IP Library Granted Patent US 12,418,512
Granted Patent B2
US 12,418,512 · App. 18/089,997 · Granted Sep 16, 2025

Alias domains for accessing ZTNA applications

Inventors: Robert Paul Andrews (Pflugerville, TX); Venkata Suresh Reddy Obulareddy (Bangalore, IN); Harsha A R (Mysore, IN); Neha Parshottam Patel (Pune, IN)
Assignee: Sophos Limited
H04L63/0281H04L61/302H04L63/029H04L63/20H04L41/12H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,512
App. No.
18/089,997
Granted
Sep 16, 2025
Kind
B2
Abstract

A cloud computing platform provides zero trust network access as a service to customers that maintain applications on-premises. In this context, the cloud computing platform may associate customers and/or applications with specific service proxies, and add an abstraction layer for network access that maps an alias domain for each customer and/or application to a network load balancer associated with the specific service proxies associated with the corresponding application(s). This approach advantageously simplifies the configuration of service proxies at the cloud computing platform by permitting dedicated relationships among network load balancers, specific service proxies, and specific applications, while concurrently reducing or avoiding the administrative burden on customers of updating network pointers when the clusters of service proxies are periodically reconfigured to adjust to varying user traffic.

Claims (41)

1. A computer program product comprising computer executable code embodied in non-transitory computer executable code that, when executing on one or more computing devices, causes the one or more computing devices to perform the steps of:

creating a cluster of service proxies on a cloud computing platform, the cluster of service proxies including one or more service proxies configured to provide access to an application on a customer premises;

coupling the one or more service proxies to a network load balancer from a plurality of network load balancers for the cloud computing platform;

creating an alias domain for zero trust network access to the application, the alias domain identified by a fully qualified domain name associated with the application;

providing an abstraction layer for the cloud computing platform that maps requests for the alias domain for the application to the network load balancer coupled to the one or more service proxies configured to provide access to the application on the customer premises;

receiving a request from a client at the cloud computing platform for the application;

connecting the request to the network load balancer with the abstraction layer;

selecting one of the one or more service proxies for the application with the network load balancer;

connecting the request to the selected one of the one or more service proxies with the network load balancer; and

connecting the request to the application with the one of the one or more service proxies.

2. The computer program product of claim 1 , further comprising code that causes the one or more computing devices to authenticate the client for zero trust network access to the application.

3. The computer program product of claim 1 , further comprising code that causes the one or more computing devices to execute a threat management facility hosted remotely from the customer premises, the threat management facility configured to provide security services for the customer premises.

4. The computer program product of claim 3 , wherein the threat management facility is configured to provide a control plane for zero trust network access to the application hosted on the customer premises.

5. The computer program product of claim 3 , wherein creating the alias domain includes creating the alias domain at the threat management facility and transmitting the alias domain to the cloud computing platform.

6. The computer program product of claim 1 , wherein the cloud computing platform is configured to provide a data plane for zero trust network access to the application hosted on the customer premises.

7. The computer program product of claim 1 , wherein the cloud computing platform includes a cloud-based zero trust network access platform configured to provide zero trust network access as a service to a plurality of customers associated with a plurality of customer premises including the customer premises.

8. A method comprising:

hosting a cluster of service proxies on a cloud computing platform, the cluster of service proxies including one or more service proxies configured to provide access to an application on a customer premises;

coupling the one or more service proxies of the cluster of service proxies to a network load balancer from a plurality of network load balancers for the cloud computing platform;

creating an alias domain for the application; and

providing an abstraction layer for the cloud computing platform that maps requests for the alias domain for the application to the network load balancer coupled to the one or more service proxies configured to provide access to the application on the customer premises.

9. The method of claim 8 , further comprising:

receiving a request from a client at the cloud computing platform for the application;

connecting the request to the network load balancer with the abstraction layer; selecting a service proxy from the cluster of service proxies with the network load balancer; and

transmitting the request to the application through the service proxy.

10. The method of claim 9 , wherein the application includes a zero trust network application hosted on the customer premises.

11. The method of claim 9 , wherein transmitting the request to the application includes authenticating the application for zero trust network access to the application.

12. The method of claim 9 , wherein transmitting the request to the application includes transmitting the request through a zero trust network access appliance hosted on the customer premises.

13. The method of claim 12 , wherein transmitting the request to the application includes transmitting the request through a reverse proxy server hosted on the cloud computing platform, the reverse proxy server securely coupled to the zero trust network access appliance hosted on the customer premises.

14. The method of claim 13 , wherein the reverse proxy server is coupled to the zero trust network access appliance through a second network load balancer.

15. The method of claim 13 , wherein the cluster of service proxies is a dedicated cluster servicing one or more predetermined applications.

16. The method of claim 15 , wherein the one or more predetermined applications are associated with at least two customers having different customer premises.

