IP Library › Granted Patent US 12,464,356
Granted Patent B2
US 12,464,356 · App. 18/237,314 · Granted Nov 4, 2025

Systems and methods for multiple point SASE access control

Inventors: Michael Xie (Palo Alto, CA); Yong Zhang (Belmont, CA); Reuben Stanley Wilson (Oswestry, GB)
Assignee: Fortinet, Inc.
H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,356
App. No.
18/237,314
Granted
Nov 4, 2025
Kind
B2
Abstract

Various systems, devices, storage media, and methods are discussed for performing secured access service edge (SASE) processing in a network potentially having multiple SASE processing capable devices.

Claims (59)

1 . A wireless access point device, the device comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, and having stored therein instructions that when executed by the processing resource cause the processing resource to:

upon determining that at least one other secured access service edge (SASE) processing capable device exists in a secure network, arbitrate with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing;

upon determining that the wireless access point is the only SASE processing capable device in the secure network, identify the wireless access point as selected to perform SASE processing;

receive a network traffic; and

where the wireless access point is identified as selected to perform SASE processing, provide a subset of the network traffic to a SASE service provider for processing.

2 . The device of claim 1 , wherein the non-transitory computer-readable medium has stored therein instructions that when executed by the processing resource further cause the processing resource to:

determine whether another SASE processing capable device exists in the secure network that includes the wireless access point.

3 . The device of claim 1 , wherein the non-transitory computer-readable medium has stored therein instructions that when executed by the processing resource further cause the processing resource to:

receive an indication from the SASE service provider that the network traffic is safe; and

open a network session corresponding to the network traffic.

4 . The device of claim 1 , wherein the non-transitory computer-readable medium has stored therein instructions that when executed by the processing resource further cause the processing resource to:

where the at least one other SASE processing capable device is selected to perform SASE processing; and

forwarding the network traffic to the at least one other SASE processing capable device.

5 . The device of claim 1 , wherein the at least one other SASE processing capable device is selected from a group consisting of: a network security appliance, and a network switch.

6 . The device of claim 1 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing includes:

determining if the wireless access point is a gateway for outgoing network traffic from the secure network to an unsecure network; and

upon determining that the wireless access point is the gateway for outgoing network traffic from the secure network to the unsecure network, identifying the wireless access point as selected to perform SASE processing.

7 . The device of claim 6 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing further includes:

sending a message from the wireless access point to the at least one other SASE processing capable device indicating that the wireless access point is selected to perform SASE processing.

8 . The device of claim 1 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing includes:

determining if the wireless access point is a gateway for outgoing network traffic from the secure network to an unsecure network; and

upon determining that the at least one other SASE processing capable device is the gateway for outgoing network traffic from the secure network to the unsecure network, identifying the at least one other SASE processing capable device as selected to perform SASE processing.

9 . The device of claim 8 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing further includes:

sending a message from the at least one other SASE processing capable device to the wireless access point indicating that the at least one other SASE processing capable device is selected to perform SASE processing.

10 . A method for performing secured access service edge (SASE) processing, the method comprising:

determining, by a wireless access point in a secure network, whether another SASE processing capable device exists in the secure network;

upon determining that at least one other SASE processing capable device exists in the secure network, arbitrating, by the wireless access point, with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing;

upon determining that the wireless access point is the only SASE processing capable device in the secure network, identifying, by the wireless access point, the wireless access point as selected to perform SASE processing;

receiving, by the wireless access point, a network traffic; and

where the wireless access point is identified as selected to perform SASE processing, providing, by the wireless access point, a subset of the network traffic to a SASE service provider for processing.

11 . The method of claim 10 , the method further including:

where the at least one other SASE processing capable device is selected to perform SASE processing, forwarding, by the wireless access point, the network traffic to the at least one other SASE processing capable device.

12 . The method of claim 10 , wherein the at least one other SASE processing capable device is selected from a group consisting of: a network security appliance, and a network switch.

13 . The method of claim 10 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing includes:

determining if the wireless access point is a gateway for outgoing network traffic from the secure network to an unsecure network; and

upon determining that the wireless access point is the gateway for outgoing network traffic from the secure network to the unsecure network, identifying the wireless access point as selected to perform SASE processing.

14 . The method of claim 13 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing further includes:

sending a message from the wireless access point to the at least one other SASE processing capable device indicating that the wireless access point is selected to perform SASE processing.

15 . The method of claim 10 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing includes:

determining if the wireless access point is a gateway for outgoing network traffic from the secure network to an unsecure network; and

upon determining that the at least one other SASE processing capable device is the gateway for outgoing network traffic from the secure network to the unsecure network, identifying the at least one other SASE processing capable device as selected to perform SASE processing.

16 . The method of claim 15 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing further includes:

sending a message from the at least one other SASE processing capable device to the wireless access point indicating that the at least one other SASE processing capable device is selected to perform SASE processing.

17 . A non-transitory computer-readable medium, the non-transitory computer readable medium having stored therein instructions that when executed by a processing resource cause the processing resource to perform a method comprising:

upon determining that at least one other secured access service edge (SASE) processing capable device exists in a secure network, arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing;

upon determining that the wireless access point is the only SASE processing capable device in the secure network, identifying the wireless access point as selected to perform SASE processing;

receiving a network traffic; and

where the wireless access point is identified as selected to perform SASE processing, providing a subset of the network traffic to a SASE service provider for processing.

18 . The non-transitory computer-readable medium of claim 17 , wherein the non-transitory computer-readable medium has stored therein instructions that when executed by the processing resource further cause the processing resource to:

determine whether another SASE processing capable device exists in the secure network that includes the wireless access point.

19 . The non-transitory computer-readable medium of claim 17 , wherein the non-transitory computer-readable medium has stored therein instructions that when executed by the processing resource further cause the processing resource to:

receive an indication from the SASE service provider that the network traffic is safe; and

open a network session corresponding to the network traffic.

20 . The non-transitory computer-readable medium of claim 17 , wherein arbitrating with the at least one other SASE processing capable device to identify which of the wireless access point or the at least one other SASE processing capable device is selected to perform SASE processing includes:

determining if the wireless access point is a gateway for outgoing network traffic from the secure network to an unsecure network;

upon determining that the wireless access point is the gateway for outgoing network traffic from the secure network to the unsecure network, identifying the wireless access point as selected to perform SASE processing; and

sending a message from the wireless access point to the at least one other SASE processing capable device indicating that the wireless access point is selected to perform SASE processing.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2023
From: XIE, MICHAEL; ZHANG, YONG; WILSON, REUBEN STANLEY
To: FORTINET, INC.
Reel/Frame 064684/0820 →
Continuity (1)
Related Publication 20250071552A1 · Feb 27, 2025
References Cited (2)
US 20240214424A1 · Ossipov · 2024 [cited by examiner]
US 20240214425A1 · Ossipov · 2024 [cited by examiner]