IP Library Granted Patent US 12,368,698
Granted Patent B2
US 12,368,698 · App. 17/490,502 · Granted Jul 22, 2025

Systems and methods for providing scalable per-client private application access directories

Inventors: John A. Chanak (Saratoga, CA); Xiang Yu (San Jose, CA); Ramesh Kumar Somasundaram (Sunnyvale, CA); Anjali Anjali (Burnaby, CA); Andrey Tverdokhleb (Cupertino, CA); Vikas Mahajan (Ludhiana, IN)
Assignee: Zscaler, Inc.
H04L63/0272G06F9/547H04L9/006H04L9/0894H04L9/14H04L9/30H04L9/3263H04L63/029H04L63/0823H04L63/0876H04L67/01H04L67/10H04L67/1021H04L45/76H04L61/4511H04L61/59
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,698
App. No.
17/490,502
Granted
Jul 22, 2025
Kind
B2
Abstract

Systems and methods implemented via a broker in a cloud-based system include steps of, responsive to a user and associated user device executing a client connector being authenticated, receiving a notification from the client connector; determining private applications accessible by the user based on policy, wherein the private applications are located in one of a public cloud, a private cloud, and an enterprise network; and sending a Top-Level Domain+1 (TLD+1) list of the accessible private applications to the user device, wherein the TLD+1 includes a TLD and a domain name.

Claims (56)

1. A method implemented at a broker in a cloud-based system, the method comprising:

responsive to a user and associated user device executing a client connector being authenticated, receiving, at the broker, a notification from the client connector;

determining private applications accessible by the user based on policy, wherein the private applications are located in one of a public cloud, a private cloud, and an enterprise network;

sending a Top-Level Domain+1 (TLD+1) list of the accessible private applications associated with the determined private applications accessible by the user to the client connector executing on the user device, wherein the TLD+1 list includes a list of TLDs and domain names accessible by the user;

receiving updates for the private applications for the user, based on a user-specific change;

dynamically determining a new TLD+1 list based on the updates;

sending the new TLD+1 list to the client connector; and

causing the client connector to clear a local cache responsive to receiving the new TLD+1 list.

2. The method of claim 1 , further comprising

receiving a Fully Qualified Domain Name (FQDN) from the user device for a private application; and

checking via a DNS check request sent to the broker if the FQDN is a qualified private application.

3. The method of claim 2 , wherein the checking utilizes a hash table to check the FQDN against the TLD+1, the hash table is updated dynamically responsive to a policy change.

4. The method of claim 2 , further comprising

providing the client connector a response when the FQDN is the qualified private application.

5. The method of claim 2 , further comprising

receiving a request to access the qualified private application; and

stitching together connections between the user device and the broker and between the broker and an app connector connected to the qualified private application.

6. The method of claim 1 , further comprising

responsive to a reconnect or network change, resending the Top-Level Domain+1 (TLD+1) list to the client connector.

7. A non-transitory computer-readable storage medium having computer readable code stored thereon for programming at least one processor at a broker to perform steps of:

responsive to a user and associated user device executing a client connector being authenticated, receiving, at the broker, a notification from the client connector;

determining private applications accessible by the user based on policy, wherein the private applications are located in one of a public cloud, a private cloud, and an enterprise network;

sending a Top-Level Domain+1 (TLD+1) list of the accessible private applications associated with the determined private applications accessible by the user to the client connector executing on the user device, wherein the TLD+1 list includes a list of TLDs and domain names accessible by the user;

receiving updates for the private applications for the user, based on a user-specific change;

dynamically determining a new TLD+1 list based on the updates;

sending the new TLD+1 list to the client connector; and

causing the client connector to clear a local cache responsive to receiving the new TLD+1 list.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the steps further include

receiving a Fully Qualified Domain Name (FQDN) from the user device for a private application; and

checking if the FQDN is a qualified private application.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the checking utilizes a hash table to check the FQDN against the TLD+1.

10. The non-transitory computer-readable storage medium of claim 8 , wherein the steps further include

providing the client connector a response when the FQDN is the qualified private application.