17. A system comprising:

a customer premises hosting an application, the customer premises including a zero trust network access appliance configured to provide zero trust network access to the application through a secure tunnel; and

a cloud computing platform coupled to the zero trust network access appliance through the secure tunnel, the cloud computing platform comprising one or more processors and memory storing code that, when executing on the one or more processors, performs the steps of:

hosting a cluster of service proxies, the cluster of service proxies including one or more service proxies configured to provide access to the application,

providing a network load balancer associated with the one or more service proxies configured to provide access to the application, and

providing an abstraction layer that maps requests for an alias domain name associated with the application to the network load balancer coupled to the one or more service proxies configured to provide access to the application on the customer premises.

18. The system of claim 17 , further comprising a threat management facility configured to provide a control plane for zero trust network access to the application, the threat management facility further configured to manage network security for the customer premises, the threat management facility further configured to generate the alias domain name for the application, and transmit the alias domain name to the cloud computing platform for use as the alias domain name in the abstraction layer.

19. The system of claim 17 , wherein the cloud computing platform hosts a plurality of clusters of proxies, each one of the plurality of clusters of proxies associated with a predetermined number of applications in a group of applications different from each other one of the plurality of clusters of proxies.

20. The system of claim 17 , wherein the cloud computing platform is configured to add a first service proxy to the cluster of service proxies or remove a second service proxy from the cluster of service proxies based on a demand for use of the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2023
From: ANDREWS, ROBERT PAUL; OBULAREDDY, VENKATA SURESH REDDY; A R, HARSHA; PATEL, NEHA PARSHOTTAM
To: SOPHOS LIMITED
Reel/Frame 062384/0195 →
Priority Claims (1)
IN 202211058975 · Oct 15, 2022 · national
Continuity (2)
Continuation PCTUS2022054075 · Dec 27, 2022
Related Publication 20240129277A1 · Apr 18, 2024
References Cited (99)
US 8396969B1 · Schwartz et al. · 2013 [cited by applicant]
US 11036885B1 · Abdelkader et al. · 2021 [cited by applicant]
US 11240242B1 · Celik · 2022 [cited by applicant]
US 11689522B2 · Kulkarni et al. · 2023 [cited by applicant]
US 11783925B2 · Ansari et al. · 2023 [cited by applicant]
US 11811734B2 · Chen et al. · 2023 [cited by applicant]
US 11895092B2 · Glazemakers et al. · 2024 [cited by applicant]
US 11949661B2 · Shah et al. · 2024 [cited by applicant]
US 12010141B1 · Mogra et al. · 2024 [cited by applicant]
US 12095794B1 · Karaje et al. · 2024 [cited by applicant]
US 12101247B2 · Vysotsky et al. · 2024 [cited by applicant]
US 20120017259A1 · Maccarthaigh · 2012 [cited by applicant]
US 20120331528A1 · Fu et al. · 2012 [cited by applicant]
US 20170310693A1 · Howard et al. · 2017 [cited by applicant]
US 20180103009A1 · Eberlein · 2018 [cited by applicant]
US 20190158423A1 · Li et al. · 2019 [cited by applicant]
US 20190297079A1 · Delcourt · 2019 [cited by examiner]
US 20200073717A1 · Hari · 2020 [cited by applicant]
US 20200236112A1 · Pularikkal et al. · 2020 [cited by applicant]
US 20200287869A1 · Glazemakers et al. · 2020 [cited by applicant]
US 20210029201A1 · Masurekar et al. · 2021 [cited by applicant]
US 20210075790A1 · Hebert et al. · 2021 [cited by applicant]
US 20210160237A1 · Rozner et al. · 2021 [cited by applicant]
US 20210250333A1 · Negrea et al. · 2021 [cited by applicant]
US 20210336788A1 · Ziegler et al. · 2021 [cited by applicant]
US 20210385221A1 · Nieman · 2021 [cited by applicant]
US 20210392111A1 · Sole et al. · 2021 [cited by applicant]
US 20220006805A1 · Kulkarni et al. · 2022 [cited by applicant]
US 20220046059A1 · Pandurangi et al. · 2022 [cited by applicant]
US 20220103527A1 · Niemi et al. · 2022 [cited by applicant]
US 20220141184A1 · Oswal et al. · 2022 [cited by applicant]
US 20220141254A1 · Oswal et al. · 2022 [cited by applicant]
US 20220210173A1 · Katmor et al. · 2022 [cited by applicant]
US 20220224621A1 · Devarajan et al. · 2022 [cited by applicant]
