IP Library › Granted Patent US 12,542,765
Granted Patent B2
US 12,542,765 · App. 18/359,538 · Granted Feb 3, 2026

Remote server isolation utilizing zero trust architecture

Inventors: Shay Shwartz (Tel Aviv, IL); Gil Azrielant (Tel Aviv, IL)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/029H04L63/0227H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,765
App. No.
18/359,538
Granted
Feb 3, 2026
Kind
B2
Abstract

A zero trust cloud environment provides access to a secure network, and secure network applications. The zero trust cloud environment performs authentication of a user account, and upon successful completion initiates a secure network application, such as an SSH session to a server in a secure network. The server is instructed to generate an isolated network namespace through which a virtual network interface is bridged to the default network namespace. A firewall of the default network namespace does not permit network traffic from the virtual network interface to pass if it is directed to an address of the secure network.

Claims (51)

1 . A method comprising:

receiving a request to authenticate an identity from a client device, the identity including at least a unique identifier of a user;

receiving a request to access a cryptographically secure network application (CSNA) on a remote server through the zero trust cloud environment, the remote server deployed in a secure network environment, and having a default network namespace (DNN), wherein the request includes session credentials for logging in to the CSNA, and wherein the secure network environment is communicatively coupled with the zero trust cloud environment;

piping communication between the client device and the remote server through the zero trust cloud environment; and

configuring the remote server to:

generate an isolated network namespace (INN);

generate a bridge between the INN and the DNN;

assign a name from the INN to a virtual network interface (VNI); and

generate a new CSNA in the INN.

2 . The method of claim 1 , further comprising: configuring a DNN firewall of the remote server to drop data packets from the INN directed to the secure network environment.

3 . The method of claim 2 , further comprising: configuring the DNN firewall to forward data packets from the INN which are not directed to the secure network environment.

4 . The method of claim 1 , further comprising:

accessing a policy engine to determine a policy matching: the identity, the session credentials, and a combination thereof.

5 . The method of claim 4 , further comprising:

piping the communication based on the determined policy.

6 . The method of claim 1 , wherein the CSNA is an SSH session.

7 . The method of claim 1 , wherein the zero trust cloud environment includes any one of: a frontend CSNA server, an access portal server, a backend server, and any combination thereof.

8 . The method of claim 7 , wherein the backend server is configured to connect to a connector deployed in the secure network environment.

9 . The method of claim 7 , wherein the client device is configured to communicate with the frontend CSNA server.

10 . A non-transitory computer-readable medium comprising instructions executable by at least one processor to:

receive a request to authenticate an identity from a client device, the identity including at least a unique identifier of a user;

receive a request to access a cryptographically secure network application (CSNA) on a remote server through the zero trust cloud environment, the remote server deployed in a secure network environment, having a default network namespace (DNN), wherein the request includes session credentials for logging in to the CSNA, and wherein the secure network environment is communicatively coupled with the zero trust cloud environment;

pipe communication between the client device and the remote server through the zero trust cloud environment; and

configure the remote server to:

generate an isolated network namespace (INN);

generate a bridge between the INN and the DNN;

assign a name from the INN to a virtual network interface (VNI); and

generate a new CSNA in the INN.

11 . A system comprising:

a processing circuitry; and

a non-transitory computer-readable medium comprising instructions executable by the processing circuitry; to:

receive a request to authenticate an identity from a client device, the identity including at least a unique identifier of a user;

receive a request to access a cryptographically secure network application (CSNA) on a remote server through the zero trust cloud environment, the remote server deployed in a secure network environment, having a default network namespace (DNN), wherein the request includes session credentials for logging in to the CSNA, and wherein the secure network environment is communicatively coupled with the zero trust cloud environment;

pipe communication between the client device and the remote server through the zero trust cloud environment; and

configure the remote server to:

generate an isolated network namespace (INN);

generate a bridge between the INN and the DNN;

assign a name from the INN to a virtual network interface (VNI); and

generate a new CSNA in the INN.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure a DNN firewall of the remote server to drop data packets from the INN directed to the secure network environment.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

configure the DNN firewall to forward data packets from the INN which are not directed to the secure network environment.

14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

access a policy engine to determine a policy matching: the identity, the session credentials, and a combination thereof.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

pipe the communication based on the determined policy.

16 . The system of claim 11 , wherein the CSNA is an SSH session.

17 . The system of claim 11 , wherein the zero trust cloud environment includes any one of: a frontend CSNA server, an access portal server, a backend server, and any combination thereof.

18 . The system of claim 17 , wherein the backend server is configured to connect to a connector deployed in the secure network environment.