11. The non-transitory computer-readable storage medium of claim 8 , wherein the steps further include

receiving a request to access the qualified private application; and

stitching together connections between the user device and the broker and between the broker and an app connector connected to the qualified private application.

12. The non-transitory computer-readable storage medium of claim 7 , wherein the steps further include

responsive to a reconnect or network change, resending the Top-Level Domain+1 (TLD+1) list to the client connector.

13. A broker device in a cloud-based system comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to

responsive to a user and associated user device executing a client connector being authenticated, receive, at the broker device, a notification from the client connector;

determine private applications accessible by the user based on policy, wherein the private applications are located in one of a public cloud, a private cloud, and an enterprise network;

send a Top-Level Domain+1 (TLD+1) list of the accessible private applications associated with the determined private applications accessible by the user to the client connector executing on the user device, wherein the TLD+1 list includes a list of TLDs and domain names accessible by the user;

receiving updates for the private applications for the user, based on a user-specific change;

dynamically determining a new TLD+1 list based on the updates;

sending the new TLD+1 list to the client connector; and

causing the client connector to clear a local cache responsive to receiving the new TLD+1 list.

14. The broker device of claim 13 , wherein the instructions that, when executed, cause the one or more processors to

receive a Fully Qualified Domain Name (FQDN) from the user device for a private application; and

check if the FQDN is a qualified private application.

15. The broker device of claim 14 , wherein the checking utilizes a hash table to check the FQDN against the TLD+1.

16. The broker device of claim 14 , wherein the instructions that, when executed, cause the one or more processors to

providing the client connector a response when the FQDN is the qualified private application.

17. The broker device of claim 14 , wherein the instructions that, when executed, cause the one or more processors to

receiving a request to access the qualified private application; and

stitching together connections between the user device and the broker device and between the broker device and an app connector connected to the qualified private application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2021
From: CHANAK, JOHN A.; YU, XIANG; SOMASUNDARAM, RAMESH KUMAR; ANJALI, ANJALI; TVERDOKHLEB, ANDREY; MAHAJAN, VIKAS
To: ZSCALER, INC.
Reel/Frame 057657/0881 →
Priority Claims (1)
IN 202111037489 · Aug 18, 2021 · national
Continuity (4)
Continuation In Part 16800307 · Feb 25, 2020
Continuation 15986874 · May 23, 2018
Continuation In Part 15158153 · May 18, 2016
Related Publication 20220029965A1 · Jan 27, 2022
References Cited (24)
US 6636923B1 · Meirsman et al. · 2003 [cited by applicant]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 9083727B1 · Stamos · 2015 [cited by examiner]
US 20060015722A1 · Rowan · 2006 [cited by examiner]
US 20060074618A1 · Miller et al. · 2006 [cited by applicant]
US 20070042756A1 · Perfetto et al. · 2007 [cited by applicant]
US 20080235383A1 · Schneider · 2008 [cited by examiner]
US 20080307519A1 · Curcio · 2008 [cited by applicant]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120023325A1 · Lai · 2012 [cited by applicant]
US 20120185913A1 · Martinez et al. · 2012 [cited by applicant]
US 20120281708A1 · Chauhan et al. · 2012 [cited by applicant]
US 20130297700A1 · Hayton · 2013 [cited by examiner]
US 20130347072A1 · Dinha · 2013 [cited by applicant]
US 20140022586A1 · Zehler · 2014 [cited by applicant]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20150264055A1 · Budhani · 2015 [cited by examiner]
US 20170262651A1 · Kaliski, Jr. · 2017 [cited by examiner]
US 20180007090A1 · Cao · 2018 [cited by examiner]
US 20180173799A1 · McGarvey · 2018 [cited by examiner]
J. R. Vic Winkler, “Securing the Cloud: Cloud Computer Security Techniques and Tactics,” May 2011, Syngress Publishing, Full Text. [cited by applicant]
Stephen R. Smoot, “Private Cloud Computing: Consolidation, Virtualization, and Service-Oriented Infrastructure,” Oct. 2011, Morgan Kaufman Publishers, Inc. Full Text. [cited by applicant]