IP Library Granted Patent US 12,010,099
Granted Patent B1
US 12,010,099 · App. 18/378,370 · Granted Jun 11, 2024

Identity-based distributed cloud firewall for access and network segmentation

Inventors: Carlos Eliseo Salas Lumbreras (Vilnius, LT); Juta Gurinaviciute (Vilnius, LT)
Assignee: UAB 360 IT
H04L63/0263H04L63/0272H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,010,099
App. No.
18/378,370
Granted
Jun 11, 2024
Kind
B1
Abstract

According to some embodiments, a method of controlling access to network resources includes: receiving an authentication request from a user device to a core security service; if the user is authenticated, authorizing the user device to connect to a private cloud, and connecting the user device with the private cloud and retrieving user-specific segmented firewall rules stored in the private cloud; routing, through the firewall rules, a request by the user device to access an outer resource; evaluating the request against the firewall rules; if the request meets the firewall rules, routing the request through security measures of the firewall; and if the request does not meet the firewall rules, denying the user device access to the outer resource.

Claims (38)

1. A method of controlling access to network resources, the method comprising:

receiving an authentication request from a user device to a core security service;

upon authentication of the user device by the core security service, authorizing the user device to connect to a private cloud, and connecting the user device to the private cloud comprising a gateway and a firewall and retrieving user-specific, segmented firewall rules stored in the private cloud;

routing a request by the user device to access an outer resource to the gateway;

evaluating the request against the segmented firewall rules;

if the request meets the segmented firewall rules, routing the request through security measures of the firewall; and

if the request does not meet the segmented firewall rules, denying the user device access to the outer resource.

2. The method of claim 1 , wherein each private cloud includes a corresponding firewall.

3. The method of claim 2 , wherein the request is transmitted through a secure VPN tunnel established by the gateway before being received by the firewall.

4. The method of claim 3 , wherein the segmented firewall rules include firewall rules associated with at least one of the user, a group of users, an organization, or the gateway.

5. The method of claim 3 , further comprising forwarding the request to the outer resource and transmitting a response from the outer resource to the user device through the secure VPN tunnel if the request meets the segmented firewall rules and passes the security measures of the firewall.

6. The method of claim 1 , wherein the core security service is located between the user device and at least one of the private cloud.

7. The method of claim 1 , wherein the authentication request includes a request to connect to one or more private clouds associated with the user.

8. An apparatus for controlling access to network resources, comprising at least one processor and at least one non-transient computer readable medium for storing instructions that, when executed by the at least one processor, causes the apparatus to perform operations comprising:

receiving an authentication request from a user device to a core security service;

upon authentication of the user by the core security service, authorizing the user device to connect to a private cloud, and connecting the user device to the private cloud comprising a gateway and a firewall and retrieving user-specific, segmented firewall rules stored in the private cloud;

routing a request by the user device to access an outer resource to the gateway;

evaluating the request against the segmented firewall rules;

if the request meets the segmented firewall rules, routing the request through security measures of the firewall; and

if the request does not meet the segmented firewall rules, denying the user device access to the outer resource.

9. The apparatus of claim 8 , wherein each private cloud includes a corresponding firewall.

10. The apparatus of claim 9 , wherein the request is transmitted through a secure VPN tunnel established by the gateway before being received by the firewall.

11. The apparatus of claim 10 , wherein the segmented firewall rules include firewall rules associated with at least one of the user, a group of users, an organization, or the gateway.

12. The apparatus of claim 10 , further comprising forwarding the request to the outer resource and transmitting a response from the outer resource to the user device through the secure VPN tunnel if the request meets the segmented firewall rules and passes the security measures of the firewall.

13. The apparatus of claim 8 , wherein the core security service is located between the user device and the private cloud.

14. The apparatus of claim 8 , wherein the authentication request includes a request to connect to one or more private clouds associated with the user.

15. One or more non-transitory computer readable media having instructions stored thereon which, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving an authentication request from a user device to a core security service;

upon authentication of the user by the core security service authorizing the user device to connect to a private cloud, and connecting the user device to the private cloud comprising a gateway and a firewall and retrieving user-specific, segmented firewall rules stored in the private cloud;

routing a request by the user device to access an outer resource to the gateway;

evaluating the request against the segmented firewall rules;

if the request meets the segmented firewall rules, routing the request through security measures of the firewall; and

if the request does not meet the segmented firewall rules, denying the user device access to the outer resource.

16. The computer readable media of claim 15 , wherein each private cloud includes a corresponding firewall.

17. The computer readable media of claim 16 , wherein the request is transmitted through a secure VPN tunnel established by the gateway before being received by the firewall.

18. The computer readable media of claim 17 , wherein the segmented firewall rules include firewall rules associated with at least one of the user, a group of users, an organization, or the gateway.

19. The computer readable media of claim 17 , forwarding the request to the outer resource and transmitting a response from the outer resource to the user device through the secure VPN tunnel if the request meets the segmented firewall rules and passes the security measures of the firewall.

20. The computer readable media of claim 15 , wherein the authentication request includes a request to connect to one or more private clouds associated with the user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2026
From: UAB 360 IT
To: 720 IT, UAB
Reel/Frame 073446/0784 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2024
From: SALAS LUMBRERAS, CARLOS ELISEO; GURINAVICIUTE, JUTA
To: UAB 360 IT
Reel/Frame 066206/0308 →