IP Library › Granted Patent US 12,231,433
Granted Patent B2
US 12,231,433 · App. 18/311,054 · Granted Feb 18, 2025

Policy-based secure communication session using direct link and digitally segregated secure tunnels

Inventor: James S. Robinson (Indianapolis, IN)
Assignee: Netskope, Inc.
H04L63/102H04L63/0435H04L63/20H04L67/141H04L67/561
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,433
App. No.
18/311,054
Granted
Feb 18, 2025
Kind
B2
Abstract

A policy-based security system for establishing a secure session from client devices to a web server includes a policy component with policies, a client device with a local application to select a cloud service, and a mid-link server. A set of policies is determined based on parameters and a tag of a shared content between the client device and the web server for the cloud service. The set of policies selectively direct traffic to the mid-link server based on the tag, and the set of policies specify a direct link between the client device and the web server if the client device satisfies security standards or a secure tunnel between the client device and the mid-link server for the secure session based on the client device does not satisfy the security standards. The secure session establishes the secure session for the cloud service and for providing the shared content.

Claims (60)

1. A policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server, the policy-based security system comprising:

a policy component comprising a plurality of policies, wherein:

the plurality of policies is based on a set of parameters, and

the plurality of policies specifies configuration settings of a plurality of secure tunnels and a plurality of session protocols,

a client device with a local application configured to execute on the client device, the local application is further configured to select a cloud service from a plurality of cloud services for shared content,

a data classifier identifies a tag associated with the shared content, wherein the shared content is to be provided between a client device and the web server,

a mid-link server, coupled to the plurality of specified secure tunnels, the mid-link server comprising:

a policy enforcer configured to determine a set of policies from the plurality of policies for the client device based on the set of parameters and the identified tag, wherein the set of determined policies selectively direct traffic to the mid-link server based on the identified tag of the shared content, and wherein (a) if the client device satisfies security standards the set of determined policies specify a direct link between the client device and the web server and (b) if the client device does not satisfy the security standards, the set of determined policies specify to establish a secure session of a secure tunnel from the plurality of specified secure tunnels between the client device and the mid-link server; and

a router configured to establish via an encryption link a secure session of the client device with the web server for providing the shared content using:

a session protocol from the set of session protocols based on the direct link; or

a tunnel protocol based on the secure tunnel.

2. The policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server as recited in claim 1 , wherein the secure tunnel from the plurality of secure tunnels and the session protocol from the plurality of session protocols to establish the secure session between the client device and the web server in accordance with the set of policies is based on a remote instance and/or an application for access to the cloud service.

3. The policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server as recited in claim 1 , wherein the secure session between the client device and the web server is established based on the parameters of the set of policies meeting a predetermined threshold value.

4. The policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server as recited in claim 1 , wherein the set of parameters include at least one of a user connection, a user application, a user location, a type of source, a source location, a destination, a destination location, a destination connection, a destination application, an application type, a type of shared content, confidentiality of the shared content, network data traffic, metadata, user role, user team, user and entity behavior analytics (UEBA) information, and/or user residency.

5. The policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server as recited in claim 1 , wherein the tag is metadata associated with a type of the shared content, and the shared content is classified based on the metadata.

6. The policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server as recited in claim 1 , wherein the set of policies are determined by an administrator of an enterprise associated with the client device based on a user group, the enterprise, or a user role, and the policy enforcer is further configured to determine the set of policies based on device profiling of the client device.

7. The policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server as recited in claim 1 , wherein the set of policies are modified when the secure tunnel is used for connection instead of the direct link using Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS) protocols.

8. The policy-based security system for establishing a direct link or a secure tunnel from client devices to remote instances on a web server as recited in claim 1 , wherein an administrator of an enterprise associated with the client device receives and analyzes:

log reports of the secure session of the client device with the web server, and

alerts of non-connected client devices,

wherein:

the log reports include client reports on a plurality of client devices for compliance with the plurality of policies, and analytics on usage of the plurality of cloud services on the plurality of client devices, and

the set of policies are modified for the secure session based on an update and/or an upgrade of the session protocol or the secure tunnel.

