IP Library Granted Patent US 12,413,624
Granted Patent B2
US 12,413,624 · App. 17/726,579 · Granted Sep 9, 2025

Cyber secure communications system

Inventors: Ofer Ben-Noon (Tel Aviv, IL); Ohad Bobrov (Tel Aviv, IL); Gilad Roth (Modi+30 in Makabim-Re+30 ut, IL); Guy Harpak (Ramat Gan, IL); Ido Salomon (Tel Aviv, IL)
Assignee: Palo Alto Networks, Inc.
H04L63/20G06F16/955G06F21/44G06F21/53G06F21/57H04L41/16H04L63/0428H04L63/08H04L63/083H04L63/10H04L63/102H04L63/1416H04L63/1425H04L63/1433H04L67/125H04L67/55H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,624
App. No.
17/726,579
Granted
Sep 9, 2025
Kind
B2
Abstract

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.

Claims (35)

1. A system comprising:

a user equipment (UE) having thereon ambient software secure isolated environment comprising a secure web browser (SWB), wherein the secure isolated environment the SWB from the ambient software in the UE;

the SWB configured to obtain a security token to access one or more digital resources of an enterprise and configured to monitor and control ingress and egress data with respect to the secure isolated environment, wherein the SWB configured to control the ingress and egress data comprises the SWB configured to enforce one or more security constraints of an enterprise associated with the UE on the ingress and egress data,

wherein the secure isolated environment is configured to run a set of one or more software integrity tests of the SWB according to a testing policy of the enterprise, and wherein the SWB being configured to obtain a security token comprises the SWB being configured to obtain the security token if a sufficient integrity value is determined from the one or more software integrity tests.

2. The system according to claim 1 wherein the secure isolated environment wraps at least one software application to conform with the one or more security constraints which are defined by a security policy of the enterprise.

3. The system according to claim 2 wherein the secure isolated environment comprises at least one secure service application useable by the SWB and the at least one wrapped application.

4. The system according to claim 2 wherein communications between wrapped applications in the secure isolated environment is via a secure encrypted communication channel and communications between the SWB and a wrapped application are via a secure encrypted communication channel.

5. The system according to claim 1 wherein the SWB monitors communications of a user of the UE to acquire data characterizing browsing behavior of the user and websites that the user visits.

6. The system according to claim 1 further comprising a data processing hub having a secure communication channel with the SWB, wherein at least one of the hub and the SWB processes the acquired data to determine normal patterns of interaction of the user with websites that the user accesses.

7. The system according to claim 1 wherein, the secure isolated environment is configured to determine risk of at least one of the ambient software and a user and to determine whether cladding of the SWB is sufficient with respect to the determined risk, and wherein the SWB being configured to obtain the security token comprises the SWB being configured to obtain the security token if the cladding is sufficient.

8. A method comprising: isolating a web browser within a secure isolated environment on a user equipment (UE) from ambient software also on the UE;

authenticating a web browser with an extended identifier;

after authenticating the web browser, running a set of one or more software integrity tests of the web browser according to a testing policy of an enterprise;

determining whether the web browser has a sufficient integrity value from the one or more software integrity tests;

based on successful authentication of the web browser and determining that the web browser has a sufficient integrity value, issuing the web browser a security token to access one or more digital resources of the enterprise; and

after the web browser is issued the security token, the web browser monitoring and controlling ingress and egress data with respect to the secure isolated environment, wherein the web browser controlling the ingress and egress data comprises the web browser enforcing one or more security constraints of the enterprise on the ingress and egress data.

9. The method of claim 8 further comprising the secure isolated environment wrapping at least one software application to conform with the one or more security constraints which are defined by a security policy of the enterprise.

10. The method of claim 8 , wherein authenticating the web browser comprises requesting a data processing hub of the enterprise to authenticate the browser.

11. The method of claim 8 , wherein the extended identifier comprises a browser identifier, a user identifier, and an identifier of the UE.

12. The method of claim 8 , further comprising the web browser acquiring data characterizing browsing behavior of a user and websites that the user visits, while monitoring the ingress and egress data.

13. The method of claim 12 further comprising the web browser processing the acquired data to determine normal behavior patterns or the web browser communicating the acquired data to a data processing hub of the enterprise via a secure communication channel with the web browser and the data processing hub processing the acquired data to determine normal patterns of behavior with respect to the user interaction with website.

