IP Library › Granted Patent US 12,245,036
Granted Patent B1
US 12,245,036 · App. 18/769,302 · Granted Mar 4, 2025

Global secure SIM clientless SASE architecture for cellular devices

Inventors: Kallol Banerjee (San Jose, CA); Jonathan Bosanac (Ennis, MT); Milind Gunjan (Olathe, KS)
Assignee: Netskope, Inc.
H04W12/088H04W8/20H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,245,036
App. No.
18/769,302
Granted
Mar 4, 2025
Kind
B1
Abstract

A clientless security system to secure cellular devices across a network in a cloud-based environment. The clientless security system includes a tenant with multiple cellular devices, tunnels for transmitting traffic, and a traffic steering module for directing traffic toward a gateway. The clientless security system further includes gateways to apply policies based on a device profile and an alert generator. The traffic steering module provides a SIM with network identifiers, configures the SIM with a custom network identifier, creates a device-to-IP mapping, and distributes the device-to-IP mapping to gateways in real-time. The gateways apply multiple policies based on a device profile, receive traffic from the traffic steering module, and perform a reverse lookup. The gateways further determine a device identity, apply policies, and forward traffic to a destination. The alert generator is also used to notify the tenant of further remediation in case of policy violations.

Claims (75)

1. A clientless security system for securing a plurality of cellular devices across a cellular network in a cloud-based environment, the clientless security system comprises:

a tenant of a plurality of tenants using a plurality of cellular networks, the tenant includes the plurality of cellular devices;

a plurality of tunnels between a cellular device of the plurality of cellular devices and the cellular network, the plurality of tunnels is operable to:

transmit traffic from the cellular device of the plurality of cellular devices at the cellular network; and

identify traffic associated with a plurality of network identifiers;

a traffic steering module to route traffic towards a gateway of a plurality of gateways in the cloud-based environment, wherein the traffic steering module is operable to:

provision a Subscriber Identity Module (SIM) with the plurality of network identifiers;

configure the SIM with a custom network identifier;

create a device-to-IP mapping;

distribute the device-to-IP mapping to the plurality of gateways in real-time; and

route traffic to the gateway of the plurality of gateways using the custom network identifier;

the plurality of gateways to apply a plurality of policies based on a device profile in the cloud-based environment, wherein the plurality of gateways is operable to:

receive traffic from the traffic steering module at the cellular network;

perform a reverse lookup for the cellular device of the plurality of cellular devices using a source IP address;

determine a device identity corresponding to traffic from the cellular device of the plurality of cellular devices;

apply the plurality of policies based on the device profile; and

forward traffic to a destination in the cloud-based environment; and

an alert generator to notify the tenant for a remediation in case of detection of violation of a policy of the plurality of policies.

2. The clientless security system of claim 1 , wherein the plurality of cellular devices authenticates with the cellular network using a network identifier in the SIM and are in active state with IPv4/IPv6 addresses.

3. The clientless security system of claim 1 , wherein the custom network identifier is used for traffic segregation in the cellular network and the custom network identifier is an APN for a 4G network and a DNN for a 5G network.

4. The clientless security system of claim 1 , wherein the device-to-IP mapping is created using a universal unique mobile subscriber identity (UUMSI) identifier as a primary key.

5. The clientless security system of claim 1 , wherein traffic at the cellular network, on a web and on a firewall side, is analyzed by a server name identification (SNI) based URL filtering method that provides security to the plurality of cellular devices.

6. The clientless security system of claim 1 , wherein the device profile is created by analyzing the plurality of policies, traffic patterns, and device types associated with the plurality of tenants.

7. The clientless security system of claim 1 , wherein the remediation in case of detection of violation of the policy of the plurality of policies includes:

blocking a corresponding traffic;

quarantining the cellular device of the plurality of cellular devices; and

allowing limited connectivity to the cellular device of the plurality of cellular devices.

8. A clientless security method for securing a plurality of cellular devices across a cellular network in a cloud-based environment, the clientless security method comprising:

transmitting traffic from a cellular device of the plurality of cellular devices at the cellular network;

identifying traffic associated with a plurality of network identifiers;

routing traffic towards a gateway of a plurality of gateways in the cloud-based environment using a traffic steering module, wherein the traffic steering module is operable to:

provisioning a Subscriber Identity Module (SIM) with the plurality of network identifiers;

configuring the SIM with a custom network identifier;

creating a device-to-IP mapping;

distributing the device-to-IP mapping to the plurality of gateways in real-time; and

routing traffic to the gateway of the plurality of gateways using the custom network identifier;

applying a plurality of policies based on a device profile in the cloud-based environment using the plurality of gateways, wherein the plurality of gateways is operable to:

receiving traffic from the traffic steering module at the cellular network;

performing a reverse lookup for the cellular device of the plurality of cellular devices using a source IP address;

determining a device identity corresponding to traffic from the cellular device of the plurality of cellular devices;

applying the plurality of policies based on the device profile; and

forwarding traffic to a destination in the cloud-based environment; and

notifying a tenant for a remediation in case of detection of violation of a policy of the plurality of policies.

9. The clientless security method of claim 8 , wherein the plurality of cellular devices authenticates with the cellular network using a network identifier in the SIM and are in active state with IPv4/IPv6 addresses.

10. The clientless security method of claim 8 , wherein the custom network identifier is used for traffic segregation in the cellular network and the custom network identifier is an APN for a 4G network and a DNN for a 5G network.

11. The clientless security method of claim 8 , wherein the device-to-IP mapping is created using a universal unique mobile subscriber identity (UUMSI) identifier as a primary key.

