IP Library Granted Patent US 12,413,558
Granted Patent B2
US 12,413,558 · App. 18/089,930 · Granted Sep 9, 2025

Cloud-based zero trust network access service

Inventors: Robert Paul Andrews (Pflugerville, TX); Biju Ramachandra Kaimal (Bangalore, IN); Venkata Suresh Reddy Obulareddy (Bangalore, IN)
Assignee: Sophos Limited
H04L63/0281G06F21/53G06F21/64H04L41/12H04L61/302H04L63/0236H04L63/029H04L63/0823H04L63/083H04L63/0884H04L63/1425H04L63/20H04L67/1008H04L67/1036G06F2221/033H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,558
App. No.
18/089,930
Granted
Sep 9, 2025
Kind
B2
Abstract

Infrastructure for zero trust network access (ZTNA) is deployed as a cloud-based service remotely from a customer premises where user applications are hosted. By connecting an appliance on the customer premises to the cloud-based service through a secure tunnel or the like, an application hosted on the customer premises can then be accessed externally as a ZTNA application without the customer premises opening a firewall to public networks or otherwise exposing potential attack surfaces to the customer premises.

Claims (31)

1. A system for zero trust network access to a customer application comprising:

an application hosted on a customer premises;

a threat management facility configured to manage security for the customer premises;

a cloud computing platform hosted remotely from the customer premises, the cloud computing platform configured to provide a cloud-based data plane for zero trust network access to the application by a device operated by a user associated with the customer premises, the cloud computing platform including:

a service proxy configured to couple the device to the application hosted on the customer premises,

a reverse proxy server connected to the service proxy, the reverse proxy server configured to securely connect to the customer premises, and

an authentication server securely coupled to the threat management facility and configured to create a secure tunnel to the customer premises by authenticating a secure connection to the reverse proxy server; and

a zero trust network access appliance hosted on the customer premises, the zero trust network access appliance configured to initiate the secure connection to the reverse proxy server, and the zero trust network access appliance configured to operatively couple the application hosted on the customer premises through the cloud-based data plane to the device operated by the user.

2. The system of claim 1 , wherein the zero trust network access appliance is configured to authenticate the user for access to the application.

3. The system of claim 2 , wherein the zero trust network access appliance is configured to authenticate the user with a username and a password managed by the customer premises.

4. The system of claim 2 , wherein the zero trust network access appliance is configured to authenticate the user with two or more authentication factors.

5. The system of claim 2 , wherein the zero trust network access appliance authenticates the user with a third party identity management platform external to the customer premises.

6. The system of claim 1 , wherein the threat management facility is hosted remotely from the customer premises and coupled in a secure communicating relationship with the customer premises.

7. The system of claim 1 , wherein the threat management facility provides a control plane for zero trust network access to the application hosted on the customer premises.

8. The system of claim 1 , wherein the zero trust network access appliance is configured to:

make an outbound connection to the reverse proxy server of the cloud computing platform;

authenticate to the reverse proxy server with the authentication server;

establish the secure tunnel between the zero trust network access appliance and the reverse proxy server; and

use the secure tunnel to provide zero trust network access to the application hosted on the customer premises by the user of the device.

9. The system of claim 1 , wherein the threat management facility is configured to provide a user interface for administrative configuration of the zero trust network access appliance.

10. The system of claim 9 , wherein the user interface for administrative configuration is configured to receive a Domain name system record identifying an address for the cloud computing platform.

11. The system of claim 9 , wherein the zero trust network access appliance is user-configurable through the threat management facility to operate as either (a) a zero trust network access gateway exposed to a public network through a firewall for the customer premises or (b) a zero trust network access connector coupled through the secure tunnel to the cloud-based data plane hosted on the cloud computing platform.

12. The system of claim 1 , wherein the application is an agentless application.

13. The system of claim 1 , wherein the application is an agent-based application.

14. The system of claim 1 , wherein the cloud computing platform provides a network address for zero trust network access to the application from a public network.

15. The system of claim 1 , wherein the cloud computing platform provides a fully qualified domain name for zero trust network access to the application.

16. The system of claim 1 , further comprising a connector configured to selectively couple the application to external users through a firewall for the customer premises and a secure tunnel to the cloud-based data plane, wherein the connector authenticates the user accessing the application through the secure tunnel.

