IP Library › Granted Patent US 12,556,581
Granted Patent B2
US 12,556,581 · App. 18/318,617 · Granted Feb 17, 2026

Policy based privileged remote access in zero trust private networks

Inventors: Dejan Mihajlovic (Sunnyvale, CA); Clifford Kahn (Sarasota, FL); Abhijeet Malik (San Jose, CA); Sandip Davara (San Jose, CA); Sunita Darbarwar (San Jose, CA); Srinivas Sannapareddy (San Jose, CA); Gana Ramachandra (San Jose, CA); William Fehring (Sunnyvale, CA); Jian Liu (Fremont, CA); John A. Chanak (Saratoga, CA); Sunil Menon (Los Gatos, CA)
Assignee: Zscaler, Inc.
H04L63/20H04L9/40H04L47/125H04L63/0823H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,581
App. No.
18/318,617
Filed
May 16, 2023
Granted
Feb 17, 2026
Kind
B2
Art Unit
2439
USPC
726/1
Abstract

Systems and methods for policy based privileged remote access in zero trust private networks. Various embodiments include receiving a request to an end system; determining available end systems based on one or more criteria associated with the request, wherein the one or more criteria are analyzed based on policy; and providing access to the end system based on the one or more criteria, wherein the access includes remote pixel rendering protocols integrated with a zero trust architecture.

Claims (30)

1 . A method comprising steps of:

receiving a request to an end system;

determining available end systems based on one or more criteria associated with the request, wherein the one or more criteria are analyzed based on policy; and

providing access to the end system based on the one or more criteria, wherein the access includes remote pixel rendering protocols integrated with a zero trust architecture, wherein the remote pixel rendering protocols establish connectivity dynamically through a private access connector and an exporter module implemented on a server or application connector configured to perform a handshake identifying a specific remote console or desktop session associated with the requested end system based on zero trust policies evaluating real-time context comprising user identity, client security posture, and trust level of the end user network, wherein the handshake directly specifies connectivity information including hostname, IP address, and port dynamically obtained from private access configurations, wherein the handshake further comprises transmitting a connect instruction establishing a remote desktop rendering session through the private access connector, and verifying a fingerprint of a certificate or public key of the end system prior to completing the remote pixel rendering session.

2 . The method of claim 1 , wherein the end system is an Operational Technology (OT) system.

3 . The method of claim 1 , wherein the dynamically established connection to the end system is one of a Secure Shell (SSH) connection, a Remote Desktop Protocol (RDP) connection, and a Virtual Network Computing (VNC) connection, wherein for the RDP connection the handshake is proxied through the private access connector and includes transmitting a browser-native remote desktop rendering connect instruction compliant with an HTML5-based remote pixel rendering protocol to specify a hostname, IP address, and port retrieved from zero-trust private access configurations.

4 . The method of claim 3 , wherein the steps further include verifying an end system certificate or public key by calculating a fingerprint and checking that it equals an expected fingerprint prior to allowing the dynamically established connection.

5 . The method of claim 1 , wherein responsive to the end system being accessed for a first time, the steps further include performing initial discovery of a fingerprint of a public key or certificate associated with the end system.

6 . The method of claim 5 , wherein the fingerprint is added to a database, thereby allowing the end system to be verified automatically based on the stored fingerprint during subsequent connections.

7 . The method of claim 1 , wherein the steps include utilizing any of control groups and process priorities to reduce traffic load.

8 . The method of claim 1 , wherein the steps further include recording sessions associated with the access.

9 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

receiving a request to an end system;

determining available end systems based on one or more criteria associated with the request, wherein the one or more criteria are analyzed based on policy; and

providing access to the end system based on the one or more criteria, wherein the access includes remote pixel rendering protocols integrated with a zero trust architecture, wherein the remote pixel rendering protocols establish connectivity dynamically through a private access connector and an exporter module implemented on a server or application connector configured to perform a handshake identifying a specific remote console or desktop session associated with the requested end system based on zero trust policies evaluating real-time context comprising user identity, client security posture, and trust level of the end user network, wherein the handshake directly specifies connectivity information including hostname, IP address, and port dynamically obtained from private access configurations, wherein the handshake further comprises transmitting a connect instruction establishing a remote desktop rendering session through the private access connector, and verifying a fingerprint of a certificate or public key of the end system prior to completing the remote pixel rendering session.

10 . The non-transitory computer-readable medium of claim 9 , wherein the end system is an Operational Technology (OT) system.

11 . The non-transitory computer-readable medium of claim 9 , wherein the dynamically established connection to the end system is one of a Secure Shell (SSH) connection, a Remote Desktop Protocol (RDP) connection, and a Virtual Network Computing (VNC) connection.

