IP Library Patent Application 18773972
Patent Application
App. No. 18/773,972

TRIGGERING PROVISIONING OF CLOUD-BASED SECURITY THROUGH FIREWALL

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/773,972
Abstract

This disclosure is related to methods and apparatus for triggering provisioning of cloud-based security through a network firewall. Triggering provisioning includes an access control service verifying authorization of the end-user device to access the private network and evaluating device characteristics of the end-user device, applying configured application control policies based on the device characteristics, evaluating Zero Trust Network Access (ZTNA) policies based on the device characteristics and application configured application control policies, generating a unique session token when the request is approved, providing the unique session token to the firewall connector, and forming a connector tunnel that establishes a secure connection between the end-user device and the private network.

Claims (91)

1 . A method for triggering provisioning of cloud-based security through a network firewall, the method comprising:

receiving, by an access control service, a request by an end-user device to access a private network via a firewall connector coupled with the network firewall;

verifying, by the access control service, authorization of the end-user device to access the private network;

evaluating, by the access control service, device characteristics of the end-user device;

applying, by the access control service, configured application control policies based on the device characteristics;

evaluating, by the access control service, Zero Trust Network Access (ZTNA) policies based on the device characteristics and application configured application control policies;

generating, by the access control service, a unique session token when the request is approved;

providing, by the access control service, the unique session token to the firewall connector; and

forming, by the access control service, a connector tunnel that establishes a secure connection between the end-user device and the private network.

2 . The method for triggering provisioning of claim 1 , wherein the access control service is a cloud-based service of a centralized management platform, and further comprising managing, by the centralized management platform, the access control service to provide administrators to manage and monitor end-user devices from a single interface, configure firewall policies, and view real-time reporting and analytics on network activity.

3 . The method for triggering provisioning of claim 1 , further comprising:

receiving, from the firewall connector, periodic requests to get updates on connector configuration; and

sending, to the firewall connector, updates about connector tunnel performance and availability.

4 . The method for triggering provisioning of claim 1 , further comprising:

provisioning a child tenant associated with the end-user device for a managed service provider;

assigning customer access rights to the child tenant; and

managing product licenses for the child tenant.

5 . The method for triggering provisioning of claim 4 , further comprising:

requesting to register, through a browser, the managed service provider and the child tenant through the access control service;

requesting to provision the managed service provider with a centralized management platform;

after the managed service provider is successfully provisioned, provisioning the child tenant with the centralized management platform;

creating administrators for the managed service provider;

assigning one or more of the administrators to the child tenant; and

sending provisioning status to the browser.

6 . The method for triggering provisioning of claim 1 , further comprising:

after the end-user device is successfully provisioned with a centralized management platform, activating the firewall connector; and

receiving, by a license manager, a request from the firewall connector to initiate connector provisioning.

7 . The method for triggering provisioning of claim 6 , further comprising:

requesting, by the firewall connector, a license through the license manager;

sending to the license manager a list of local network routes and private DNS domains; and

provision JSON specifications in the centralized management platform for the firewall connector.

8 . The method for triggering provisioning of claim 7 , further comprising:

calling, by the license manager, the access control service;

requesting, by the access control service, the centralized management platform to issue an org admin-scoped API key to the license manager;

providing, by the centralized management platform, the org admin-scoped API key to the access control service;

providing, by the access control service, the org admin-scoped API key to the license manager;

using, by the license manager, the org admin-scoped API key to provision a connector-scoped API key in the centralized management platform;

creating, in the centralized management platform, the connector-scoped API key based on connector specifications that ties the firewall connector to the connector-scoped API key; and

providing the connector-scoped API key to the license manager.

9 . The method for triggering provisioning of claim 8 , further comprising:

sending, by the license manager, the connector-scoped API key to the firewall connector; and

calling, by the firewall connector, the centralized management platform by using the connector-scoped API key to fetch connector configurations and reporting connector tunnel status.

