IP Library Granted Patent US 12,432,161
Granted Patent B2
US 12,432,161 · App. 19/216,072 · Granted Sep 30, 2025

Multi-perimeter firewall in the cloud

Inventors: Joseph E. Rubenstein (Beijing, CN); Carlos Eduardo Ore (Saint-Herblain, FR)
Assignee: UMBRA Technologies Ltd.
H04L47/825G06F9/4401G06F9/4416G06F21/575H04L9/08H04L12/4633H04L12/465H04L45/22H04L45/28H04L45/302H04L45/64H04L47/83H04L63/02H04L63/0218H04L63/0236H04L63/0254H04L63/0263H04L63/0272H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,161
App. No.
19/216,072
Filed
May 22, 2025
Granted
Sep 30, 2025
Kind
B2
Art Unit
2438
USPC
726/11
Abstract

Systems and methods for providing multi-perimeter firewalls via a virtual global network are disclosed. In one embodiment the network system may comprise an egress ingress point in communication with a first access point server, a second access point server in communication with the first access point server, an endpoint device in communication with the second access point server, a first firewall in communication with the first access point server, and a second firewall in communication with the second access point server. The first and second firewalls may prevent traffic from passing through their respective access point servers. The first and second may be in communication with each other and exchange threat information.

Claims (21)

1. A method of operating a multi-perimeter distributed firewall in a geographically extended virtual network system, the method comprising:

connecting

a compute cloud location and

a secure endpoint located at a remote location that is geographically separate from

the compute cloud location to a packet-data-based secure virtual network maintained over-the-top of at least one wide area network;

determining, at a control node for the secure virtual network, an on-demand allocation of compute resources at the compute cloud location to instantiate a variable number of virtual firewalls, up to a plurality of virtual firewalls, to serve the secure virtual network;

upon instantiation of each given firewall of the virtual firewalls, configuring that given firewall as part of a first firewall perimeter for at least a portion of packet traffic ingressing to a secure perimeter that includes connection to the secure virtual network at the compute cloud location;

operating the variable number of virtual firewalls in parallel as the first firewall perimeter to provide traffic inspection for packet traffic ingressing to the secure perimeter;

for packet traffic clearing the first firewall perimeter and having a respective destination reachable via the remote location, forwarding that packet traffic over the secure virtual network towards the remote location; and

operating at least one second firewall at a second firewall perimeter coupled to the secure virtual network, to provide second traffic inspection for at least some packet traffic forwarded from the first firewall perimeter over the secure virtual network towards the remote location.

2. The method of claim 1 , wherein the secure endpoint is one of a plurality of respective secure endpoints located at a plurality of respective remote locations that are geographically separate from the compute cloud location, each of the plurality of respective secure endpoints connected to the secure virtual network, the variable number of virtual firewalls providing the first firewall perimeter for packet traffic having a respective destination reachable by any of the remote locations.

3. The method of claim 1 , further comprising each of the variable number of firewalls, the second firewall, and the secure endpoint communicating at least with the control node via a back channel mechanism separate from the secure virtual network.

4. The method of claim 3 , further comprising providing access to one or more of the variable number of firewalls and the second firewall, via the back channel mechanism, to threat information detected by one or more others of the variable number of firewalls and the second firewall.

5. The method of claim 1 , further comprising configuring instantiation of each given firewall of the virtual firewalls to require retrieval of secure boot credentials from a boot server upon validation of that given firewall.

6. The method of claim 1 , wherein each of the variable number of firewalls is configured to perform stateful packet inspection for a respective load-balanced portion of the packet traffic ingressing to the secure perimeter.

7. The method of claim 6 , wherein the at least one second firewall is configured to perform deep packet inspection for the at least some packet traffic.

8. The method of claim 7 , further comprising cloning the packet traffic upon which deep packet inspection is to be performed, and directing the cloned packet traffic to the at least one second firewall.

9. The method of claim 6 , further comprising connecting each of the variable number of firewalls to receive its respective load-balanced portion of the packet traffic ingressing to the secure perimeter through a cloud firewall load balancer, the cloud firewall load balancer operating to direct the respective load-balanced portions to each of the variable number of firewalls.

10. The method of claim 1 , wherein the at least a portion of packet traffic ingressing to the secure perimeter comprises traffic ingressing from the open Internet.

11. The method of claim 10 , wherein the at least a portion of packet traffic ingressing to the secure perimeter comprises traffic ingressing from cloud-based servers or storage devices associated with an organization operating at the remote location.