9. A method for establishing policy-based security for a secure session between a plurality of client devices and a web server in cloud-based multi-tenant systems, the method comprising:

identifying a tag associated with a shared content, wherein the shared content is to be provided between a client device and the web server;

provisioning on a mid-link server, coupled to a plurality of secure tunnels, between the client device and the web server, the set of policies;

determining a set of policies for a client device of the plurality of client devices with a policy component having a plurality of policies, wherein:

the set of policies from the plurality of policies are determined based on a set of parameters and the identified tag,

the set of policies specify configuration settings of a plurality of secure tunnels and a plurality of session protocols, and

the set of determined policies selectively direct traffic to the mid-link server based on the identified tag of the shared content, and wherein (a) if the client device satisfies security standards the set of determined policies specify a direct link between the client device and the web server and (b) if the client device does not satisfy the security standards, the set of determined policies specify to establish a secure session of a secure tunnel from the plurality of specified secure tunnels between the client device and the mid-link server;

receiving from a local application running on the client device of the plurality of client devices, selection of a cloud service from a plurality of cloud services for providing the shared content;

provisioning on a mid-link server between the client device and the web server, the set of policies;

determining an encryption link of a plurality of encryption links specified for the set of policies and the cloud service, wherein the plurality of encryption links deliver the cloud service to the client device;

selecting a set of session protocols from the plurality of session protocols for establishing a secure session between the client device and the web server in accordance with the set of policies; and

establishing via the encryption link a secure session of the client device with the web server for providing the shared content using:

a session protocol from the set of session protocols based on the selection of the direct link, or

a tunnel protocol based on the selection of the secure tunnel.

10. The method for establishing policy-based security for a secure session between a plurality of client devices and a web server in cloud-based multi-tenant systems as recited in claim 9 , wherein the secure tunnel from the plurality of secure tunnels and the session protocol from the plurality of session protocols to establish the secure session between the client device and the web server in accordance with the set of policies is based on a remote instance and/or an application for access to the cloud service.

11. The method for establishing policy-based security for a secure session between a plurality of client devices and a web server in cloud-based multi-tenant systems as recited in claim 9 , wherein the secure session between the client device and the web server is established based on the parameters of the set of policies meeting a predetermined threshold value.

12. The method for establishing policy-based security for a secure session between a plurality of client devices and a web server in cloud-based multi-tenant systems as recited in claim 9 , wherein the set of parameters include at least one of a user connection, a user application, a user location, a type of source, a source location, a destination, a destination location, a destination connection, a destination application, an application type, a type of shared content, confidentiality of the shared content, network data traffic, metadata, user role, user team, user and entity behavior analytics (UEBA) information, and/or user residency.

13. The method for establishing policy-based security for a secure session between a plurality of client devices and a web server in cloud-based multi-tenant systems as recited in claim 9 , wherein shared content between the client device and the web server is labeled with tags, the tags are metadata associated with a type of the shared content, the shared content is classified based on the metadata, and the set of policies are determined based on the tags.

14. The method for establishing policy-based security for a secure session between a plurality of client devices and a web server in cloud-based multi-tenant systems as recited in claim 9 , wherein the set of policies are determined by an administrator of an enterprise associated with the client device based on a user group, the enterprise, or a user role.

15. The method for establishing policy-based security for a secure session between a plurality of client devices and a web server in cloud-based multi-tenant systems as recited in claim 9 , further comprising a policy enforcer configured to determine the set of policies based on device profiling of the client device.

16. A policy-controlled communication system including client devices establishing a secure session with remote instances on a web server using an encryption protocol, the policy-controlled communication system comprising a plurality of servers, collectively having code for:

identifying a tag associated with a shared content, wherein the shared content is to be provided between a client device and the web server;

provisioning on a mid-link server, coupled to a plurality of secure tunnels, between the client device and the web server, the set of policies;

determining a set of policies for a client device of a plurality of client devices with a policy component having a plurality of policies, wherein:

the set of policies from the plurality of policies are determined based on a set of parameters and the identified tag,

the set of policies specify configuration settings of a plurality of secure tunnels and a plurality of session protocols, and