17. The system of claim 1 , wherein the threat management facility is hosted remotely from the customer premises and coupled in a secure communicating relationship with the customer premises and the cloud computing platform.

18. The system of claim 1 , wherein the zero trust network access appliance is configured to authenticate the user with at least one of a biometric authentication factor, a hardware-based authentication factor, or a software-based authentication factor.

19. The system of claim 1 , wherein the zero trust network access appliance is configured to authenticate the user with a heartbeat from a user device.

20. The system of claim 1 , wherein the cloud computing platform is configured to authenticate the user for zero trust network access to the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2023
From: ANDREWS, ROBERT PAUL; KAIMAL, BIJU RAMACHANDRA; OBULAREDDY, VENKATA SURESH REDDY
To: SOPHOS LIMITED
Reel/Frame 062383/0928 →
Priority Claims (1)
IN 202211058975 · Oct 15, 2022 · national
Continuity (2)
Continuation PCTUS2022054075 · Dec 27, 2022
Related Publication 20240129296A1 · Apr 18, 2024
References Cited (94)
US 8396969B1 · Schwartz et al. · 2013 [cited by applicant]
US 11240242B1 · Celik · 2022 [cited by examiner]
US 11689522B2 · Kulkarni et al. · 2023 [cited by applicant]
US 11783925B2 · Ansari · 2023 [cited by examiner]
US 11811734B2 · Chen et al. · 2023 [cited by applicant]
US 11895092B2 · Glazemakers et al. · 2024 [cited by applicant]
US 11949661B2 · Shah et al. · 2024 [cited by applicant]
US 12010141B1 · Mogra et al. · 2024 [cited by applicant]
US 12095794B1 · Karaje · 2024 [cited by examiner]
US 12101247B2 · Vysotsky et al. · 2024 [cited by applicant]
US 20120017259A1 · MacCarthaigh · 2012 [cited by examiner]
US 20120331528A1 · Fu et al. · 2012 [cited by applicant]
US 20170310693A1 · Howard et al. · 2017 [cited by applicant]
US 20180103009A1 · Eberlein · 2018 [cited by applicant]
US 20190158423A1 · Li et al. · 2019 [cited by applicant]
US 20190297079A1 · Delcourt et al. · 2019 [cited by applicant]
US 20200236112A1 · Pularikkal · 2020 [cited by examiner]
US 20200287869A1 · Glazemakers et al. · 2020 [cited by applicant]
US 20210029201A1 · Masurekar et al. · 2021 [cited by applicant]
US 20210075790A1 · Hebert · 2021 [cited by examiner]
US 20210160237A1 · Rozner et al. · 2021 [cited by applicant]
US 20210250333A1 · Negrea et al. · 2021 [cited by applicant]
US 20210336788A1 · Ziegler · 2021 [cited by examiner]
US 20210385221A1 · Nieman · 2021 [cited by applicant]
US 20210392111A1 · Sole et al. · 2021 [cited by applicant]
US 20220006805A1 · Kulkarni et al. · 2022 [cited by applicant]
US 20220046059A1 · Pandurangi et al. · 2022 [cited by applicant]
US 20220103527A1 · Niemi et al. · 2022 [cited by applicant]
US 20220141184A1 · Oswal et al. · 2022 [cited by applicant]
US 20220141254A1 · Oswal et al. · 2022 [cited by applicant]
US 20220210173A1 · Katmor et al. · 2022 [cited by applicant]
US 20220224621A1 · Devarajan et al. · 2022 [cited by applicant]
US 20220224622A1 · Kamath et al. · 2022 [cited by applicant]
US 20220224623A1 · Kamath et al. · 2022 [cited by applicant]
US 20220224703A1 · Devarajan · 2022 [cited by applicant]
US 20220272082A1 · Gupta et al. · 2022 [cited by applicant]
US 20220278917A1 · Voderbet et al. · 2022 [cited by applicant]
US 20220345463A1 · Wu et al. · 2022 [cited by applicant]
US 20220393943A1 · Pangeni et al. · 2022 [cited by applicant]
US 20220394083A1 · Pangeni et al. · 2022 [cited by applicant]
US 20220400114A1 · Sreedhar et al. · 2022 [cited by applicant]
US 20220400116A1 · Sreedhar et al. · 2022 [cited by applicant]
US 20220407840A1 · Chen et al. · 2022 [cited by applicant]