10 . The method for triggering provisioning of claim 9 , further comprising:

fetching, by the firewall connector, a tunnel config of the connector tunnel with the connector-scoped API key from the centralized management platform;

receiving, by the access control service, the tunnel config;

applying, by the access control service, any config changes to the connector tunnel; and

publish, by the access control service, tunnel health status to the centralized management platform.

11 . The method for triggering provisioning of claim 1 , wherein the connector tunnel uses WireGuard peering.

12 . A system for triggering provisioning of cloud-based security through a network firewall, the system comprising:

a firewall connector coupled with the network firewall; and

a centralized management platform, wherein an access control service is a cloud-based service of the centralized management platform, and wherein the access control service performs a method comprising:

receiving a request by an end-user device to access a private network via the firewall connector coupled with a network firewall;

verifying authorization of the end-user device to access the private network;

evaluating device characteristics of the end-user device;

applying configured application control policies based on the device characteristics;

evaluating Zero Trust Network Access (ZTNA) policies based on the device characteristics and application configured application control policies;

generating a unique session token when the request is approved;

providing the unique session token to the firewall connector; and

forming a connector tunnel that establishes a secure connection between the end-user device and the private network.

13 . The system for triggering provisioning of claim 12 , wherein the centralized management platform manages the access control service to provide administrators to manage and monitor end-user devices from a single interface, configure firewall policies, and view real-time reporting and analytics on network activity.

14 . The system for triggering provisioning of claim 12 , wherein the firewall connector performs a method comprising:

receiving, from the firewall connector, periodic requests to get updates on connector configuration; and

sending, to the firewall connector, updates about connector tunnel performance and availability.

15 . The system for triggering provisioning of claim 12 , wherein the method further comprising:

provisioning a child tenant associated with the end-user device for a managed service provider;

assigning customer access rights to the child tenant; and

managing product licenses for the child tenant.

16 . The system for triggering provisioning of claim 15 , wherein the method further comprising:

requesting to register, through a browser, the managed service provider and the child tenant through the access control service;

requesting to provision the managed service provider with the centralized management platform;

after the managed service provider is successfully provisioned, provisioning the child tenant with the centralized management platform;

creating administrators for the managed service provider;

assigning one or more of the administrators to the child tenant; and

sending provisioning status to the browser.

17 . The system for triggering provisioning of claim 12 , wherein the method further comprising:

after the end-user device is successfully provisioned with the centralized management platform, activating the firewall connector, and

sending, to a license manager, a request to initiate connector provisioning.

18 . The system for triggering provisioning of claim 17 , wherein the firewall connector performs a method comprising:

requesting, by the firewall connector, a license through the license manager;

sending to the license manager a list of local network routes and private DNS domains; and

provision a JavaScript Object Notation (JSON) specification in the centralized management platform for the firewall connector.

19 . The system for triggering provisioning of claim 12 , wherein the connector tunnel uses WireGuard peering.

20 . A non-transitory computer readable storage medium having embodied thereon a program executable by a processor for implementing a method for triggering provisioning of cloud-based security through firewall, the method comprising:

receiving a request by an end-user device to access a private network via a firewall connector coupled with a network firewall;

verifying authorization of the end-user device to access the private network;

evaluating device characteristics of the end-user device;

applying configured application control policies based on the device characteristics;

evaluating Zero Trust Network Access (ZTNA) policies based on the device characteristics and application configured application control policies;

generating a unique session token when the request is approved;

providing the unique session token to the firewall connector; and

forming a connector tunnel that establishes a secure connection between the end-user device and the private network.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2026
From: DESIKAN, TARUN; GUMMARAJU, JAYANTH; TURNER, YOSHIO; SANGHVI, JASMINE S.
To: SONICWALL INC.
Reel/Frame 075715/0007 →
SECURITY INTEREST Recorded Jul 9, 2026
From: SONICWALL US HOLDINGS INC.; SONICWALL INC.; BANYAN SECURITY, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 075961/0674 →
SECURITY INTEREST Recorded Jul 9, 2026
From: SONICWALL US HOLDINGS INC.; SONICWALL INC.; BANYAN SECURITY, INC.
To: UBS AG, STAMFORD BRANCH
Reel/Frame 075961/0907 →