IP Library › Granted Patent US 11,544,410
Granted Patent B2
US 11,544,410 · App. 17/190,547 · Granted Jan 3, 2023

Secure access to third-party cloud-based applications

Inventor: Steve Peschka (Goodyear, AZ)
Assignee: Zscaler, Inc.
G06F21/629H04L63/0853H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,544,410
App. No.
17/190,547
Granted
Jan 3, 2023
Kind
B2
Abstract

Systems and methods include, on a respective node of a plurality of nodes communicatively coupled to one another forming a cloud-based system, receiving a request to obtain data from the third-party cloud application. The systems and methods also include implementing a lightweight agent, on the respective node, that is configured to access data, of a third-party cloud application of the cloud-based services, via an application-only security token layer on the cloud-based system. The systems and methods further include utilizing the lightweight agent to access the third-party cloud application via the application-only security token and obtain data from the third-party cloud application. The systems and methods yet further include providing a response to the request based on the data obtained from the third-party cloud application.

Claims (42)

1. A system comprising:

a plurality of nodes communicatively coupled to one another forming a cloud-based system configured to implement cloud-based services, each node of the cloud-based system including one or more processors and memory comprising instructions that, when executed, cause the one or more processors to

receive a request to obtain data from a third-party cloud application;

implement a lightweight agent, on a node, that is configured to access data, of the third-party cloud application of the cloud-based services, via an application-only security token layer on the cloud-based system,

utilize the lightweight agent to access the third-party cloud application via the application-only security token and obtain data from the third-party cloud application, and

provide a response to the request based on the data obtained from the third-party cloud application.

2. The system of claim 1 , wherein the instructions, when executed, further cause the one or more processors to

determine one or more statistics of the third-party cloud application based on the data obtained,

incorporate the one or more statistics in historical statistics, and

provide a notification when any of the one or more statistics exceeds a defined threshold.

3. The system of claim 1 , wherein the lightweight agent issues a lightweight probe that simulates user activity in the third-party cloud application to obtain the data from the third-party cloud application.

4. The system of claim 1 , wherein the third-party application is implemented on the node.

5. The system of claim 1 , wherein the application-only security token for the third-party cloud application is obtained by the cloud-based system via a one-time consent process without requiring a customer to configure the third-party cloud application.

6. The system of claim 1 , wherein the data includes one or more of email data, collaboration application data, and cloud storage resource data.

7. The system of claim 1 , wherein the cloud application includes a collaboration application.

8. A non-transitory computer-readable storage medium having computer-readable code stored thereon for programming one or more processors to perform steps of:

receive a request to obtain data from a third-party cloud application

implement a lightweight agent, on a node, that is configured to access data, of the third-party cloud application of the cloud-based services, via an application-only security token layer on the cloud-based system,

utilize the lightweight agent to access the third-party cloud application via the application-only security token and obtain data from the third-party cloud application, and

provide a response to the request based on the data obtained from the third-party cloud application.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the computer-readable code stored further programs the one or more processors to perform steps of

determine one or more statistics of the third-party cloud application based on the data obtained,

incorporate the one or more statistics in historical statistics, and

provide a notification when any of the one or more statistics exceeds a defined threshold.

10. The non-transitory computer-readable storage medium of claim 8 , wherein the lightweight agent issues a lightweight probe that simulates user activity in the third-party cloud application to obtain the data from the third-party cloud application.

11. The non-transitory computer-readable storage medium of claim 8 , wherein the third-party application is implemented on the node.

12. The non-transitory computer-readable storage medium of claim 8 , wherein the application-only security token for the third-party cloud application is obtained via a one-time consent process without requiring a customer to configure the third-party cloud application.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the data includes one or more of email data, collaboration application data, and cloud storage resource data.

14. The non-transitory computer-readable storage medium of claim 8 , wherein the cloud application includes a collaboration application.

15. A method comprising:

receiving a request to obtain data from a third-party cloud application;

implementing a lightweight agent, on a node, that is configured to access data, of the third-party cloud application of the cloud-based services, via an application-only security token layer on the cloud-based system;

utilizing the lightweight agent to access the third-party cloud application via the application-only security token and obtain data from the third-party cloud application; and

providing a response to the request based on the data obtained from the third-party cloud application.

16. The method of claim 15 , further comprising

determining one or more statistics of the third-party cloud application based on the data obtained;

incorporating the one or more statistics in historical statistics; and

providing a notification when any of the one or more statistics exceeds a defined threshold.

17. The method of claim 15 , wherein the lightweight agent issues a lightweight probe that simulates user activity in the third-party cloud application to obtain the data from the third-party cloud application.

18. The method of claim 15 , wherein the third-party application is implemented on the node.

19. The method of claim 15 , wherein the application-only security token for the third-party cloud application is obtained via a one-time consent process without requiring a customer to configure the third-party cloud application.

20. The method of claim 19 , wherein the data includes one or more of email data, collaboration application data, and cloud storage resource data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2021
From: PESCHKA, STEVE
To: ZSCALER, INC.
Reel/Frame 055473/0255 →
Continuity (2)
Continuation In Part 16739256 · Jan 10, 2020
Related Publication 20210216655A1 · Jul 15, 2021
Cited By (3)
US 1,102,450 US 12,250,221 US 12,355,589