12 . The non-transitory computer-readable medium of claim 11 , wherein the steps further include verifying an end system certificate or public key by calculating a fingerprint and checking that it equals an expected fingerprint prior to allowing the dynamically established connection.

13 . The non-transitory computer-readable medium of claim 9 , wherein responsive to the end system being accessed for a first time, the steps further include performing initial discovery of a fingerprint of a public key or certificate associated with the end system.

14 . The non-transitory computer-readable medium of claim 13 , wherein the fingerprint is added to a database, thereby allowing the end system to be verified automatically based on the stored fingerprint during subsequent connections.

15 . The non-transitory computer-readable medium of claim 9 , wherein the steps include utilizing any of control groups and process priorities to reduce traffic load.

16 . The non-transitory computer-readable medium of claim 9 , wherein the steps further include recording sessions associated with the access.

17 . A cloud-based system comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to:

receive a request to an end system;

determine available end systems based on one or more criteria associated with the request, wherein the one or more criteria are analyzed based on policy; and

provide access to the end system based on the one or more criteria, wherein the access includes remote pixel rendering protocols integrated with a zero trust architecture, wherein the remote pixel rendering protocols establish connectivity dynamically through a private access connector and an exporter module implemented on a server application connector configured to perform a handshake identifying a specific remote console or desktop session associated with the requested end system based on zero trust policies evaluating real-time context comprising user identity, client security posture, and trust level of the end user network, wherein the handshake directly specifies connectivity information including hostname, IP address, and port dynamically obtained from private access configurations, wherein the handshake further comprises transmitting a connect instruction establishing a remote desktop rendering session through the private access connector, and verifying a fingerprint of a certificate or public key of the end system prior to completing the remote pixel rendering session.

18 . The cloud-based system of claim 17 , wherein the end system is an Operational Technology (OT) system.

19 . The cloud-based system of claim 17 , wherein the dynamically established connection to the end system is one of a Secure Shell (SSH) connection, a Remote Desktop Protocol (RDP) connection, and a Virtual Network Computing (VNC) connection.

20 . The cloud-based system of claim 19 , wherein the instructions further cause the one or more processors to verify an end system certificate or public key by calculating a fingerprint and checking that it equals an expected fingerprint prior to allowing the dynamically established connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2023
From: MIHAJLOVIC, DEJAN; KAHN, CLIFFORD; MALIK, ABHIJEET; DAVARA, SANDIP; DARBARWAR, SUNITA; SANNAPAREDDY, SRINIVAS; RAMACHANDRA, GANA; FEHRING, WILLIAM; LIU, JIAN; CHANAK, JOHN A.; MENON, SUNIL
To: ZSCALER, INC.
Reel/Frame 063660/0405 →
Continuity (1)
Related Publication 20240388606A1 · Nov 21, 2024
References Cited (23)
US 6636923B1 · Meirsman et al. · 2003 [cited by applicant]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 11943195B1 · Jain · 2024 [cited by examiner]
US 20060074618A1 · Miller et al. · 2006 [cited by applicant]
US 20070042756A1 · Perfetto et al. · 2007 [cited by applicant]
US 20080307519A1 · Curcio · 2008 [cited by applicant]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120023325A1 · Lai · 2012 [cited by applicant]
US 20120185913A1 · Martinez et al. · 2012 [cited by applicant]
US 20120281708A1 · Chauhan et al. · 2012 [cited by applicant]
US 20130347072A1 · Dinha · 2013 [cited by applicant]
US 20140022586A1 · Zehler · 2014 [cited by applicant]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20200007498A1 · Tang · 2020 [cited by examiner]
US 20230123781A1 · Kaimal · 2023 [cited by examiner]
US 20230216947A1 · Bernardi · 2023 [cited by examiner]
US 20230297357A1 · Zemla · 2023 [cited by examiner]
“Securing the Cloud: Cloud Computer Security Techniques and Tactics”—Vic Winkler, Syngress Publishing, May 2011 https://www.academia.edu/77450555/Securing_the_Cloud_Cloud_Computer_Security_Techniques_and_Tactics (Year: … [cited by examiner]
“Zero Trust Architecture”—Rose et al, Nist, US Dept. of Commerce, Aug. 2020 https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf (Year: 2020). [cited by examiner]
J. R. Vic Winkler, “Securing the Cloud: Cloud Computer Security Techniques and Tactics”, May 2011, Syngress Publishing, Full Text. [cited by applicant]
Stephen R. Smoot, “Private Cloud Computing: Consolidation, Virtualization, and Service-Oriented Infrastructure”, Oct. 2011, Morgan Kaufman Publishers, Inc. Full Text. [cited by applicant]