IP Library Patent Application 18902289
Patent Application
App. No. 18/902,289

METHOD FOR APPLICATION ACCESS IN ZERO TRUST CAMPUS NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/902,289
Abstract

Disclosed herein are system, method, and computer program product aspects for providing an agent-based zero trust network access (ZTNA) remote device access to a campus network. Some aspects of this disclosure relate to a universal network access application including a memory and a processor. The processor is configured to receive an authentication request from a client device and in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request. The processor is further configured to transmit the set of network policies to a policy enforcement application in a campus network.

Claims (59)

1 . A universal network access application, comprising:

a memory;

at least one processor coupled to the memory and configured to:

receive an authentication request from a client device;

in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request; and

transmit the set of network policies to a policy enforcement application in a campus network.

2 . The universal network access application of claim 1 , wherein the at least one processor is further configured to:

authenticate the client device based on the authentication request; and

in response to authenticating the client device, transmit the set of network policies to the policy enforcement application.

3 . The universal network access application of claim 1 ,

wherein the client device has established a secured tunnel with a destination device via a cloud gateway of the universal network access application, and

wherein the IP address and the port number correspond to the cloud gateway.

4 . The universal network access application of claim 3 , wherein the secured tunnel is an Internet protocol security (IPSEC) tunnel or a wireguard tunnel.

5 . The universal network access application of claim 1 , wherein the at least one processor is further configured to:

receive an instruction from an administrator of the campus network;

generate a second set of network policies based on the instruction; and

transmit the second set of network policies to the policy enforcement application.

6 . The universal network access application of claim 1 , wherein the set of network policies and the second set of network policies configure the policy enforcement application to determine whether to permit or deny a packet from the client device.

7 . The universal network access application of claim 1 , wherein the at least one processor is further configured to:

receive a packet from the policy enforcement application; and

forward the packet to a destination device.

8 . The universal network access application of claim 7 , wherein the first set of rules corresponds to a header of the packet.

9 . A method for a universal network access application, comprising:

receiving an authentication request from a client device;

in response to receiving the authentication request, retrieving a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request; and

transmitting the set of network policies to a policy enforcement application in a campus network.

10 . The method of claim 9 , further comprising:

authenticating the client device based on the authentication request; and

in response to authenticating the client device, transmitting the set of network policies to the policy enforcement application.

11 . The method of claim 9 ,

wherein the client device has established an Internet protocol security (IPSEC) tunnel with a destination device via a cloud gateway of the universal network access application, and

wherein the IP address and the port number correspond to the cloud gateway.

12 . The method of claim 9 , further comprising:

receiving an instruction from an administrator of the campus network;

generating a second set of network policies based on the instruction; and

transmitting the second set of network policies to the policy enforcement application.

13 . The method of claim 9 , wherein the set of network policies and the second set of network policies configure the policy enforcement application to determine whether to permit or deny a packet from the client device.

14 . The method of claim 9 , further comprising:

receiving a packet from the policy enforcement application; and

forwarding the packet to a destination device.

15 . The method of claim 14 , wherein the first set of rules corresponds to a header of the packet.

16 . A non-transitory computer-readable medium (CRM) comprising instructions to, upon execution of the instructions by one or more processors of a universal network access application, cause the universal network access application to perform operations, the operations comprising:

receiving an authentication request from a client device;

in response to receiving the authentication request, retrieving a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request; and

transmitting the set of network policies to a policy enforcement application in a campus network.

17 . The non-transitory CRM of claim 16 , wherein the operations further comprise:

authenticating the client device based on the authentication request; and

in response to authenticating the client device, transmitting the set of network policies to the policy enforcement application.

18 . The non-transitory CRM of claim 16 ,

wherein the client device has established an Internet protocol security (IPSEC) tunnel with a destination device via a cloud gateway of the universal network access application, and

wherein the IP address and the port number correspond to the cloud gateway.

19 . The non-transitory CRM of claim 16 , wherein the operations further comprise:

receiving an instruction from an administrator of the campus network;

generating a second set of network policies based on the instruction; and

transmitting the second set of network policies to the policy enforcement application.

20 . The non-transitory CRM of claim 16 , wherein the operations further comprise:

receiving a packet from the policy enforcement application; and

forwarding the packet to a destination device, and

wherein the first set of rules corresponds to a header of the packet.

Assignments (2)
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2024
From: GROSSER, DONALD B.; SAMARYA, MAHENDRA; BICKFORD, CHARLES; YOHE, KEVIN, II; JAMES, SUVEENA; BRADY, MICHAEL
To: EXTREME NETWORKS, INC.
Reel/Frame 069485/0291 →