IP Library Granted Patent US 12,513,111
Granted Patent B2
US 12,513,111 · App. 18/210,569 · Granted Dec 30, 2025

Firewall access rule authenticated by security assertion markup language (SAML)

Inventors: Riji Cai (Milpitas, CA); Hao Zhang (Milpitas, CA); Rui Zheng (Milpitas, CA)
Assignee: SonicWALL Inc.
H04L63/0209H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,111
App. No.
18/210,569
Granted
Dec 30, 2025
Kind
B2
Abstract

Disclosed are systems, apparatuses, methods, computer readable medium, and circuits for providing access to a network. According to at least one example, a method includes: intercepting a request at a firewall the request sent from a computing device regarding establishment of a secure communication session with a network; in response to determining that the request is unauthenticated, notifying a service provider node of the request, wherein the service provider node is configured to: generating a communication session between the computing device and a RBI server; receiving at the firewall authentication information pertaining to authorization for the computing device to establish the secure communication session with the network; identifying that the secure communication session is allowed to be established based on the authentication information; and providing access at the firewall to the computing device to establish the secure communication session with the network.

Claims (40)

1 . A method for providing access to a network, the method comprising:

intercepting a request at a firewall that resides in a private network, wherein the request is unauthenticated, sent from a computing device, and corresponds to a plurality of security assertion markup language (SAML) requests;

identifying the computing device by an identity provider node in a public network, wherein the identity provider node identifies the computing device for verification prior to authenticating the computing device for access; and

notifying a service provider node of the request, wherein the service provider node verifies the request by:

generating a communication session between the computing device and a remote browser isolation (RBI) server;

receiving, at the firewall, authentication information pertaining to authorization for the computing device to establish a secure communication session with the private network;

identifying that the secure communication session is allowed to be established based on the authentication information; and

providing the computing device with authorization to establish the secure communication session and access the private network.

2 . The method of claim 1 , wherein the request is a resource request.

3 . The method of claim 2 , wherein the resource request further includes an authentication request to connect to the private network.

4 . The method of claim 3 , wherein the RBI server communicates with the identity provider node, and wherein the identity provider node verifies the authentication request prior to the authorization of the computing device to establish the secure communication session with the private network.

5 . The method of claim 1 , wherein intercepting the request is based on determining that one or more access rules associated with the firewall are invoked.

6 . The method of claim 1 , further comprising generating a secure redirect weblink that redirects to the RBI server; and transmitting the secure redirect weblink to a browser of the computing device.

7 . The method of claim 6 , wherein the secure redirect weblink includes an address of the RBI server.

8 . The method of claim 1 , further comprising prompting the computing device for the authentication information, and transmitting the authentication information to an identity provider node via the firewall.

9 . The method of claim 1 , wherein the private network further includes the computing device.

10 . A non-transitory computer-readable storage medium, the non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for providing access to a network, the method comprising:

intercepting a request at a firewall that resides in a private network, wherein the request is unauthenticated, sent from a computing device, and corresponds to a plurality of security assertion markup language (SAML) requests;

identifying the computing device by an identity provider node configured in a public network, wherein the identity provider node identifies the computing device for verification prior to authenticating the computing device for access; and

notifying a service provider node of the request, wherein the service provider node verifies the request by:

generating a communication session between the computing device and a remote browser isolation (RBI) server;

receiving, at the firewall, authentication information pertaining to authorization for the computing device to establish a secure communication session with the private network;

identifying that the secure communication session is allowed to be established based on the authentication information; and

providing the computing device with authorization to establish the secure communication session and access the private network.

11 . The non-transitory computer-readable storage medium of claim 10 , wherein the request is a resource request.

12 . The non-transitory computer-readable storage medium of claim 11 , wherein the resource request further includes an authentication request to connect to the private network.

13 . The non-transitory computer-readable storage medium of claim 12 , wherein the RBI server communicates with the identity provider node, and wherein the identity provider node verifies the authentication request prior to the authorization, of the computing device to establish the secure communication session with the private network.

14 . The non-transitory computer-readable storage medium of claim 10 , wherein intercepting the request is based on determining that one or more access rules associated with the firewall are invoked.

