IP Library Granted Patent US 12,363,174
Granted Patent B2
US 12,363,174 · App. 18/527,887 · Granted Jul 15, 2025

Cloud-based security service that includes external evaluation for accessing a third-party application

Inventor: James Howard Royal (Austin, TX)
Assignee: CLOUDFLARE, INC.
H04L63/20H04L63/0807H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,363,174
App. No.
18/527,887
Granted
Jul 15, 2025
Kind
B2
Abstract

A cloud-based security service that includes external evaluation for accessing a third-party application. The security service receives a request to access a third-party application from a client device. The security service enforces a set of one or more access policies configured for the third-party application including an external evaluation rule. As part of enforcing the external evaluation rule, the security service transmits an external evaluation request to an external endpoint defined in the external evaluation rule. The external evaluation request includes an identity of a user associated with the request. The security service receives the result of the external evaluation. If the external evaluation passed, the security service grants access to the third-party application based at least in part on its passing.

Claims (73)

1. A method in a server providing a cloud-based security service, comprising:

receiving, from a client device at the cloud-based security service, a request to access a third-party application;

determining an identity of a user associated with the request;

determining, at the cloud-based security service, a set of one or more access policies that are configured for accessing the third-party application, wherein the set of one or more access policies includes:

an identity-based access rule that specifies criteria the identity of the user associated with the request must meet to satisfy the identity-based access rule, and

an external evaluation rule;

enforcing the identity-based access rule including determining that the identity of the user associated with the request meets the specified criteria;

enforcing the external evaluation rule including transmitting an external evaluation request to an external endpoint defined in the external evaluation rule, wherein the external endpoint is external to the cloud-based security service and is controlled or managed by an owner or operator of the third-party application, and wherein the external evaluation request includes an identity of a user associated with the request;

receiving, from the external endpoint defined in the external evaluation rule, an external evaluation response that is responsive to the external evaluation request, the external evaluation response specifying that an external evaluation has passed; and

granting access to the third-party application based at least in part on receiving the external evaluation response specifying that the external evaluation has passed.

2. The method of claim 1 , wherein granting access to the third-party application includes transmitting the request to the third-party application.

3. The method of claim 1 , further comprising:

wherein granting access to the third-party application includes setting an authorization cookie or token and redirecting the client device to transmit the request again with the authorization cookie or token; and

transmitting the request to the third-party application.

4. The method of claim 1 , wherein determining the identity of the user associated with the request includes:

causing the client device to transmit an authentication request to an identity provider; and

receiving, from the client device, an authentication response that was generated by the identity provider that identifies the user and signifies the user has successfully authenticated to the identity provider.

5. The method of claim 1 , further comprising:

wherein the set of one or more access policies further includes a device posture rule that specifies criteria related to device posture in which the client device must meet for satisfying the device posture rule; and

enforcing the device posture rule including:

transmitting a request for device posture status of the client device to an endpoint protection provider,

receiving a response to the request for device posture status of the client device from the endpoint protection provider, and

determining that the device posture status of the client device meets the specified criteria in the device posture rule.

6. The method of claim 1 , wherein the cloud-based security service acts as a service provider on behalf of the third-party application.

7. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor of a server providing a cloud-based security service, will cause said processor to perform operations comprising:

receiving, from a client device at the cloud-based security service, a request to access a third-party application;

determining an identity of a user associated with the request;

determining, at the cloud-based security service, a set of one or more access policies that are configured for accessing the third-party application, wherein the set of one or more access policies includes:

an identity-based access rule that specifies criteria the identity of the user associated with the request must meet to satisfy the identity-based access rule, and

an external evaluation rule;

enforcing the identity-based access rule including determining that the identity of the user associated with the request meets the specified criteria;

enforcing the external evaluation rule including transmitting an external evaluation request to an external endpoint defined in the external evaluation rule, wherein the external endpoint is external to the cloud-based security service and is controlled or managed by an owner or operator of the third-party application, and wherein the external evaluation request includes an identity of a user associated with the request;

receiving, from the external endpoint defined in the external evaluation rule, an external evaluation response that is responsive to the external evaluation request, the external evaluation response specifying that an external evaluation has passed; and

granting access to the third-party application based at least in part on receiving the external evaluation response specifying that the external evaluation has passed.

8. The non-transitory machine-readable storage medium of claim 7 , wherein granting access to the third-party application includes transmitting the request to the third-party application.

9. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

wherein granting access to the third-party application includes setting an authorization cookie or token and redirecting the client device to transmit the request again with the authorization cookie or token; and

transmitting the request to the third-party application.

10. The non-transitory machine-readable storage medium of claim 7 , wherein determining the identity of the user associated with the request includes:

causing the client device to transmit an authentication request to an identity provider; and

receiving, from the client device, an authentication response that was generated by the identity provider that identifies the user and signifies the user has successfully authenticated to the identity provider.

11. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

wherein the set of one or more access policies further includes a device posture rule that specifies criteria related to device posture in which the client device must meet for satisfying the device posture rule; and

enforcing the device posture rule including:

transmitting a request for device posture status of the client device to an endpoint protection provider,

receiving a response to the request for device posture status of the client device from the endpoint protection provider, and

determining that the device posture status of the client device meets the specified criteria in the device posture rule.

12. The non-transitory machine-readable storage medium of claim 7 , wherein the cloud-based security service acts as a service provider on behalf of the third-party application.

13. A server providing a cloud-based security service, the server comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor, will cause the server to perform operations including:

receiving, from a client device at the cloud-based security service, a request to access a third-party application;

determining an identity of a user associated with the request;

determining, at the cloud-based security service, a set of one or more access policies that are configured for accessing the third-party application, wherein the set of one or more access policies includes:

an identity-based access rule that specifies criteria the identity of the user associated with the request must meet to satisfy the identity-based access rule, and

an external evaluation rule;

enforcing the identity-based access rule including determining that the identity of the user associated with the request meets the specified criteria;

enforcing the external evaluation rule including transmitting an external evaluation request to an external endpoint defined in the external evaluation rule, wherein the external endpoint is external to the cloud-based security service and is controlled or managed by an owner or operator of the third-party application, and wherein the external evaluation request includes an identity of a user associated with the request;

receiving, from the external endpoint defined in the external evaluation rule, an external evaluation response that is responsive to the external evaluation request, the external evaluation response specifying that an external evaluation has passed; and

granting access to the third-party application based at least in part on receiving the external evaluation response specifying that the external evaluation has passed.

14. The server of claim 13 , wherein granting access to the third-party application includes transmitting the request to the third-party application.

15. The server of claim 13 , wherein the operations further comprise:

wherein granting access to the third-party application includes setting an authorization cookie or token and redirecting the client device to transmit the request again with the authorization cookie or token; and

transmitting the request to the third-party application.

16. The server of claim 13 , wherein determining the identity of the user associated with the request includes:

causing the client device to transmit an authentication request to an identity provider; and

receiving, from the client device, an authentication response that was generated by the identity provider that identifies the user and signifies the user has successfully authenticated to the identity provider.

17. The server of claim 15 , wherein the operations further comprise:

wherein the set of one or more access policies further includes a device posture rule that specifies criteria related to device posture in which the client device must meet for satisfying the device posture rule; and

enforcing the device posture rule including:

transmitting a request for device posture status of the client device to an endpoint protection provider,

receiving a response to the request for device posture status of the client device from the endpoint protection provider, and

determining that the device posture status of the client device meets the specified criteria in the device posture rule.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2023
From: ROYAL, JAMES HOWARD
To: CLOUDFLARE, INC.
Reel/Frame 065784/0467 →
Continuity (3)
Continuation 17936572 · Sep 29, 2022
Provisional Application 63366686 · Jun 20, 2022
Related Publication 20240106864A1 · Mar 28, 2024
References Cited (12)
US 8806570B2 · Barton et al. · 2014 [cited by applicant]
US 9143509B2 · Rose · 2015 [cited by examiner]
US 10771435B2 · Goldschlag · 2020 [cited by examiner]
US 10944561B1 · Cahill · 2021 [cited by examiner]
US 20140040977A1 · Barton · 2014 [cited by examiner]
US 20160269416A1 · Camenisch · 2016 [cited by examiner]
US 20210200870A1 · Yavo · 2021 [cited by examiner]
Cloudflare One, Our SASE Platform, Design Guide, Cloudflare Inc., Jan. 13, 2022, 26 pages. [cited by applicant]
Final Office Action, U.S. Appl. No. 17/936,572, Apr. 25, 2023, 12 pages. [cited by applicant]
Garbers, et al., Zero Trust, SASE and SSE: Foundational Concepts for Your Next-Generation Network, Cloudflare, Inc., Jun. 19, 2022, 18 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/936,572, Dec. 8, 2022, 9 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/936,572, Jul. 20, 2023, 9 pages. [cited by applicant]