IP Library Granted Patent US 12,438,915
Granted Patent B2
US 12,438,915 · App. 17/719,228 · Granted Oct 7, 2025

Systems and methods for context based access control in a bridge server

Inventor: Isaac Michael Johnson (Roselle, IL)
Assignee: Fortinet, Inc.
H04L63/20H04L63/0281H04L63/0428H04L63/08H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,915
App. No.
17/719,228
Granted
Oct 7, 2025
Kind
B2
Abstract

Systems, devices, and methods are discussed for context protected access to an air-gapped network resource via a bridge server.

Claims (46)

1. A method for performing context based security for an isolated network element, the method comprising:

resolving, by a bridge server, a requested resource using a proxy included in a received command, wherein the requested resource is an air-gapped resource associated with an air-gapped network that is accessible to an outside network only via the bridge server;

accessing, by the bridge server, a security policy associated with the requested resource;

analyzing, by the bridge server, the received command based at least in part on a context of the received command and the security policy; and

based upon a determination that the received command is acceptable, transferring a communication corresponding to the command to the requested resource.

2. The method of claim 1 , wherein the communication corresponding to the command includes a command component of the received command.

3. The method of claim 2 , wherein the communication corresponding to the command additionally includes a source address identifying the bridge server.

4. The method of claim 2 , wherein the communication corresponding to the command additionally includes a source address identifying a source of the received command.

5. The method of claim 1 , wherein the received command is a first received command, wherein the proxy is a first proxy, the method further comprising:

resolving, by the bridge server, the requested resource using a second proxy included in a second received command;

accessing, by the bridge server, the security policy associated with the requested resource;

analyzing, by the bridge server, the second received command based at least in part on a context of the second received command and the security policy; and

based upon a determination that the second received command is not acceptable, deleting the second received command.

6. The method of claim 1 , wherein the security policy applies at least one context based decision, and wherein the context based decision is based upon a context selected from a group consisting of: an identity of an individual generating the received command, an origin of the received command, a submission time of the received command, and an intent of the command.

7. The method of claim 6 , wherein the security policy applies at least one context based decision, and wherein the context based decision is based upon a context including two or more of: an identity of an individual generating the received command, an origin of the received command, a submission time of the received command, and an intent of the command.

8. The method of claim 1 , the method further comprising:

receiving, by the bridge server, an encrypted information packet from a network element via a communication network; and

decrypting, by the processing resource, the encrypted information packet to yield the received command.

9. A bridge server for performing context based security for an isolated network element, the bridge server comprising:

a processing resource;

a non-transitory computer readable medium coupled to the processing resource and having stored therein instructions that when executed by the processing resource cause the processing resource to:

resolve a requested resource using a proxy included in a received command, wherein the requested resource is an air-gapped resource associated with an air-gapped network that is accessible to an outside network only via the bridge server;

access a security policy associated with the requested resource;

analyze the received command based at least in part on a context of the received command and the security policy; and

based upon a determination that the received command is acceptable, transfer a communication corresponding to the command to the requested resource.

10. The bridge server of claim 9 , wherein the communication corresponding to the command includes a command component of the received command.

11. The bridge server of claim 10 , wherein the communication corresponding to the command additionally includes a source address identifying the bridge server.

12. The bridge server of claim 10 , wherein the communication corresponding to the command additionally includes a source address identifying a source of the received command.

13. The bridge server of claim 9 , wherein the received command is a first received command, wherein the proxy is a first proxy, and wherein the non-transient computer readable medium has stored therein instructions that when executed by the processing resource further cause the processing resource to:

resolve the requested resource using a second proxy included in a second received command;

access the security policy associated with the requested resource;

analyze the second received command based at least in part on a context of the second received command and the security policy; and

based upon a determination that the second received command is not acceptable, delete the second received command.

14. The bridge server of claim 9 , wherein the security policy applies at least one context based decision, and wherein the context based decision is based upon a context selected from a group consisting of: an identity of an individual generating the received command, an origin of the received command, a submission time of the received command, and an intent of the command.

15. The bridge server of claim 14 , wherein the security policy applies at least one context based decision, and wherein the context based decision is based upon a context including two or more of: an identity of an individual generating the received command, an origin of the received command, a submission time of the received command, and an intent of the command.

16. The bridge server of claim 9 , wherein the instructions further cause the processing resource to:

receive an encrypted information packet from a network element via a communication network; and

decrypt the encrypted information packet to yield the received command.

17. A non-transitory computer readable medium having stored therein instructions that when executed by a processing resource of a bridge server cause the processing resource to:

resolve a requested resource using a proxy included in a received command, wherein the requested resource is an air-gapped resource associated with an air-gapped network that is accessible to an outside network only via the bridge server;

access a security policy associated with the requested resource;

analyze the received command based at least in part on a context of the received command and the security policy; and

based upon a determination that the received command is acceptable, transfer a communication corresponding to the command to the requested resource.

18. The non-transitory computer readable medium of claim 17 , wherein the security policy applies at least one context based decision, and wherein the context based decision is based upon a context including two or more of: an identity of an individual generating the received command, an origin of the received command, a submission time of the received command, and an intent of the command.

19. The non-transitory computer readable medium of claim 17 , wherein the communication corresponding to the command includes a command component of the received command.

20. The non-transitory computer readable medium of claim 19 , wherein the communication corresponding to the command additionally includes a source address identifying the bridge server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2022
From: JOHNSON, ISAAC MICHAEL
To: FORTINET, INC.
Reel/Frame 059690/0266 →
Continuity (1)
Related Publication 20230328106A1 · Oct 12, 2023
References Cited (13)
US 7954144B1 · Ebrahimi · 2011 [cited by examiner]
US 8745709B2 · Narendra et al. · 2014 [cited by applicant]
US 10171463B1 · Wiger · 2019 [cited by applicant]
US 10547599B1 · Mehta et al. · 2020 [cited by applicant]
US 20020036983A1 · Widegren · 2002 [cited by examiner]
US 20110265168A1 · Lucovsky · 2011 [cited by examiner]
US 20160087957A1 · Shah et al. · 2016 [cited by applicant]
US 20180213002A1 · Figovsky · 2018 [cited by applicant]
US 20200151339A1 · Silverstone · 2020 [cited by applicant]
US 20210014224A1 · Gordon et al. · 2021 [cited by applicant]
US 20220129284A1 · Zhou · 2022 [cited by applicant]
Office Action for U.S. Appl. No. 17/831,155 mailed Feb. 7, 2025, 13 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/831,155 mailed May 20, 2025, 9 pages. [cited by applicant]