15 . The non-transitory computer-readable storage medium of claim 10 , further comprising instructions executable to generate a secure redirect weblink that redirects to the RBI server and to transmit the secure redirect weblink to a browser of the computing device.

16 . The non-transitory computer-readable storage medium of claim 15 , wherein the secure redirect weblink includes an address of the RBI server.

17 . The non-transitory computer-readable storage medium of claim 10 , further comprising instructions executable to prompt the computing device for the authentication information, and to transmit the authentication information to an identity provider node via the firewall.

18 . The non-transitory computer-readable storage medium of claim 10 , wherein the private network further includes the computing device.

19 . A system for providing access to a network, the system comprising:

a firewall that resides in a private network, wherein the firewall intercepts a request that is unauthenticated, sent from a computing device, and corresponds to a plurality of security assertion markup language (SAML) requests;

an identity provider node in a public network, wherein the identity provider node identifies the computing device for verification prior to authenticating the computing device for access; and

a service provider node that is notified of the request and verifies the request by:

generating a communication session between the computing device and a remote browser isolation (RBI) server, wherein the firewall receives authentication information pertaining to authorization for the computing device to establish a secure communication session with the private network,

identifying that the secure communication session is allowed to be established based on the authentication information, and

providing the computing device with authorization to establish the secure communication session and access the private network.

20 . The system of claim 19 , wherein the request is a resource request.