14. The method of claim 8 further comprising:

running software environment safety tests on the ambient software;

retrieving a risk profile of a user identified with a user identifier that is part of the extended identifier;

determining risk based on a result of the software environment safety tests and based on the risk profile; and

determining whether cladding of the web browser is sufficient with respect to the determined risk,

wherein issuing the web browser the security token is also based on determining that the cladding is sufficient.

15. The method of claim 14 further comprising amending the cladding after an initial determination that the cladding is insufficient and then determining that the cladding is sufficient after amending the cladding.

16. The method of claim 8 , wherein authenticating the web browser comprises requesting an identity service provider to authenticate the web browser and then, based on successful authentication of the web browser, determining whether the web browser is permitted to access digital resources of the enterprise.

17. The method of claim 8 further comprising retrieving the set of software integrity tests.

18. The method of claim 17 further comprising:

determining a weight for each of the set of software integrity tests, wherein the weights are based on at least one of a type of the UE, true positive rate of the corresponding software integrity test, true negative rate of the corresponding software integrity test, nuisance rating, past performance of the corresponding software integrity test, and a current cybersecurity context,

wherein running the set of one or more software integrity tests on the web browser comprises selecting which of the set of software integrity tests to run based on the weighting.

19. The method of claim 8 , wherein running a set of one or more software integrity tests of the web browser according to a testing policy of an enterprise comprises running the set of software integrity tests based on at least one of frequency of user activity with known malicious websites and time since software integrity of the web browser was tested.

