IP Library Granted Patent US 11,876,781
Granted Patent B2
US 11,876,781 · App. 16/565,139 · Granted Jan 16, 2024

Protecting network devices by a firewall

Inventors: Kurt Glazemakers (Grembergen, BE); Per Johan Allansson (Kungsbacka, SE); Thomas Bruno Emmanuel Cellerier (Kungalv, SE); Kosmas Valianos (Gothenburg, SE); Tom Viljo Weber (Kode, SE)
Assignee: CRYPTZONE NORTH AMERICA, INC.
H04L63/0236H04L47/70H04L63/029H04L63/0263H04L63/0272H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,781
App. No.
16/565,139
Granted
Jan 16, 2024
Kind
B2
Abstract

Systems and methods provide for management of a gateway. In one embodiment, a method includes: in response to a request from a client device, establishing, by a computer system implementing a gateway to a private network, a network tunnel between the client device and the gateway; and starting a firewall service with a set of firewall rules on the computer system for selectively blocking and allowing network traffic between the client device and one or more network devices in the private network.

Claims (42)

1. A method, comprising:

receiving, by a computer system that implements a gateway to a private network, a client tunnel list over a first connection, the client tunnel list including information in order to establish a networking tunnel with the computer system;

establishing a second connection to the computer system using the client tunnel list;

receiving, by the computer system, a client access list comprising a script;

deriving a set of firewall rules from the client access list;

executing, by the computer system, the script to obtain one or more destinations, wherein the script is executed when a client device deploys a tunnel between the client device and the gateway, and wherein the script is configured to make a query, using an application programming interface, to a remote system to obtain the destinations, and the destinations comprise IP addresses or ports;

updating the set of firewall rules based on the obtained destinations; and

applying the set of firewall rules on the second connection to selectively block and allow network traffic between the client device and one or more network devices.

2. The method of claim 1 , wherein the script is a destination firewall rule of the client access list.

3. The method of claim 2 , wherein the client access list is received from an authentication service that manages access to network devices in the private network.

4. The method of claim 3 , wherein the client access list comprises a first access rule identifying a first network device of the network devices in the private network, and deriving the set of firewall rules comprises translating the first access rule into multiple firewall rules.

5. The method of claim 1 , wherein the script passes a username for an active session to an application programming interface, the method further comprising receiving a list of names for computers associated with the username to which access is granted.

6. The method of claim 5 , wherein a token or condition is associated with the username, the method further comprising updating the client access list in response to expiration or revocation of the token or condition.

7. The method of claim 1 , further comprising:

adding the obtained destinations to the client access list;

after adding the obtained destinations to the client access list, deriving, using the client access list, one or more new firewall rules; and

applying, by a firewall service, the new firewall rules for a network tunnel between the client device and the gateway.

8. The method of claim 1 , wherein updating the set of firewall rules based on the obtained destinations comprises updating the client access list by adding the obtained destinations, and wherein the set of firewall rules is updated based on the updated client access list.

9. A system, comprising:

at least one processor configured to implement a gateway to a private network; and

memory storing instructions configured to instruct the at least one processor to:

receive a client tunnel list over a first connection, the client tunnel list including information in order to establish a networking tunnel;

establishing a second connection using the client tunnel list;

receive a client access list comprising a script;

derive a set of firewall rules from the client access list;

execute the script to obtain one or more destinations, wherein the script is executed when a first networking tunnel is deployed between a client device and the gateway, and wherein the script is configured to make a query, using an application programming interface, to a remote system to obtain the destinations, and the destinations comprise IP addresses or ports;

update the set of firewall rules based on the obtained destinations; and

apply the set of firewall rules on the second connection to selectively block and allow network traffic between the client device and one or more network devices.

10. The system of claim 9 , wherein the instructions are further configured to instruct the at least one processor to receive a connection request from the client device, wherein the client access list is received after receiving the connection request.

11. The system of claim 10 , wherein the client access list indicates network devices in the private network that are allowed to communicate with the client device.

12. The system of claim 11 , wherein the client access list comprises an access rule that identifies a first network device of the private network by specifying a web service that can access the first network device.

13. The system of claim 9 , wherein the instructions are further configured to instruct the at least one processor to start a firewall service for the first networking tunnel, wherein the set of firewall rules is applied by the firewall service.

14. The system of claim 9 , wherein the client access list comprises a first access rule that is a call to a web service, and wherein the instructions are further configured to instruct the at least one processor to receive, in reply to the call to the web service, a list of network devices using an API according to metadata assigned to virtual instances.

15. The system of claim 9 , wherein the client access list is received from at least one of the client device, or an authentication service.

16. A non-transitory computer readable storage medium storing computer-readable instructions, which when executed, cause a computer system to at least:

receive a client tunnel list over a first connection, the client tunnel list including information in order to establish a networking tunnel;

establishing a second connection using the client tunnel list;

receive a client access list comprising a script;

derive a set of firewall rules from the client access list;

execute the script to obtain one or more destinations, wherein the script is executed when a client device deploys a tunnel between the client device and a gateway, and wherein the script is configured to make a query, using an application programming interface, to a remote system to obtain the destinations, and the destinations comprise IP addresses or ports;

update the set of firewall rules based on the obtained destinations; and

apply the set of firewall rules on the second connection to selectively block and allow network traffic between the client device and one or more network devices.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2019
From: GLAZEMAKERS, KURT; ALLANSSON, PER JOHAN; CELLERIER, THOMAS BRUNO EMMANUEL; VALIANOS, KOSMAS; WEBER, TOM VILJO
To: CRYPTZONE NORTH AMERICA, INC.
Reel/Frame 050319/0031 →
Continuity (4)
Continuation 15488132 · Apr 14, 2017
Continuation In Part 15053422 · Feb 25, 2016
Provisional Application 62292702 · Feb 8, 2016
Related Publication 20200007500A1 · Jan 2, 2020