12. The clientless security method of claim 8 , wherein traffic at the cellular network, on a web and on a firewall side, is analyzed by a server name identification (SNI) based URL filtering method that provides security to the plurality of cellular devices.

13. The clientless security method of claim 8 , wherein the device profile is created by analyzing the plurality of policies, traffic patterns, and device types associated with a plurality of tenants.

14. The clientless security method of claim 8 , wherein the remediation in case of detection of violation of the policy of the plurality of policies further comprises:

blocking a corresponding traffic;

quarantining the cellular device of the plurality of cellular devices; and

allowing limited connectivity to the cellular device of the plurality of cellular devices.

15. A non-transitory computer-readable media having computer-executable instructions embodied thereon that, when executed by one or more processors, facilitate a clientless security method for securing a plurality of cellular devices across a cellular network in a cloud-based environment, the clientless security method comprising:

transmitting traffic from a cellular device of the plurality of cellular devices at the cellular network;

identifying traffic associated with a plurality of network identifiers;

routing traffic towards a gateway of a plurality of gateways in the cloud-based environment using a traffic steering module, wherein the traffic steering module is operable to:

provisioning a Subscriber Identity Module (SIM) with the plurality of network identifiers;

configuring the SIM with a custom network identifier;

creating a device-to-IP mapping;

distributing the device-to-IP mapping to the plurality of gateways in real-time; and

routing traffic to the gateway of the plurality of gateways using the custom network identifier;

applying a plurality of policies based on a device profile in the cloud-based environment using the plurality of gateways, wherein the plurality of gateways is operable to:

receiving traffic from the traffic steering module at the cellular network;

performing a reverse lookup for the cellular device of the plurality of cellular devices using a source IP address;

determining a device identity corresponding to traffic from the cellular device of the plurality of cellular devices;

applying the plurality of policies based on the device profile; and

forwarding traffic to a destination in the cloud-based environment; and

notifying a tenant for a remediation in case of detection of violation of a policy of the plurality of policies.

16. The non-transitory computer-readable media of claim 15 , wherein the plurality of cellular devices authenticates with the cellular network using a network identifier in a SIM and are in active state with IPv4/IPv6 addresses.

17. The non-transitory computer-readable media of claim 15 , wherein the custom network identifier is used for traffic segregation in the cellular network and the custom network identifier is an APN for a 4G network and a DNN for a 5G network.

18. The non-transitory computer-readable media of claim 15 , wherein the device-to-IP mapping is created using a universal unique mobile subscriber identity (UUMSI) identifier as a primary key.

19. The non-transitory computer-readable media of claim 15 , wherein the device profile is created by analyzing the plurality of policies, traffic patterns, and device types associated with a plurality of tenants.

20. The non-transitory computer-readable media of claim 15 , wherein the remediation in case of detection of violation of the policy of the plurality of policies further comprises:

blocking a corresponding traffic; quarantining the cellular device of the plurality of cellular devices; and

allowing limited connectivity to the cellular device of the plurality of cellular devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2024
From: BANERJEE, KALLOL; BOSANAC, JONATHAN; GUNJAN, MILIND
To: NETSKOPE, INC.
Reel/Frame 067955/0595 →
References Cited (139)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7546629B2 · Albert et al. · 2009 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7822972B2 · Lillie et al. · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 9949130B2 · Ophir et al. · 2018 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10178133B2 · Mattes et al. · 2019 [cited by applicant]
US 10200412B2 · Jacobsen et al. · 2019 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10812532B2 · Verma et al. · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11039299B2 · Gui · 2021 [cited by examiner]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 12120022B1 · Thomas · 2024 [cited by examiner]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060075075A1 · Malinen et al. · 2006 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070055752A1 · Wiegand et al. · 2007 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130007837A1 · King · 2013 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130239171A1 · Ramesh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130318346A1 · Libonate · 2013 [cited by examiner]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150099559A1 · Bendixen · 2015 [cited by examiner]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150237500A1 · Muddassir · 2015 [cited by applicant]
US 20150350878A1 · Li · 2015 [cited by examiner]
US 20160234205A1 · An et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170033984A1 · Lear · 2017 [cited by examiner]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20190069122A1 · Karimli · 2019 [cited by examiner]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200314107A1 · Joshi et al. · 2020 [cited by applicant]
US 20210014686A1 · Hu et al. · 2021 [cited by applicant]
US 20210092596A1 · Kudtarkar et al. · 2021 [cited by applicant]
US 20210105617A1 · Mo · 2021 [cited by applicant]
US 20210211862A1 · Chen · 2021 [cited by examiner]
US 20210243083A1 · Martini et al. · 2021 [cited by applicant]
US 20220210656A1 · Shaw et al. · 2022 [cited by applicant]
US 20220329615A1 · Kim et al. · 2022 [cited by applicant]
US 20230328063A1 · Li et al. · 2023 [cited by applicant]
US 20240107294A1 · Silverlock · 2024 [cited by examiner]
US 20240205810A1 · Majjiga · 2024 [cited by examiner]
CN 108076450B · 2022 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
GB 2594827A · 2021 [cited by examiner]
WO WO2022035696A1 · 2022 [cited by examiner]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff Ending Clear Text Protocols, Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al. “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., Farsite: Federated, available, and reliable storage for an incompletely trusted environment, SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ASM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al. , Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html# :˜: text=mode of communication.-,What are the different email proto… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” Tech Target, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?% 20Off… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1 , Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/%2010.1007/978-3-319… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. no date provided. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al. “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs No. date provided. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&p. 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs,. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]
Cited By (3)
US 12,552,406 US 12,615,257 US 12,634,261