20. The method of claim 8 , wherein the web browser monitoring ingress and egress data comprises the web browser acquiring at least one of data characterizing browser extensions and data indicating access behavior with respect to the digital resources.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2025
From: TALON CYBER SECURITY LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 069993/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2022
From: BEN-NOON, OFER; BOBROV, OHAD; ROTH, GILAD; HARPAK, GUY; SALOMON, IDO
To: TALON CYBER SECURITY LTD.
Reel/Frame 060313/0584 →
Continuity (2)
Provisional Application 63177998 · Apr 22, 2021
Related Publication 20220366050A1 · Nov 17, 2022
References Cited (84)
US 7698398B1 · Lai · 2010 [cited by applicant]
US 8069435B1 · Lai · 2011 [cited by applicant]
US 8132242B1 · Wu · 2012 [cited by applicant]
US 8151349B1 · Yee · 2012 [cited by applicant]
US 8346929B1 · Lai · 2013 [cited by applicant]
US 8752183B1 · Heiderich et al. · 2014 [cited by applicant]
US 9021254B2 · Bokarius et al. · 2015 [cited by applicant]
US 9032519B1 · Maher · 2015 [cited by examiner]
US 9348663B1 · Boodman · 2016 [cited by examiner]
US 9521032B1 · Worsley · 2016 [cited by applicant]
US 9547769B2 · Aissi et al. · 2017 [cited by applicant]
US 9635041B1 · Warman et al. · 2017 [cited by applicant]
US 9948612B1 · Jawahar · 2018 [cited by examiner]
US 10356693B2 · Reith · 2019 [cited by applicant]
US 10599486B1 · Borkar et al. · 2020 [cited by applicant]
US 10798140B1 · Mercier et al. · 2020 [cited by applicant]
US 10848571B2 · Fleck et al. · 2020 [cited by applicant]
US 10855754B1 · Mercier et al. · 2020 [cited by applicant]
US 10908785B2 · Borkar et al. · 2021 [cited by applicant]
US 10963532B2 · Borkar et al. · 2021 [cited by applicant]
US 11019066B2 · Borkar et al. · 2021 [cited by applicant]
US 11061999B2 · Borkar et al. · 2021 [cited by applicant]
US 11075984B1 · Mercier et al. · 2021 [cited by applicant]
US 11087008B2 · Borkar et al. · 2021 [cited by applicant]
US 11093570B2 · Chauhan · 2021 [cited by applicant]
US 11153285B2 · Chauhan et al. · 2021 [cited by applicant]
US 11153306B2 · Chauhan · 2021 [cited by applicant]
US 11159552B2 · Fleck et al. · 2021 [cited by applicant]
US 11233832B2 · Chauhan et al. · 2022 [cited by applicant]
US 11265337B2 · Smelov et al. · 2022 [cited by applicant]
US 11275811B2 · Borkar et al. · 2022 [cited by applicant]
US 11323327B1 · Chitalia et al. · 2022 [cited by applicant]
US 11328077B2 · Fleck et al. · 2022 [cited by applicant]
US 11381610B2 · Le Strat et al. · 2022 [cited by applicant]
US 11412003B1 · Lyon et al. · 2022 [cited by applicant]
US 11429243B2 · Fleck et al. · 2022 [cited by applicant]
US 11450069B2 · Chauhan · 2022 [cited by applicant]
US 11469979B2 · Chauhan · 2022 [cited by examiner]
US 11475146B2 · Chauhan · 2022 [cited by applicant]
US 12026711B2 · LeBel · 2024 [cited by examiner]
US 20050044197A1 · Lai · 2005 [cited by applicant]
US 20080301794A1 · Lee · 2008 [cited by applicant]
US 20090138804A1 · Shepherd et al. · 2009 [cited by applicant]
US 20090216910A1 · Duchesneau · 2009 [cited by applicant]
US 20100050244A1 · Tarkhanyan et al. · 2010 [cited by applicant]
US 20120084184A1 · Raleigh et al. · 2012 [cited by applicant]
US 20130297700A1 · Hayton et al. · 2013 [cited by applicant]
US 20140237576A1 · Zhang et al. · 2014 [cited by applicant]
US 20150007291A1 · Miller · 2015 [cited by applicant]
US 20150113092A1 · Chadha et al. · 2015 [cited by applicant]
US 20150201417A1 · Raleigh et al. · 2015 [cited by applicant]
US 20160261627A1 · Lin · 2016 [cited by applicant]
US 20170111322A1 · Patidar et al. · 2017 [cited by applicant]
US 20170187839A1 · Raleigh et al. · 2017 [cited by applicant]
US 20180359244A1 · Cockerill et al. · 2018 [cited by applicant]
US 20190065177A1 · Khoongumjorn · 2019 [cited by examiner]
US 20190261169A1 · Kamal · 2019 [cited by examiner]
US 20200092382A1 · Borkar · 2020 [cited by examiner]
US 20200097614A1 · Borkar et al. · 2020 [cited by applicant]
US 20200177546A1 · Petry · 2020 [cited by examiner]
US 20200296776A1 · Raleigh et al. · 2020 [cited by applicant]
US 20210176336A1 · Fleck · 2021 [cited by applicant]
US 20210185015A1 · Sapp et al. · 2021 [cited by applicant]
US 20220038282A1 · Teramoto et al. · 2022 [cited by applicant]
US 20220094547A1 · Duchastel et al. · 2022 [cited by applicant]
US 20220116345A1 · Xu · 2022 [cited by examiner]
US 20220217169A1 · Varanda · 2022 [cited by applicant]
US 20220417277A1 · Ben-Noon et al. · 2022 [cited by applicant]
US 20230122247A1 · Ben-Noon et al. · 2023 [cited by applicant]
US 20230308451A1 · Ben-Noon et al. · 2023 [cited by applicant]
JP 2016526201A · 2016 [cited by applicant]
KR 102038842 · 2019 [cited by applicant]
WO 0175564 · 2001 [cited by applicant]
WO 2014048751A1 · 2014 [cited by applicant]
WO 2022224262A1 · 2022 [cited by applicant]
“Azure AD Conditional Access Documention”, Microsoft Docs, (downloaded May 25, 2022) https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/. [cited by applicant]
Barth A., et al., “The Security Architecture of the Chromium Browser” https://seclab.stanford.edu/websec/chromium/chromium-security-architecture.pdf. [cited by applicant]
International Preliminary Report on Patentability dated Aug. 8, 2023 for application No. PCT/IL2022/050416 filed Apr. 22, 2022. [cited by applicant]
International Search Report dated Aug. 12, 2022 for application No. PCT/IL2022/050416 filed Apr. 22, 2022. [cited by applicant]
U.S. Appl. No. 17/841,727, Non-Final Office Action mailed May 8, 2024, 20 pages. [cited by applicant]
U.S. Appl. No. 17/893,226, Non-Final Office Action mailed Jul. 3, 2024, 11 pages. [cited by applicant]
EP Application No. 22725568.4, Communication Pursuant to Article 94(3) EPC mailed May 9, 2025, 6 pages. [cited by applicant]
JP Application No. 2023565437, Office Action mailed May 20, 2025, 21 pages, including English translation. [cited by applicant]
U.S. Appl. No. 18/127,681, Non-Final Office action mailed Feb. 12, 2025, 30 pages. [cited by applicant]
Cited By (1)
US 12,676,855