE) platforms

Inventor: Edwin Sutherland (Bletchley, GB)
Assignee: Zscaler, Inc.
H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,676,831
App. No.
18/613,328
Granted
Jul 7, 2026
Kind
B2
Abstract

Systems and methods for uniquely labeling egress traffic from Secure Service Edge (SSE) platforms include intercepting traffic at cloud, wherein the traffic is associated with a tenant of one or more tenants of the cloud, and wherein the traffic is destined for an application; labeling the traffic with an egress Internet Protocol (IP) address and a unique hash value; and forwarding the traffic including the egress IP address and the unique hash value to the application. The unique hash value is unique to the tenant and identifiable by the application for determining the tenant of the one or more tenants based thereon.

Claims (38)

1 . A method comprising steps of:

intercepting traffic at a cloud operating as a Secure Service Edge (SSE) provider wherein the traffic is associated with a tenant of one or more tenants of the cloud, and wherein the traffic is destined for a Software-as-a-Service (SaaS) application;

labeling the traffic with an egress Internet Protocol (IP) address and a unique hash value that is generated for the tenant and uniquely identifies the tenant among the one or more tenants of the cloud; and

forwarding the traffic to the SaaS application via an Internet Protocol version 6 (IPv6) network, wherein the forwarding includes inserting the unique hash value into a flow label field of an IPv6 header such that the SaaS application can identify the tenant based on the combination of the egress IP address and the unique hash value.

2 . The method of claim 1 , wherein the cloud operates as a Secure Service Edge (SSE) provider that enforces tenant-specific policies across a shared egress IP address block without requiring a dedicated egress IP for each tenant.

3 . The method of claim 1 , wherein the Software-as-a-Service (SaaS) application applies an Internet Protocol (IP) allow-list control policy, and wherein the unique hash value enables the SaaS application to distinguish tenants of the SSE provider despite shared egress IP addressing.

4 . The method of claim 1 , wherein the forwarding includes forwarding the traffic via the Internet Protocol version 6 (IPv6) network includes inserting the unique hash value into a 20-bit flow label field of an IPv6 header, the flow label being repurposed to identify the tenant to the application.

5 . The method of claim 1 , wherein the steps comprise:

generating one or more unique hash values for each of the one or more tenants of the cloud.

6 . The method of claim 5 , wherein the steps comprise:

communicating the one or more unique hash values of each of the one or more tenants to the application.

7 . The method of claim 6 , wherein communicating the one or more unique hash values of each of the one or more tenants to the application is performed by an administrator of each of the one or more tenants.

8 . The method of claim 6 , wherein the communicating comprises:

establishing an Application Programing Interface (API) integration between the cloud and the application; and

communicating the egress IP and the one or more unique hash values of the one or more tenants to the application via the API integration.

9 . The method of claim 8 , wherein the steps further comprise:

regenerating the one or more unique hash values for each of the one or more tenants of the cloud periodically; and

communicating the egress IP and the one or more regenerated unique hash values of the one or more tenants to the application via the API integration.

10 . The method of claim 1 , wherein the unique hash value is unique to the tenant and identifiable by the application for determining the tenant, and wherein the application enforces access based on a tuple of the egress IP address and the unique hash value.

11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

intercepting traffic at a cloud operating as a Secure Service Edge (SSE) provider, wherein the traffic is associated with a tenant of one or more tenants of the cloud, and wherein the traffic is destined for a Software-as-a-Service (Saas) application;

labeling the traffic with an egress Internet Protocol (IP) address and a unique hash value that is generated for the tenant and uniquely identifies the tenant among the one or more tenants of the cloud; and

forwarding the traffic to the Saas application via an Internet Protocol version 6 (IPv6) network, wherein the forwarding includes inserting the unique hash value into a flow label field of an IPv6 header such that the SaaS application can identify the tenant based on the combination of the egress IP address and the unique hash value.

12 . The non-transitory computer-readable medium of claim 11 , wherein the cloud operates as a Secure Service Edge (SSE) provider that enforces tenant-specific policies across a shared egress IP address block without requiring a dedicated egress IP for each tenant.

13 . The non-transitory computer-readable medium of claim 11 , wherein the Software-as-a-Service (SaaS) application applies an Internet Protocol (IP) allow-list control policy, and wherein the unique hash value enables the SaaS application to distinguish tenants of the SSE provider despite shared egress IP addressing.

14 . The non-transitory computer-readable medium of claim 11 , wherein the forwarding includes forwarding the traffic via the Internet Protocol version 6 (IPv6) network includes inserting the unique hash value into a 20-bit flow label field of an IPv6 header, the flow label being repurposed to identify the tenant to the application.

15 . The non-transitory computer-readable medium of claim 11 , wherein the steps comprise:

generating one or more unique hash values for each of the one or more tenants of the cloud.

16 . The non-transitory computer-readable medium of claim 15 , wherein the steps comprise:

communicating the one or more unique hash values of each of the one or more tenants to the application.

17 . The non-transitory computer-readable medium of claim 16 , wherein communicating the one or more unique hash values of each of the one or more tenants to the application is performed by an administrator of each of the one or more tenants.

18 . The non-transitory computer-readable medium of claim 16 , wherein the communicating comprises:

establishing an Application Programing Interface (API) integration between the cloud and the application; and

communicating the egress IP and the one or more unique hash values of the one or more tenants to the application via the API integration.

19 . The non-transitory computer-readable medium of claim 18 , wherein the steps further comprise:

regenerating the one or more unique hash values for each of the one or more tenants of the cloud periodically; and

communicating the egress IP and the one or more regenerated unique hash values of the one or more tenants to the application via the API integration.

20 . The non-transitory computer-readable medium of claim 11 , wherein the unique hash value is unique to the tenant and identifiable by the application for determining the tenant, and wherein the application enforces access based on a tuple of the egress IP address and the unique hash value.