IP Library Granted Patent US 11,531,749
Granted Patent B2
US 11,531,749 · App. 16/879,401 · Granted Dec 20, 2022

Controlling access to external networks by an air-gapped endpoint

Inventors: Boris Figovsky (Hadera, IL); Tal Zamir (Tel Aviv, IL); Oleg Zlotnik (Nesher, IL); Nir Adler (Netanya, IL)
Assignee: Perception Point Ltd.
G06F21/53G06F9/45537G06F9/45545G06F9/45558G06F21/606H04L61/5014H04L63/02H04L63/0209H04L63/0272H04L63/0815H04L63/10H04L63/1416H04L63/1491H04L63/20H04W12/086G06F2009/4557G06F2009/45562G06F2009/45587G06F2009/45591G06F2009/45595H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,531,749
App. No.
16/879,401
Granted
Dec 20, 2022
Kind
B2
Abstract

A method and system for controlling access to external networks by an air-gapped endpoint is provided. The method includes providing, on the air-gapped endpoint, a plurality of isolated security zones by instantiating a plurality of corresponding virtual machines using a hypervisor; selecting one security zone of the plurality of isolated security zones; and tunneling a traffic from the selected security zone to a designated network location, wherein the tunneling is through a virtual private network (VPN).

Claims (35)

1. A method for controlling access to external networks by a virtually air-gapped endpoint that has a plurality of isolated security zones, each of the plurality of isolated security zones is realized as a respective corresponding one of a plurality of instantiated, already executing, virtual machines that were instantiated using a hypervisor, comprising:

selecting one security zone of the plurality of isolated security zones; and

tunneling a traffic from the selected security zone to a designated network location, wherein the tunneling is through a virtual private network (VPN); and

allowing the selected one security zone to connect to an external network based on at least one access rule, wherein allowing the connection between the security zone and the external network further comprises: exposing a virtual network interface card (NIC) corresponding to a physical NIC, wherein the connection to the external network is through the physical NIC, wherein a MAC address of the virtual NIC is the same as the MAC address of the physical NIC.

2. The method of claim 1 , wherein the selected security zone is a corporate zone, and the designated network location is a cloud VPN server.

3. The method of claim 1 , further comprising:

monitoring all traffic between the selected security zone and the external network to at least maintain compliance with a security policy set for the respective security zone.

4. The method of claim 1 , wherein the at least one access rule determines when the access to the external network is allowed.

5. The method of claim 4 , wherein the external network is the Internet.

6. The method of claim 1 , further comprising:

bridging the selected security zone directly into a network adapter, when the network adapter was verified to be connected to a public network.

7. The method of claim 6 , wherein verifying if the network adapter is connected to a public network, further comprises:

establishing a connection to an internet web server that is not accessible within the selected security zone;

cryptographically verifying an identity of the internet web server.

8. A method for controlling access to external networks by a virtually air-gapped endpoint that has a plurality of isolated security zones, each of the plurality of isolated security zones is realized as a respective corresponding one of a plurality of instantiated, already executing, virtual machines that were instantiated using a hypervisor, comprising:

selecting one security zone of the plurality of isolated security zones; and

tunneling a traffic from the selected security zone to a designated network location, wherein the tunneling is through a virtual private network (VPN); and

wherein the selecting and tunneling is performed by a hidden networking virtual machine (VM) responsible for managing all network activities of the virtually air-gapped endpoint.

9. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for controlling access to external networks by a virtually air-gapped endpoint that has a plurality of isolated security zones, each of the plurality of isolated security zones is realized as a respective corresponding one of a plurality of instantiated, already executing, virtual machines that were instantiated using a hypervisor, the process comprising:

selecting one security zone of the plurality of isolated security zones; and tunneling a traffic from the selected security zone to a designated network location, wherein the tunneling is through a virtual private network (VPN); and

allowing the selected one security zone to connect to an external network based on at least one access rule, wherein allowing the connection between the security zone and the external network further comprises: exposing a virtual network interface card (NIC) corresponding to a physical NIC, wherein the connection to the external network is through the physical NIC, wherein a MAC address of the virtual NIC is the same as the MAC address of the physical NIC.

10. A virtually gapped computing system that has a plurality of isolated security zones, each of the plurality of isolated security zones is realized as a respective corresponding one of a plurality of instantiated, already executing, virtual machines that were instantiated using a hypervisor, comprising: a network card interface; a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

select one security zone of the plurality of isolated security zones; and

tunnel a traffic from the selected security zone to a designated network location, wherein the tunneling is through a virtual private network (VPN); and

allowing the selected one security zone to connect to an external network based on at least one access rule, wherein allowing the connection between the security zone and the external network further comprises: exposing a virtual network interface card (NIC) corresponding to a physical NIC, wherein the connection to the external network is through the physical NIC, wherein a MAC address of the virtual NIC is the same as the MAC address of the physical NIC.

11. The air-gapped computing system of claim 10 , wherein the selected security zone is a corporate zone, and the designated network location is a cloud VPN server.

12. The air-gapped computing system of claim 9 , wherein the system is further configured:

monitor all traffic between the selected security zone and the external network to at least maintain compliance with a security policy set for the respective security zone.

13. The air-gapped computing system of claim 9 , wherein the at least one access rule determines when the access to the external network is allowed.

14. The air-gapped computing system of claim 9 , wherein the external network is the Internet.

15. The air-gapped computing system of claim 9 , wherein the system is further configured to:

bridge the selected security zone directly into a network adapter, when the network adapter was verified to be connected to a public network.

16. The air-gapped computing system of claim 9 , wherein the system is further configured to:

establish a connection to an internet web server that is not accessible within the selected security zone; and

cryptographically verify an identity of the internet web server.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2025
From: PERCEPTION POINT LTD.
To: FORTINET, INC.
Reel/Frame 070933/0424 →
SECURITY INTEREST Recorded Mar 26, 2023
From: PERCEPTION POINT LTD
To: KREOS CAPITAL VII AGGREGATOR SCSP
Reel/Frame 063103/0450 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2022
From: HYSOLATE LTD.
To: PERCEPTION POINT LTD.
Reel/Frame 060958/0747 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2020
From: FIGOVSKY, BORIS; ZAMIR, TAL; ZLOTNIK, OLEG; ADLER, NIR
To: HYSOLATE LTD.
Reel/Frame 052716/0225 →
Continuity (3)
Continuation 15876675 · Jan 22, 2018
Provisional Application 62449123 · Jan 23, 2017
Related Publication 20200285735A1 · Sep 10, 2020
Cited By (1)
US 12,255,873