19 . The system of claim 17 , wherein the client device is configured to communicate with the frontend CSNA server.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2024
From: AXIS CYBER SECURITY LTD
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 067407/0249 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: AXIS CYBER SECURITY LTD
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 066846/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2024
From: SHWARTZ, SHAY; AZRIELANT, GIL
To: AXIS CYBER SECURITY LTD.
Reel/Frame 066193/0935 →
Continuity (1)
Related Publication 20250039152A1 · Jan 30, 2025
References Cited (68)
US 10764263B2 · Rossi · 2020 [cited by examiner]
US 11240242B1 · Celik · 2022 [cited by examiner]
US 11470100B1 · Christian · 2022 [cited by examiner]
US 12155667B2 · Sviry et al. · 2024 [cited by applicant]
US 20120265976A1 · Spiers · 2012 [cited by examiner]
US 20160087933A1 · Johnson · 2016 [cited by examiner]
US 20160234196A1 · Fausak · 2016 [cited by examiner]
US 20170064005A1 · Lee · 2017 [cited by examiner]
US 20180152426A1 · Rossi · 2018 [cited by examiner]
US 20180255060A1 · Bansal · 2018 [cited by examiner]
US 20190141015A1 · Nellen · 2019 [cited by examiner]
US 20200236112A1 · Pularikkal · 2020 [cited by examiner]
US 20200336466A1 · Goldschlag · 2020 [cited by examiner]
US 20210218747A1 · Azrielant et al. · 2021 [cited by applicant]
US 20210240818A1 · Seksenov · 2021 [cited by examiner]
US 20220038281A1 · King · 2022 [cited by examiner]
US 20220075889A1 · Friedman · 2022 [cited by examiner]
US 20220294788A1 · Pattar · 2022 [cited by examiner]
US 20220353201A1 · Navali · 2022 [cited by examiner]
US 20230104568A1 · Miriyala · 2023 [cited by examiner]
US 20230106531A1 · Henkel · 2023 [cited by examiner]
US 20230107891A1 · Miriyala · 2023 [cited by examiner]
US 20230123781A1 · Kaimal · 2023 [cited by examiner]
US 20230224167A1 · Wang · 2023 [cited by examiner]
US 20230224302A1 · Sviri · 2023 [cited by examiner]
US 20230224303A1 · Sviri et al. · 2023 [cited by applicant]
US 20230247003A1 · Chanak · 2023 [cited by examiner]
US 20230247016A1 · Nagaraja · 2023 [cited by examiner]
US 20230336414A1 · Miriyala · 2023 [cited by examiner]
US 20230362236A1 · Nair · 2023 [cited by examiner]
US 20240037242A1 · Suryanarayana · 2024 [cited by examiner]
US 20240095739A1 · Adogla · 2024 [cited by examiner]
US 20240129161A1 · Miriyala · 2024 [cited by examiner]
US 20240129185A1 · Shetye · 2024 [cited by examiner]
US 20240129258A1 · Ead · 2024 [cited by examiner]
US 20240129321A1 · Howe · 2024 [cited by examiner]
US 20240214350A1 · Sole · 2024 [cited by examiner]
US 20240223454A1 · Miriyala · 2024 [cited by examiner]
US 20240297872A1 · Stayskal · 2024 [cited by examiner]
US 20240346184A1 · Suryanarayana · 2024 [cited by examiner]
US 20240364509A1 · Potlapally · 2024 [cited by examiner]
US 20240364632A1 · Henkel · 2024 [cited by examiner]
US 20240378072A1 · Ignoto · 2024 [cited by examiner]
US 20240386098A1 · Sawant · 2024 [cited by examiner]
US 20240406277A1 · Henkel · 2024 [cited by examiner]
US 20250023787A1 · Miriyala · 2025 [cited by examiner]
US 20250039131A1 · Elul · 2025 [cited by examiner]
US 20250039145A1 · Dekel · 2025 [cited by examiner]
US 20250039152A1 · Shwartz · 2025 [cited by examiner]
US 20250039161A1 · Gangadharappa · 2025 [cited by examiner]
US 20250039173A1 · Azrielant · 2025 [cited by examiner]
US 20250039195A1 · Shwartz · 2025 [cited by examiner]
US 20250047605A1 · Elul · 2025 [cited by examiner]
US 20250088360A1 · Evani · 2025 [cited by examiner]
US 20250088544A1 · Clark · 2025 [cited by examiner]
US 20250112892A1 · Parekh · 2025 [cited by examiner]
US 20250158989A1 · Howe · 2025 [cited by examiner]
US 20250158990A1 · Howe · 2025 [cited by examiner]
US 20250159022A1 · Howe · 2025 [cited by examiner]
US 20250159023A1 · Howe · 2025 [cited by examiner]
US 20250202902A1 · Long · 2025 [cited by examiner]
US 20250233888A1 · Bransi · 2025 [cited by examiner]
US 20250279950A1 · Swindle · 2025 [cited by examiner]
US 20250286888A1 · Small · 2025 [cited by examiner]
Rose, Scott, et al. “Sp 800-207: Zero trust architecture.” National Institute of Standards and Technology (NIST), Computer Security Resource Center 8 (2020). [cited by examiner]
Wikipedia, “iptables”, available online at <https://en.wikipedia.org/w/index.php?title=Iptables&oldid=1093246628>, Jun. 15, 2022, 3 Pages. [cited by applicant]
Wikipedia, “Windows Filtering Platform”, available online at <https://en.wikipedia.org/w/index.php? title=Windows_Filtering_Platform&oldid=1009001725>, Feb. 26, 2021, 2 pages. [cited by applicant]
Wikipedia, “Secure Shell”, available online at <https://en.wikipedia.org/w/index.php? title=Secure_Shell&oldid=1158549718>, Jun. 4, 2023, 8 pages. [cited by applicant]