IP Library Granted Patent US 12,368,697
Granted Patent B2
US 12,368,697 · App. 17/352,651 · Granted Jul 22, 2025

Private service edge nodes in a cloud-based system for private application access

Inventors: John A. Chanak (Saratoga, CA); Ale A. Mansoor (Apex, NC); Maxim Perepelitsyn (San Jose, CA); Deepak Khungar (Bangalore, IN); William Fehring (Sunnyvale, CA)
Assignee: Zscaler, Inc.
H04L63/0272G06F9/547H04L9/006H04L9/0894H04L9/14H04L9/30H04L9/3263H04L63/029H04L63/0823H04L63/0876H04L67/1021H04L67/1097H04L61/4511H04L61/59
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,697
App. No.
17/352,651
Granted
Jul 22, 2025
Kind
B2
Abstract

Systems and methods include, connecting to a first service edge node in a cloud-based system and obtaining one or more addresses each for one or more service edge nodes in the cloud-based system, wherein the one or more service edge nodes include public service edge nodes and private service edge nodes; connecting to a second service edge node of the one or more service edge nodes using the corresponding address; providing a request for an application to the second service edge node; and responsive to policy and accessibility determined via the cloud-based system, receiving access to the application via a connector adjacent to the application.

Claims (33)

1. A method implemented at a user device comprising:

connecting to a first service edge node, the connecting being facilitated by a connector application executing on the user device dialing out to the first service edge node, wherein the first service edge node is a public service edge node located within a cloud-based system configured to support a data connection from the connector application;

obtaining from the first service edge node, at the connector application executing on the user device, one or more addresses each for one or more additional service edge nodes, wherein the one or more additional service edge nodes include private service edge nodes;

dialing out via a redirection proxy and connecting to a second service edge node of the one or more additional service edge nodes using a corresponding address, wherein the redirection proxy is on-premises and provides on-demand dial-out capability and tunneling of authenticated traffic, and wherein the second service edge node is a private service edge node located within an enterprise network configured to setup a connection with an application and a virtual connector associated with the application;

providing a request for the application to the second service edge node; and

responsive to policy and accessibility determined via the second service edge node, receiving access to the application via the virtual connector associated with the application.

2. The method of claim 1 , wherein the user device is remote from the enterprise network, and the method further comprising

connecting to the second service edge node via one or more additional secure multiple hops defining tunnels dynamically formed between the second service edge node and the connector.

3. The method of claim 1 , wherein the second service edge node includes a publish address where it can open connections and listen address where it can accept incoming connections, and wherein the second service edge node, based on the policy, accepts connections from the connector application and the virtual connector associated with the application via the publish and listen addresses.

4. The method of claim 1 , wherein connecting to a second service edge node further comprises

attempting to connect to each of the one or more service edge nodes in the cloud-based system until a secure tunnel session is achieved, and connecting to the second service edge node via the secure tunnel formed between the second service edge node and the connector application, the secure tunnel is created through software without dedicated hardware and defining one of Transport Layer Security (TLS) or a proprietary approach.

5. The method of claim 4 , wherein the one or more secure tunnels are between corresponding service edge nodes, the connector application executing on the user device, and a specific virtual connector associated with the application.

6. The method of claim 5 , wherein the corresponding service edge nodes include both public service edge nodes and private service edge nodes.

7. The method of claim 1 , wherein the connector and the second service edge node are both configured to dial out tunnel connections and establish an on-demand tunnel to receive packets.

8. The method of claim 1 , wherein the obtained addresses are provided based on utilization of the one or more service edge nodes.

9. A method implemented at a private service edge node within an enterprise network communicatively coupled to a cloud-based system, wherein the cloud-based system includes a plurality of service edge nodes including public service edge nodes and private service edge nodes configured to setup a data connection to a private application, the method comprising:

receiving a request for the private application within the enterprise network from an application executing on a user device;

receiving a connection from a specific virtual connector associated with the private application via one or more publish and listen IP addresses;

connecting by dialing out via a redirection proxy to the application executing on the user device via one or more additional secure tunnels formed between the private service edge node and the connector, wherein the redirection proxy is on-premises and provides on-demand dial-out capability and tunneling of authenticated traffic, and

responsive to policy and accessibility determined via the cloud-based system, receiving the connection from the application executing on the user device and allowing access to the private application via the virtual connector and enforcing the policy.

