IP Library › Granted Patent US 12,309,144
Granted Patent B2
US 12,309,144 · App. 17/225,187 · Granted May 20, 2025

Utilizing endpoint security posture, identification, and remote attestation for restricting private application access

Inventors: Pankaj Chhabra (Surrey, CA); Amandeep Singh (Surrey, CA); Srujan Kotha (Santa Clara, CA); Sandeep Kumar (Panchkula, IN); David Creedy (Los Gatos, CA); Sreedhar Pampati (San Jose, CA)
Assignee: Zscaler, Inc.
H04L63/0853H04L12/4633H04L63/0861H04L63/101H04L63/102H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,144
App. No.
17/225,187
Granted
May 20, 2025
Kind
B2
Abstract

Systems and methods include, responsive to a request to access an application, wherein the application is in one of a public cloud, a private cloud, and an enterprise network, and wherein the user device is remote over the Internet, determining if a user of the user device is permitted to access the application; determining a posture of the user device; and allowing access to the application based on whether the user is permitted to access the application and based on the posture of the user device.

Claims (31)

1. A non-transitory computer-readable medium comprising instructions that, when executed, cause a user device to perform the steps of:

responsive to a request to access a specific application, wherein the specific application is in one of a public cloud, a private cloud, and an enterprise network, and wherein the user device is remote over the Internet, determining if a user of the user device is permitted to access the specific application;

causing a connector application executing on the user device to perform a process check, wherein the process check includes remote attestation-based measurements using a Trusted Platform Module (TPM) and verifying if a specific predetermined process is running on the user device, and wherein the specific predetermined process is a specific endpoint security product;

determining a posture of the user device based on the process check;

in response to determining that the user is not permitted to access the specific application and if the posture fails, notifying the user device the specific application does not exist, wherein the user device is prevented from ascertaining an existence of applications that the user device is not permitted to access; and

in response to determining that the user device is permitted to access the specific application and if the posture passes, stitching together connections between a lightweight connector associated with the specific application, a cloud-based system, and the connector application executing on the user device on a per-user, per-application basis, thereby providing access to only the specific application and not an entire network associated with the specific application.

2. The non-transitory computer-readable medium of claim 1 , wherein the stitching together the connections is on a per-use or per-application basis and includes the cloud-based system creating both a connection to the application on the user device and to the lightweight connector associated with the specific application to enable the user device and the specific application to communicate.

3. The non-transitory computer-readable medium of claim 2 , wherein the stitching together the connections includes at least two tunnels between the user device and the specific application based on connection information.

4. The non-transitory computer-readable medium of claim 1 , wherein the process check includes determining, via the connector application, whether the user device is executing a specific process and, responsive to determining that the specific process is executing on the user device, checking whether a thumbprint of the specific process matches a signer of an executable, thereby verifying that the specific process is a real process signed by a specific signer.

5. The non-transitory computer-readable medium of claim 1 , wherein the posture includes attestation based on a Trusted Platform Module (TPM) on the user device.

6. The non-transitory computer-readable medium of claim 1 , wherein the posture includes identity attestation based on a Trusted Platform Module (TPM) on the user device.

7. A method comprising the steps of:

responsive to a request to access a specific application, wherein the specific application is in one of a public cloud, a private cloud, and an enterprise network, and wherein the user device is remote over the Internet, determining if a user of the user device is permitted to access the specific application;

causing a connector application executing on the user device to perform a process check, wherein the process check includes remote attestation-based measurements using a Trusted Platform Module (TPM) and verifying if a specific predetermined process is running on the user device, and wherein the specific predetermined process is a specific endpoint security product;

determining a posture of the user device based on the process check;

in response to determining that the user is not permitted to access the specific application and if the posture fails, notifying the user device the specific application does not exist, wherein the user device is prevented from ascertaining an existence of applications that the user device is not permitted to access; and

in response to determining that the user device is permitted to access the specific application and if the posture passes, stitching together connections between a lightweight connector associated with the specific application, a cloud-based system, and the connector application executing on the user device on a per-user, per-application basis, thereby providing access to only the specific application and not an entire network associated with the specific application.

8. The method of claim 7 , wherein the stitching together the connections includes the cloud-based system creating both a connection to the application on the user device and to the lightweight connector associated with the specific application to enable the user device and the specific application to communicate.

9. The method of claim 8 , wherein the stitching together the connections includes at least two tunnels between the user device and the specific application.

10. The method of claim 7 , wherein the process check includes determining, via the connector application, whether the user device is executing a specific process and, responsive to determining that the specific process is executing on the user device, checking whether a thumbprint of the specific process matches a signer of an executable, thereby verifying that the specific process is a real process signed by a specific signer.

