IP Library Granted Patent US 12,695,789
Granted Patent B2
US 12,695,789 · App. 17/720,647 · Granted Jul 28, 2026

System and method to create zero trust framework for security as a service

Inventors: Anamika Bhattacharya (Bangalore, IN); Deepak Bharadwaj (Bangalore, IN); Sriranga Seetharamaiah (Bangalore, IN); Abhisek Sanyal (Bangalore, IN); Siddaraya Revashetti (Cupertino, CA)
Assignee: Skyhigh Security LLC
H04L63/20H04L63/102H04L67/1008H04L67/1014
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,695,789
App. No.
17/720,647
Granted
Jul 28, 2026
Kind
B2
Abstract

An apparatus includes a network interface that performs a reception of a launch request and receives a policy for a service. The launch request includes an identifier of a workload and an identifier of an application. A processor determines a customer security posture, at least in part based on the identifier of the workload and the identifier of the application. Further, the processor determines to deny the launch request, at least in part based on the policy and the customer security posture.

Claims (47)

1 . An apparatus, comprising:

a network interface that performs a reception of a launch request to launch an application and receives a policy for a service, wherein the launch request includes an identifier of a workload within a customer infrastructure making the launch request and an identifier of the application; and

a processor configured to determine a customer security posture, at least in part based on the identifier of the workload, activities performed by the workload, and the identifier of the application, and to determine to deny the launch request, at least in part based on the policy and the customer security posture, wherein determining to deny the launch request includes determining whether the workload meets hardening rules and determining whether a checksum of the application matches a predetermined checksum and determining whether a risk score exceeds a predetermined value indicated in the policy, wherein the risk score is based on an evaluation of hardware running a virtual machine (VM) or container that produced the workload within the customer infrastructure.

2 . The apparatus of claim 1 , wherein the network interface receives an application programming interface (API) request for access to the service, the API request includes the identifier of the workload, and the processor further is configured to deny the access to the service, at least in part based on the policy and the customer security posture.

3 . The apparatus of claim 1 , wherein the network interface receives an access request for access to a vendor apparatus, the access request includes the identifier of the workload, and the processor further is configured to deny the access to the vendor apparatus, at least in part based on the policy and the customer security posture.

4 . The apparatus of claim 1 , wherein the network interface transmits a policy request, at least in part based on the reception of the launch request.

5 . The apparatus of claim 1 , wherein the processor further is configured to detect an event, and the network interface transmits an artifact of the event.

6 . The apparatus of claim 1 , wherein the network interface transmits policy management information including an identifier of the apparatus.

7 . The apparatus of claim 1 , wherein the processor further is configured to determine to allow a launch request, at least in part based on the policy and a customer security posture for another workload.

8 . A method, comprising:

receiving a launch request to launch an application including an identifier of a workload within a customer infrastructure making the launch request and an identifier of the application;

receiving a policy for a service;

determining a customer security posture, at least in part based on the identifier of the workload, activities performed by the workload, and the identifier of the application; and

determining to deny the launch request, at least in part based on the policy and the customer security posture, wherein determining to deny the launch request includes determining whether the workload meets hardening rules and determining whether a checksum of the application matches a predetermined checksum and determining whether a risk score exceeds a predetermined value indicated in the policy, wherein the risk score is based on an evaluation of hardware running a virtual machine (VM) or container that produced the workload within the customer infrastructure.

9 . The method of claim 8 , further comprising:

receiving an application programming interface (API) request for access to the service, the API request including the identifier of the workload; and

denying the access to the service, at least in part based on the policy and the customer security posture.

10 . The method of claim 8 , further comprising:

receiving an access request for access to a vendor apparatus, the access request including the identifier of the workload; and

denying the access to the vendor apparatus, at least in part based on the policy and the customer security posture.

11 . The method of claim 8 , further comprising:

transmitting a policy request, at least in part based on the receiving the launch request.

12 . The method of claim 8 , further comprising:

detecting an event; and

transmitting an artifact of the event.

13 . The method of claim 8 , further comprising:

transmitting policy management information including an identifier of an apparatus.

14 . The method of claim 8 , further comprising:

determining to allow a launch request, at least in part based on the policy and a customer security posture for another workload.

15 . A non-transitory, computer-readable medium encoded with executable instructions that, when executed by a processing unit, perform operations comprising:

receiving a launch request to launch an application, wherein the launch request includes an identifier of a workload within a customer infrastructure making the launch request and an identifier of the application;

receiving a policy for a service;

determining a customer security posture, at least in part based on the identifier of the workload, activities performed by the workload, and the identifier of the application; and

determining to deny the launch request, at least in part based on the policy and the customer security posture, wherein determining to deny the launch request includes determining whether the workload meets hardening rules and determining whether a checksum of the application matches a predetermined checksum and determining whether a risk score exceeds a predetermined value indicated in the policy, wherein the risk score is based on an evaluation of hardware running a virtual machine (VM) or container that produced the workload within the customer infrastructure exceeds.

16 . The medium of claim 15 , the operations further comprising:

receiving an application programming interface (API) request for access to the service, the API request including the identifier of the workload; and

denying the access to the service, at least in part based on the policy and the customer security posture.

17 . The medium of claim 15 , the operations further comprising:

receiving an access request for access to a vendor apparatus, the access request including the identifier of the workload; and

denying the access to the vendor apparatus, at least in part based on the policy and the customer security posture.

18 . The medium of claim 15 , the operations further comprising:

transmitting a policy request, at least in part based on the receiving the launch request.

19 . The medium of claim 15 , the operations further comprising:

detecting an event; and

transmitting an artifact of the event.

20 . The medium of claim 15 , the operations further comprising:

determining to allow a launch request, at least in part based on the policy and a customer security posture for another workload.

Assignments (7)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2023
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 063735/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2023
From: BHATTACHARYA, ANAMIKA; BHARADWAJ, DEEPAK; SEETHARAMAIAH, SRIRANGA; SANYAL, ABHISEK
To: MUSARUBRA US LLC
Reel/Frame 063487/0246 →
Priority Claims (1)
IN 202141017536 · Apr 15, 2021 · national
Continuity (1)
Related Publication 20220337631A1 · Oct 20, 2022
References Cited (9)
US 9973525B1 · Roturier · 2018 [cited by examiner]
US 10154007B1 · Viswanathan · 2018 [cited by examiner]
US 10382401B1 · Lee · 2019 [cited by examiner]
US 11170099B1 · Sandall · 2021 [cited by examiner]
US 11240109B2 · Andrews · 2022 [cited by examiner]
US 20150256341A1 · Ye · 2015 [cited by examiner]
US 20180026893A1 · Jeuk · 2018 [cited by examiner]
US 20190273746A1 · Coffing · 2019 [cited by examiner]
US 20220141254A1 · Oswal · 2022 [cited by examiner]