10. The method of claim 9 , wherein the user device is on-premises on the enterprise network.

11. The method of claim 9 , wherein the private service edge node includes a publish address where it can open connections and listen address where it can accept incoming connections.

12. A non-transitory computer-readable medium comprising instructions that, when executed, cause a user device to perform the steps of:

connecting to a first service edge node, the connecting being facilitated by a connector application executing on the user device dialing out to the first service edge node, wherein the first service edge node is a public service edge node located within a cloud-based system configured to support a data connection from the connector application;

obtaining from the first service edge node, at the connector application executing on the user device, one or more addresses each for one or more additional service edge nodes, wherein the one or more additional service edge nodes include private service edge nodes;

dialing out via a redirection proxy and connecting to a second service edge node of the one or more additional service edge nodes using a corresponding address, wherein the redirection proxy is on-premises and provides on-demand dial-out capability and tunneling of authenticated traffic, and wherein the second service edge node is a private service edge node located within an enterprise network configured to setup a connection with an application and a virtual connector associated with the application;

providing a request for the application to the second service edge node; and responsive to policy and accessibility determined via the second service edge node, receiving access to the application via the virtual connector associated with the application.

13. The non-transitory computer-readable medium of claim 12 wherein the user device is remote from the enterprise network, and the steps include

connecting to the private service edge node via one or more additional secure tunnels formed between the private service edge node and the connector.

14. The non-transitory computer-readable medium of claim 12 , wherein the private service edge node includes publish address where it can open connections and listen address where it can accept incoming connections, and wherein the second service edge node, based on the policy, accepts connections from the connector application and the virtual connector associated with the application via the publish and listen addresses.

15. The non-transitory computer-readable medium of claim 12 , wherein connecting to a second service edge node further comprises

attempting to connect to each of the one or more service edge nodes in the cloud-based system until a secure tunnel session is achieved, and connecting to the second service edge node via the secure tunnel formed between the private service edge node and the connector application.

16. The method of claim 12 , wherein the connector and the private service edge node are both configured to dial out tunnel connections.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2021
From: CHANAK, JOHN A.; MANSOOR, ALE A.; PEREPELITSYN, MAXIM; KHUNGAR, DEEPAK; FEHRING, WILLIAM
To: ZSCALER, INC.
Reel/Frame 056601/0585 →
Continuity (4)
Continuation In Part 16800307 · Feb 25, 2020
Continuation 15986874 · May 23, 2018
Continuation In Part 15158153 · May 18, 2016
Related Publication 20210314301A1 · Oct 7, 2021
References Cited (27)
US 6636923B1 · Meirsman et al. · 2003 [cited by applicant]
US 8806606B2 · Ahmad · 2014 [cited by examiner]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 20050073982A1 · Corneille · 2005 [cited by examiner]
US 20060074618A1 · Miller et al. · 2006 [cited by applicant]
US 20070042756A1 · Perfetto et al. · 2007 [cited by applicant]
US 20080307519A1 · Curcio · 2008 [cited by applicant]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120023325A1 · Lai · 2012 [cited by applicant]
US 20120185913A1 · Martinez et al. · 2012 [cited by applicant]
US 20120281708A1 · Chauhan et al. · 2012 [cited by applicant]
US 20130347072A1 · Dinha · 2013 [cited by applicant]
US 20140022586A1 · Zehler · 2014 [cited by applicant]
US 20140164584A1 · Joe · 2014 [cited by examiner]
US 20140173694A1 · Kranz · 2014 [cited by examiner]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20150006730A1 · Helfman · 2015 [cited by examiner]
US 20150200974A1 · Pearce · 2015 [cited by examiner]
US 20160149926A1 · Ancin · 2016 [cited by examiner]
US 20190372960A1 · Huang · 2019 [cited by examiner]
EP 3381171B1 · 2021 [cited by examiner]
WO WO2017091709A1 · 2017 [cited by examiner]
WO WO2018022908A1 · 2018 [cited by examiner]
J. R. Vic Winkler, “Securing the Cloud: Cloud Computer Security Techniques and Tactics”, May 2011, Syngress Publishing, Full Text. [cited by applicant]
Stephen R. Smoot, “Private Cloud Computing: Consolidation, Virtualization, and Service-Oriented Infrastructure”, Oct. 2011, Morgan Kaufman Publishers, Inc. Full Text. [cited by applicant]