US 20230049547A1 · Glazemakers et al. · 2023 [cited by applicant]
US 20230069738A1 · Sreedhar et al. · 2023 [cited by applicant]
US 20230115982A1 · Lin et al. · 2023 [cited by applicant]
US 20230122630A1 · Balaiah et al. · 2023 [cited by applicant]
US 20230139695A1 · Xu · 2023 [cited by examiner]
US 20230188505A1 · Jensen · 2023 [cited by applicant]
US 20230198764A1 · Panicker et al. · 2023 [cited by applicant]
US 20230229787A1 · Mahdavipour et al. · 2023 [cited by applicant]
US 20230239297A1 · McElhoe et al. · 2023 [cited by applicant]
US 20230247003A1 · Chanak et al. · 2023 [cited by applicant]
US 20230254318A1 · Hu et al. · 2023 [cited by applicant]
US 20230269252A1 · Bakke · 2023 [cited by applicant]
US 20230328063A1 · Li et al. · 2023 [cited by applicant]
US 20230353543A1 · Solanki et al. · 2023 [cited by applicant]
US 20230362202A1 · Li et al. · 2023 [cited by applicant]
US 20230367605A1 · Bedi et al. · 2023 [cited by applicant]
US 20230379405A1 · Chhabra · 2023 [cited by applicant]
US 20230403282A1 · Smith et al. · 2023 [cited by applicant]
US 20230403304A1 · Balmakhtar et al. · 2023 [cited by applicant]
US 20240031337A1 · Sharma et al. · 2024 [cited by applicant]
US 20240031413A1 · Oswal et al. · 2024 [cited by applicant]
US 20240048564A1 · Sreedhar et al. · 2024 [cited by applicant]
US 20240064138A1 · Jain · 2024 [cited by examiner]
US 20240073236A1 · Schumacher · 2024 [cited by applicant]
US 20240073694A1 · Srinivas et al. · 2024 [cited by applicant]
US 20240080744A1 · Hotchkiss et al. · 2024 [cited by applicant]
US 20240103932A1 · Hebbar et al. · 2024 [cited by applicant]
US 20240126868A1 · Andrews et al. · 2024 [cited by applicant]
US 20240129277A1 · Andrews et al. · 2024 [cited by applicant]
US 20240129278A1 · Andrews et al. · 2024 [cited by applicant]
US 20240129297A1 · Obulareddy et al. · 2024 [cited by applicant]
US 20240129298A1 · Obulareddy et al. · 2024 [cited by applicant]
US 20240129310A1 · Andrews et al. · 2024 [cited by applicant]
US 20240171555A1 · Chen et al. · 2024 [cited by applicant]
US 20240205231A1 · Bardhan et al. · 2024 [cited by applicant]
US 20240214350A1 · Sole et al. · 2024 [cited by applicant]
US 20240289264A1 · Desai · 2024 [cited by applicant]
US 20240414160A1 · Bakke · 2024 [cited by applicant]
WO WO2020180776 · 2020 [cited by applicant]
WO WO2024081014 · 2024 [cited by applicant]
EPO Searching Authority, , “PCT Application No. PCT/US22/054075 International Search Report and Written Opinion mailed Jul. 3, 2023”, , 15 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/089,946 Non-Final Office Action mailed Sep. 23, 2024”, 10 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/089,997 Non-Final Office Action mailed Nov. 6, 2024”, 11 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/090,025 Non-Final Office Action mailed Nov. 7, 2024”, 36 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/089,946 Notice of Allowance mailed Jan. 21, 2025”, 8 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/089,967 Non-Final Office Action mailed Dec. 23, 2024”, 24 pages. [cited by applicant]
Dasher, et al., “Architectures for Protecting Cloud Data Plane”, Jan. 31, 2022 , 43 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/089,967 Notice of Allowance mailed Apr. 28, 2025”, 15 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/090,009 Non-Final Office Action mailed Mar. 27, 2025”, 15 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/090,025 Final Office Action mailed Apr. 18, 2025”, 45 pages. [cited by applicant]
WIPO, , “PCT Application No. PCT/US22/54075 International Preliminary Report on Patentability mailed Apr. 24, 2025”, 10 pages. [cited by applicant]