IP Library Granted Patent US 11,695,736
Granted Patent B2
US 11,695,736 · App. 17/199,824 · Granted Jul 4, 2023

Cloud-based explicit proxy with private access feature set

Inventors: Olli-Pekka Niemi (Espoo, FI); Ville Mattila (Helsinki, FI)
Assignee: FORCEPOINT LLC
H04L63/0281H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,695,736
App. No.
17/199,824
Granted
Jul 4, 2023
Kind
B2
Abstract

A system for processing data is disclosed that includes a first processor configured to operate one or more algorithms to identify a user identity as a function of user metadata and to provide access to a predetermined network resource using a cloud-based explicit proxy as a function of the user identity and one or more service requests, the first processor configured to operate one or more algorithms to detect a change in the one or more service requests and wherein access to the predetermined network resources using the cloud-based explicit proxy is modified as a function of the detected change in the one or more service requests.

Claims (28)

1. A system for processing data, comprising:

a first processor configured to operate one or more algorithms to identify a user identity as a function of user metadata and to provide access to a predetermined network resource using a cloud-based explicit proxy in a hosted container selected from an integrated suite of containers as a function of the user identity and one or more service requests;

the first processor configured to operate one or more algorithms to detect a change in the one or more service requests; and

wherein access to the predetermined network resource using the cloud-based explicit proxy is modified as a function of the detected change in the one or more service requests.

2. The system of claim 1 wherein providing access to the predetermined network resource comprises authorizing access as a function of the user identity using the cloud-based explicit proxy and using a cloud-based domain name caching resolver.

3. The system of claim 1 wherein modifying access to the predetermined network resource comprises terminating access to one or more predetermined network resources using the cloud-based explicit proxy.

4. The system of claim 1 wherein modifying access to the predetermined network resource comprises providing access to an additional one or more predetermined network resources.

5. A system for processing data, comprising:

a first processor configured to operate one or more algorithms to identify a user identity as a function of user metadata and to provide access to a predetermined network resource using a cloud-based firewall explicit proxy as a function of the user identity and one or more service requests;

the first processor configured to operate one or more algorithms to detect a change in the one or more service requests; and

wherein access to the predetermined network resource using the cloud-based firewall explicit proxy is modified as a function of the detected change in the one or more service requests and the cloud-based firewall explicit proxy is provided in a container selected from an integrated suite of containers.

6. The system of claim 5 wherein providing access to the predetermined network resource comprises authorizing access as a function of the user identity using the cloud-based firewall explicit proxy and using a cloud-based domain name caching resolver in a second container selected from the integrated suite of containers.

7. The system of claim 5 wherein modifying access to the predetermined network resource comprises terminating access to one or more predetermined network resources.

8. The system of claim 5 wherein modifying access to the predetermined network resources comprises providing access to an additional one or more predetermined network resources using the cloud-based firewall explicit proxy.

9. The system of claim 5 wherein providing access to the predetermined network resource comprises authorizing access as a function of the user identity using the cloud-based firewall explicit proxy and a security key.

10. The system of claim 5 wherein providing access to the predetermined network resource comprises authorizing access as a function of the user identity using the cloud-based firewall explicit proxy and a security key issued by a cloud-based firewall system.

11. The system of claim 5 wherein the service requests comprise firewall service requests.

12. The system of claim 5 wherein the service requests comprise a proxy auto-configuration request.

13. The system of claim 5 wherein the service requests comprise a dynamic edge protection request that is processed using a DNS caching resolver docker container of the integrated suite of containers.

14. The system of claim 5 wherein access is provided to a predetermined network resource by modifying a default deny posture of zero trust.

15. The system of claim 5 wherein access is provided to a predetermined network resource by modifying a default deny posture of zero trust of a software defined perimeter.

16. A system for processing data, comprising:

a first processor configured to operate one or more algorithms to identify a user identity as a function of user metadata and to provide access to a software-defined network perimeter using a cloud-based explicit proxy stored in a container of an integrated suite of containers as a function of the user identity and one or more service requests;

the first processor configured to operate one or more algorithms to detect a change in the one or more service requests; and

wherein access to the software-defined network perimeter using the cloud-based explicit proxy is modified as a function of the detected change in the one or more service requests.

17. The system of claim 16 wherein providing access to the software-defined network perimeter comprises authorizing access as a function of the user identity using the cloud-based explicit proxy and a domain name caching resolver container.

18. The system of claim 16 wherein modifying access to the software-defined network perimeter comprises terminating access to one or more predetermined network resources.

19. The system of claim 16 wherein modifying access to the software-defined network perimeter comprises providing access to one or more predetermined network resources.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2021
From: NIEMI, OLLI-PEKKA; MATTILA, VILLE
To: FORCEPOINT LLC
Reel/Frame 055865/0676 →