11. The method of claim 7 , wherein the posture includes attestation based on a Trusted Platform Module (TPM) on the user device.

12. The method of claim 7 , wherein the posture includes identity attestation based on a Trusted Platform Module (TPM) on the user device.

13. A user device comprising:

one or more processors and memory comprising instructions that, when executed, cause the one or more processors to

responsive to a request to access a specific application, wherein the specific application is in one of a public cloud, a private cloud, and an enterprise network, and wherein the user device is remote over the Internet, determining if a user of the user device is permitted to access the specific application;

causing a connector application executing on the user device to perform a process check, wherein the process check includes remote attestation-based measurements using a Trusted Platform Module (TPM) and verifying if a specific predetermined process is running on the user device, and wherein the specific predetermined process is a specific endpoint security product;

determining a posture of the user device based on the process check;

in response to determining that the user is not permitted to access the specific application and if the posture fails, notifying the user device the specific application does not exist, wherein the user device is prevented from ascertaining an existence of applications that the user device is not permitted to access; and

in response to determining that the user device is permitted to access the specific application and if the posture passes, stitching together connections between a lightweight connector associated with the specific application, a cloud-based system, and the connector application executing on the user device on a per-user, per-application basis, thereby providing access to only the specific application and not an entire network associated with the specific application.

14. The user device of claim 13 , wherein the connections are stitched together includes the cloud-based system creating both a connection to the application on the user device and to the lightweight connector associated with the specific application to enable the user device and the specific application to communicate.

15. The user device of claim 13 , wherein the process check includes determining, via the connector application, whether the user device is executing a specific process and, responsive to determining that the specific process is executing on the user device, checking whether a thumbprint of the specific process matches a signer of an executable, thereby verifying that the specific process is a real process signed by a specific signer.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2021
From: SINGH, AMANDEEP; KOTHA, SRUJAN; KUMAR, SANDEEP; CREEDY, DAVID; PAMPATI, SREEDHAR
To: ZSCALER, INC.
Reel/Frame 057690/0936 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2021
From: CHHABRA, PANKAJ
To: ZSCALER, INC.
Reel/Frame 055861/0466 →
Continuity (1)
Related Publication 20220329585A1 · Oct 13, 2022
References Cited (39)
US 6636923B1 · Meirsman et al. · 2003 [cited by applicant]
US 8769644B1 · Eicken · 2014 [cited by examiner]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 11784976B1 · Wei · 2023 [cited by examiner]
US 20060074618A1 · Miller et al. · 2006 [cited by applicant]
US 20060089938A1 · Leonard · 2006 [cited by examiner]
US 20070042756A1 · Perfetto et al. · 2007 [cited by applicant]
US 20080307519A1 · Curcio · 2008 [cited by applicant]
US 20080320308A1 · Kostiainen · 2008 [cited by examiner]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120023325A1 · Lai · 2012 [cited by applicant]
US 20120185913A1 · Martinez et al. · 2012 [cited by applicant]
US 20120281708A1 · Chauhan et al. · 2012 [cited by applicant]
US 20130347072A1 · Dinha · 2013 [cited by applicant]
US 20140022586A1 · Zehler · 2014 [cited by applicant]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20160261564A1 · Foxhoven · 2016 [cited by examiner]
US 20160308859A1 · Barry · 2016 [cited by examiner]
US 20170244729A1 · Fahrny · 2017 [cited by examiner]
US 20170279803A1 · Desai · 2017 [cited by examiner]
US 20190132152A1 · Wang · 2019 [cited by examiner]
US 20190141015A1 · Nellen · 2019 [cited by examiner]
US 20190312860A1 · Dykes · 2019 [cited by examiner]
US 20200084295A1 · Hayward · 2020 [cited by examiner]
US 20200092271A1 · Kumar · 2020 [cited by examiner]
US 20200142608A1 · Nassi · 2020 [cited by examiner]
US 20200412608A1 · Dunbar · 2020 [cited by examiner]
US 20210083900A1 · Shaw · 2021 [cited by examiner]
US 20210105275A1 · Bansal · 2021 [cited by examiner]
US 20210168125A1 · Vemulpali · 2021 [cited by examiner]
US 20210367920A1 · Devarajan · 2021 [cited by examiner]
US 20220036352A1 · De Vos · 2022 [cited by examiner]
US 20220210173A1 · Katmor · 2022 [cited by examiner]
US 20220224023A1 · Graham · 2022 [cited by examiner]
US 20220224621A1 · Devarajan · 2022 [cited by examiner]
US 20220287151A1 · Howe · 2022 [cited by examiner]
US 20220368631A1 · Narula · 2022 [cited by examiner]