Assignments (2)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071758/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: ZHANG, HOA; ZHENG, RUI; CAI, BRUCE
To: SONICWALL INC.
Reel/Frame 065257/0751 →
Continuity (1)
Related Publication 20240422125A1 · Dec 19, 2024
References Cited (94)
US 7185361B1 · Ashoff · 2007 [cited by examiner]
US 7305705B2 · Shelest · 2007 [cited by examiner]
US 8484716B1 · Hodgson · 2013 [cited by examiner]
US 8850546B1 · Field · 2014 [cited by examiner]
US 9137131B1 · Sarukkai · 2015 [cited by examiner]
US 9661083B1 · Eykholt · 2017 [cited by examiner]
US 9729539B1 · Agrawal · 2017 [cited by examiner]
US 10148621B2 · Benari · 2018 [cited by examiner]
US 10798059B1 · Singh · 2020 [cited by examiner]
US 10944561B1 · Cahill · 2021 [cited by examiner]
US 11240205B1 · Ramesh · 2022 [cited by examiner]
US 11258756B2 · Huang · 2022 [cited by examiner]
US 11579955B1 · Wilson · 2023 [cited by examiner]
US 11593606B1 · LaBorde · 2023 [cited by examiner]
US 11863530B1 · Sreekumar · 2024 [cited by examiner]
US 12058137B1 · Hanwella · 2024 [cited by examiner]
US 20050268333A1 · Betts · 2005 [cited by examiner]
US 20080028445A1 · Dubuc · 2008 [cited by examiner]
US 20110252462A1 · Bonanno · 2011 [cited by examiner]
US 20120110469A1 · Magarshak · 2012 [cited by examiner]
US 20120214444A1 · McBride · 2012 [cited by examiner]
US 20140223532A1 · Satoh · 2014 [cited by examiner]
US 20140297863A1 · Zhu · 2014 [cited by examiner]
US 20140298419A1 · Boubez · 2014 [cited by examiner]
US 20150039677A1 · Kahol · 2015 [cited by examiner]
US 20150200926A1 · Fukuda · 2015 [cited by examiner]
US 20160094546A1 · Innes · 2016 [cited by examiner]
US 20160162988A1 · Englehart · 2016 [cited by examiner]
US 20160217312A1 · Gardiner · 2016 [cited by examiner]
US 20160234209A1 · Kahol · 2016 [cited by examiner]
US 20170004500A1 · Lim · 2017 [cited by examiner]
US 20170063927A1 · Schultz · 2017 [cited by examiner]
US 20170142129A1 · Peng · 2017 [cited by examiner]
US 20180007059A1 · Innes · 2018 [cited by examiner]
US 20180097840A1 · Murthy · 2018 [cited by examiner]
US 20180115547A1 · Peterson · 2018 [cited by examiner]
US 20180198791A1 · Desai · 2018 [cited by examiner]
US 20180227759A1 · Liu · 2018 [cited by examiner]
US 20180302391A1 · Jones · 2018 [cited by examiner]
US 20180367499A1 · Bansal · 2018 [cited by examiner]
US 20190007409A1 · Totale · 2019 [cited by examiner]
US 20190081927A1 · Pham · 2019 [cited by examiner]
US 20190245848A1 · Divoux · 2019 [cited by examiner]
US 20190319946A1 · Fan · 2019 [cited by examiner]
US 20190386980A1 · Kludy · 2019 [cited by examiner]
US 20200036699A1 · Suresh · 2020 [cited by examiner]
US 20200045015A1 · Nukala · 2020 [cited by examiner]
US 20200099658A1 · Couillard · 2020 [cited by examiner]
US 20200145420A1 · Haletky · 2020 [cited by examiner]
US 20200177596A1 · Grobelny · 2020 [cited by examiner]
US 20200314066A1 · Cruz Farmer · 2020 [cited by examiner]
US 20210029146A1 · Kancherla · 2021 [cited by examiner]
US 20210075811A1 · Gupta · 2021 [cited by examiner]
US 20210075832A1 · Bisztrai · 2021 [cited by examiner]
US 20210165879A1 · Duo · 2021 [cited by examiner]
US 20210166515A1 · Durham, III · 2021 [cited by examiner]
US 20210250333A1 · Negrea · 2021 [cited by applicant]
US 20210314310A1 · Cao · 2021 [cited by examiner]
US 20210349867A1 · Faber · 2021 [cited by examiner]
US 20220100827A1 · Nomura · 2022 [cited by examiner]
US 20220150066A1 · Sugarev · 2022 [cited by examiner]
US 20220188438A1 · Lewin · 2022 [cited by examiner]
US 20220200990A1 · Madej · 2022 [cited by examiner]
US 20220215005A1 · Bidkar · 2022 [cited by examiner]
US 20220217124A1 · Fryer · 2022 [cited by examiner]
US 20220337590A1 · Jaiswal · 2022 [cited by examiner]
US 20220407850A1 · Blasi · 2022 [cited by examiner]
US 20220417216A1 · Elliott · 2022 [cited by examiner]
US 20230022478A1 · Batchu · 2023 [cited by applicant]
US 20230088489A1 · Szczepanik · 2023 [cited by examiner]
US 20230129776A1 · Agarwal · 2023 [cited by examiner]
US 20230145127A1 · Barnum · 2023 [cited by examiner]
US 20230164178A1 · Singh · 2023 [cited by examiner]
US 20230229752A1 · Brooks · 2023 [cited by examiner]
US 20230247003A1 · Chanak · 2023 [cited by examiner]
US 20230328091A1 · Proynov · 2023 [cited by examiner]
US 20230379265A1 · Masters · 2023 [cited by examiner]
US 20230409680A1 · Blachman · 2023 [cited by examiner]
US 20240004673A1 · Liu · 2024 [cited by examiner]
US 20240012904A1 · Goradia · 2024 [cited by examiner]
US 20240022555A1 · Koikara · 2024 [cited by examiner]
US 20240036892A1 · Goradia · 2024 [cited by examiner]
US 20240098102A1 · Sloane · 2024 [cited by examiner]
US 20240223534A1 · Gu · 2024 [cited by examiner]
US 20240291837A1 · Levari · 2024 [cited by examiner]
US 20240333734A1 · Barton · 2024 [cited by examiner]
US 20240356901A1 · Spillman · 2024 [cited by examiner]
US 20240380737A1 · Brown · 2024 [cited by examiner]
US 20240388589A1 · Venkatesan · 2024 [cited by examiner]
US 20250039161A1 · Gangadharappa · 2025 [cited by examiner]
US 20250047656A1 · Chen · 2025 [cited by examiner]
EP 241825819 · 2024 [cited by applicant]
EP 4478665 · 2024 [cited by applicant]
EP Application No. 24182581.9, Extended European Search Report dated Oct. 21, 2024. [cited by applicant]