the set of determined policies selectively direct traffic to the mid-link server based on the identified tag of the shared content, and wherein (a) if the client device satisfies security standards the set of determined policies specify a direct link between the client device and the web server and (b) if the client device does not satisfy the security standards, the set of determined policies specify to establish a secure session of a secure tunnel from the plurality of specified secure tunnels between the client device and the mid-link server;

receiving from a local application running on the client device of the plurality of client devices, selection of a cloud service from a plurality of cloud services for providing the shared content;

determining an encryption link of a plurality of encryption links specified for the set of policies and the cloud service, wherein the plurality of encryption links deliver the cloud service to the client device;

selecting a set of session protocols from the plurality of session protocols for establishing the secure session between the client device and the web server in accordance with the set of policies; and

establishing via the encryption link a secure session of the client device with the web server for providing the shared content using:

a session protocol from the set of session protocols based on the direct link, or

a tunnel protocol based on the secure tunnel.

17. The policy-controlled communication system with the client devices establishing the secure session with the remote instances on the web server using the encryption protocol as recited in claim 16 , wherein the secure tunnel from the plurality of secure tunnels and the session protocol from the plurality of session protocols to establish the secure session between the client device and the web server in accordance with the set of policies is based on a remote instance and/or an application for access to the cloud service.

18. The policy-controlled communication system with the client devices establishing the secure session with the remote instances on the web server using the encryption protocol as recited in claim 16 , wherein the secure session between the client device and the web server is established based on the parameters of the set of policies meeting a predetermined threshold value.

19. The policy-controlled communication system with the client devices establishing the secure session with the remote instances on the web server using the encryption protocol as recited in claim 16 , wherein the set of parameters include at least one of a user connection, a user application, a user location, a type of source, a source location, a destination, a destination location, a destination connection, a destination application, an application type, a type of shared content, confidentiality of the shared content, network data traffic, metadata, user role, user team, user and entity behavior analytics (UEBA) information, and/or user residency.

20. The policy-controlled communication system with the client devices establishing the secure session with the remote instances on the web server using the encryption protocol as recited in claim 16 , wherein shared content between the client device and the web server is labeled with tags, the tags are metadata associated with a type of the shared content, the shared content is classified based on the metadata, and the set of policies are determined based on the tags.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2023
From: ROBINSON, JAMES S.
To: NETSKOPE, INC.
Reel/Frame 063512/0828 →
Continuity (4)
Continuation 17985733 · Nov 11, 2022
Continuation In Part 17549638 · Dec 13, 2021
Continuation 17331516 · May 26, 2021
Related Publication 20230269254A1 · Aug 24, 2023
References Cited (128)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9087189B1 · Koeten et al. · 2015 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9749292B2 · Martini · 2017 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10798558B2 · Raleigh et al. · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11005682B2 · Chang et al. · 2021 [cited by applicant]
US 11019106B1 · Harvell · 2021 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11134104B2 · Qureshi et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11546358B1 · Robinson et al. · 2023 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130005299A1 · Raleigh · 2013 [cited by examiner]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160006765A1 · Shem Tov · 2016 [cited by examiner]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20190173895A1 · Scales · 2019 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200053051A1 · Medappa et al. · 2020 [cited by applicant]
US 20200220746A1 · Shribman et al. · 2020 [cited by applicant]
US 20210250333A1 · Negrea et al. · 2021 [cited by applicant]
US 20220366050A1 · Ben-Noon et al. · 2022 [cited by applicant]
US 20220385669A1 · Robinson · 2022 [cited by applicant]
US 20230089132A1 · Robinson · 2023 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
EP 2854347A2 · 2015 [cited by applicant]
EP 3690649A1 · 2020 [cited by applicant]
JP 2010123115A · 2010 [cited by applicant]
JP 2019096339A · 2019 [cited by applicant]
WO 0131855A2 · 2001 [cited by applicant]
WO 2012048210A1 · 2012 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff Ending Clear Text Protocols,' Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Nevvton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al. “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., 'Farsite: Federated, available, and reliable storage for an incompletely trusted environment, SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al. , Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.htm#:˜:text=mode of communication.-,What are the different email protocol… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” Tech Target, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?% 20Off… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1 , Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/%2010.1007/978-3-319… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al. “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs,. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]