US 20220224622A1 · Kamath et al. · 2022 [cited by applicant]
US 20220224623A1 · Kamath et al. · 2022 [cited by applicant]
US 20220224703A1 · Devarajan · 2022 [cited by applicant]
US 20220272082A1 · Gupta et al. · 2022 [cited by applicant]
US 20220278917A1 · Voderbet et al. · 2022 [cited by applicant]
US 20220311822A1 · Nord et al. · 2022 [cited by applicant]
US 20220345463A1 · Wu et al. · 2022 [cited by applicant]
US 20220393943A1 · Pangeni et al. · 2022 [cited by applicant]
US 20220394083A1 · Pangeni et al. · 2022 [cited by applicant]
US 20220400114A1 · Sreedhar et al. · 2022 [cited by applicant]
US 20220400116A1 · Sreedhar et al. · 2022 [cited by applicant]
US 20220407840A1 · Chen et al. · 2022 [cited by applicant]
US 20230049547A1 · Glazemakers et al. · 2023 [cited by applicant]
US 20230069738A1 · Sreedhar et al. · 2023 [cited by applicant]
US 20230115982A1 · Lin et al. · 2023 [cited by applicant]
US 20230122630A1 · Balaiah et al. · 2023 [cited by applicant]
US 20230139695A1 · Xu et al. · 2023 [cited by applicant]
US 20230188505A1 · Jensen · 2023 [cited by applicant]
US 20230198764A1 · Panicker et al. · 2023 [cited by applicant]
US 20230229787A1 · Mahdavipour et al. · 2023 [cited by applicant]
US 20230239297A1 · McElhoe · 2023 [cited by examiner]
US 20230247003A1 · Chanak et al. · 2023 [cited by applicant]
US 20230254318A1 · Hu et al. · 2023 [cited by applicant]
US 20230269252A1 · Bakke · 2023 [cited by applicant]
US 20230328063A1 · Li et al. · 2023 [cited by applicant]
US 20230353543A1 · Solanki et al. · 2023 [cited by applicant]
US 20230362202A1 · Li et al. · 2023 [cited by applicant]
US 20230367605A1 · Bedi et al. · 2023 [cited by applicant]
US 20230379405A1 · Chhabra · 2023 [cited by applicant]
US 20230403282A1 · Smith et al. · 2023 [cited by applicant]
US 20230403304A1 · Balmakhtar et al. · 2023 [cited by applicant]
US 20240031337A1 · Sharma et al. · 2024 [cited by applicant]
US 20240031413A1 · Oswal et al. · 2024 [cited by applicant]
US 20240048564A1 · Sreedhar et al. · 2024 [cited by applicant]
US 20240064138A1 · Jain et al. · 2024 [cited by applicant]
US 20240073236A1 · Schumacher · 2024 [cited by applicant]
US 20240073694A1 · Srinivas et al. · 2024 [cited by applicant]
US 20240080744A1 · Hotchkiss et al. · 2024 [cited by applicant]
US 20240103932A1 · Hebbar et al. · 2024 [cited by applicant]
US 20240126868A1 · Andrews et al. · 2024 [cited by applicant]
US 20240129278A1 · Andrews et al. · 2024 [cited by applicant]
US 20240129296A1 · Andrews et al. · 2024 [cited by applicant]
US 20240129297A1 · Obulareddy et al. · 2024 [cited by applicant]
US 20240129298A1 · Obulareddy et al. · 2024 [cited by applicant]
US 20240129310A1 · Andrews et al. · 2024 [cited by applicant]
US 20240171555A1 · Chen et al. · 2024 [cited by applicant]
US 20240205231A1 · Bardhan et al. · 2024 [cited by applicant]
US 20240214350A1 · Sole et al. · 2024 [cited by applicant]
US 20240289264A1 · Desai · 2024 [cited by applicant]
US 20240414160A1 · Bakke · 2024 [cited by applicant]
WO WO2020180776 · 2020 [cited by applicant]
WO WO2024081014 · 2024 [cited by applicant]
EPO Searching Authority, “PCT Application No. PCT/US22/054075 International Search Report and Written Opinion mailed Jul. 3, 2023”, 15 pages. [cited by applicant]
“U.S. Appl. No. 18/089,946 Notice of Allowance mailed Jan. 21, 2025”, 8 pages. [cited by applicant]
“U.S. Appl. No. 18/089,967 Non-Final Office Action mailed Dec. 23, 2024”, 24 pages. [cited by applicant]
“U.S. Appl. No. 18/089,930 Non-Final Office Action mailed Oct. 24, 2024”, 19 pages. [cited by applicant]
“U.S. Appl. No. 18/089,946 Non-Final Office Action mailed Sep. 23, 2024”, 10 pages. [cited by applicant]
“U.S. Appl. No. 18/090,025 Non-Final Office Action mailed Nov. 7, 2024”, 36 pages. [cited by applicant]
Dasher, et al., “Architectures for Protecting Cloud Data Plane”, Jan. 31, 2022 , 43 pages. [cited by applicant]
“U.S. Appl. No. 18/089,930 Notice of Allowance mailed Feb. 26, 2025”, 8 pages. [cited by applicant]
“U.S. Appl. No. 18/089,967 Notice of Allowance mailed Apr. 28, 2025”, 15 pages. [cited by applicant]
“U.S. Appl. No. 18/090,009 Non-Final Office Action mailed Mar. 27, 2025”, 15 pages. [cited by applicant]
“U.S. Appl. No. 18/090,025 Final Office Action mailed Apr. 18, 2025”, 45 pages. [cited by applicant]
WIPO, , “PCT Application No. PCT/US22/54075 International Preliminary Report on Patentability mailed Apr. 24, 2025”, 10 pages. [cited by applicant]
USPTO, , “U.S. Appl. No. 18/090,041 Notice of Allowance mailed Jul. 1, 2025”, 11 pages. [cited by applicant]
Cited By (1)
US 12,627,673