12. The method of claim 1 , wherein the at least a portion of packet traffic ingressing to the secure perimeter comprises traffic ingressing from cloud-based servers or storage devices associated with an organization operating at the remote location.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2025
From: RUBENSTEIN, JOSEPH E.; SAINT-MARTIN, THIBAUD AUGUSTE BERNARD JEAN; BROUSSARD, FRED
To: UMBRA TECHNOLOGIES LTD.
Reel/Frame 071299/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2025
From: RUBENSTEIN, JOSEPH E.; ORE, CARLOS EDUARDO
To: UMBRA TECHNOLOGIES LTD.
Reel/Frame 071299/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2025
From: UMBRA TECHNOLOGIES LIMITED (CN)
To: UMBRA TECHNOLOGIES LTD. (UK)
Reel/Frame 071299/0977 →
Continuity (7)
Continuation 18940371 · Nov 7, 2024
Continuation 17686870 · Mar 4, 2022
Continuation 16745125 · Jan 16, 2020
Continuation 15563261
Provisional Application 62151174 · Apr 22, 2015
Provisional Application 62144293 · Apr 7, 2015
Related Publication 20250286831A1 · Sep 11, 2025
References Cited (69)
US 7254833B1 · Cornelius et al. · 2007 [cited by applicant]
US 7409706B1 · O'Rourke et al. · 2008 [cited by applicant]
US 8595478B2 · Haney · 2013 [cited by applicant]
US 8601565B1 · Sakata et al. · 2013 [cited by applicant]
US 8955093B2 · Shieh et al. · 2015 [cited by applicant]
US 9237129B2 · Ling et al. · 2016 [cited by applicant]
US 9350644B2 · Desai et al. · 2016 [cited by applicant]
US 9350710B2 · Herle et al. · 2016 [cited by applicant]
US 9369433B1 · Paul et al. · 2016 [cited by applicant]
US 9407557B2 · Wadkins et al. · 2016 [cited by applicant]
US 9432336B2 · Ostrowski · 2016 [cited by applicant]
US 9524167B1 · Cohn et al. · 2016 [cited by applicant]
US 9525663B2 · Yuan et al. · 2016 [cited by applicant]
US 9591018B1 · Zakian et al. · 2017 [cited by applicant]
US 12160328B2 · Rubenstein · 2024 [cited by examiner]
US 20020046253A1 · Uchida · 2002 [cited by examiner]
US 20020087447A1 · McDonald et al. · 2002 [cited by applicant]
US 20040268151A1 · Matsuda · 2004 [cited by applicant]
US 20050216957A1 · Banzhof et al. · 2005 [cited by applicant]
US 20050235352A1 · Staats · 2005 [cited by examiner]
US 20060085855A1 · Shin et al. · 2006 [cited by applicant]
US 20060195896A1 · Fulp et al. · 2006 [cited by applicant]
US 20070156919A1 · Potti et al. · 2007 [cited by applicant]
US 20070226043A1 · Pietsch et al. · 2007 [cited by applicant]
US 20080010676A1 · Dosa Racz et al. · 2008 [cited by applicant]
US 20080201722A1 · Sarathy · 2008 [cited by applicant]
US 20080203110A1 · LaFlamme et al. · 2008 [cited by applicant]
US 20080301794A1 · Lee · 2008 [cited by applicant]
US 20090193428A1 · Dalberg et al. · 2009 [cited by applicant]
US 20090265778A1 · Wahl et al. · 2009 [cited by applicant]
US 20100131616A1 · Walter et al. · 2010 [cited by applicant]
US 20120210417A1 · Shieh · 2012 [cited by applicant]
US 20120210434A1 · Curtis et al. · 2012 [cited by applicant]
US 20130111038A1 · Girard · 2013 [cited by applicant]
US 20130247167A1 · Paul et al. · 2013 [cited by applicant]
US 20130332983A1 · Koorevaar et al. · 2013 [cited by applicant]
US 20140278543A1 · Kasdon · 2014 [cited by applicant]
US 20140280911A1 · Wood et al. · 2014 [cited by applicant]
US 20140366119A1 · Floyd, III et al. · 2014 [cited by applicant]
US 20150089582A1 · Dilley et al. · 2015 [cited by applicant]
US 20150128245A1 · Brown et al. · 2015 [cited by applicant]
US 20150128246A1 · Feghali et al. · 2015 [cited by applicant]
US 20150207812A1 · Back et al. · 2015 [cited by applicant]
US 20150281176A1 · Banfield · 2015 [cited by examiner]
US 20150326535A1 · Rao · 2015 [cited by examiner]
US 20150334090A1 · Ling et al. · 2015 [cited by applicant]
US 20150363240A1 · Koizumi · 2015 [cited by applicant]
US 20160119256A1 · Wang et al. · 2016 [cited by applicant]
US 20160234250A1 · Ashley et al. · 2016 [cited by applicant]
US 20170063920A1 · Thomas et al. · 2017 [cited by applicant]
US 20170099196A1 · Barsheshet et al. · 2017 [cited by applicant]
US 20180034781A1 · Jaeger · 2018 [cited by examiner]
CN 1754161A · 2006 [cited by applicant]
CN 101478533A · 2009 [cited by applicant]
CN 102687480A · 2012 [cited by applicant]
EP 2357763B1 · 2015 [cited by applicant]
EP 2154834B1 · 2017 [cited by applicant]
WO 2012163587A1 · 2012 [cited by applicant]
Cisco Systems, Inc.'s Petition for Inter Partes Review of U.S. Pat. No. 10,574,482, dated Jan. 29, 2024, Paper 2 in IPR2024-00270, 74 pages. [cited by applicant]
Patent Owner UMBRA Technologies Ltd.'s Preliminary Response submitted in IPR2024-00498 on May 13, 2024 (22 pages). [cited by applicant]
Petitioner's Reply to Patent Owner's Preliminary Response, dated Jun. 17, 2025, in IPR2024-00498, 8 pages. [cited by applicant]
Patent Owner's Sur-Reply, dated Jun. 25, 2025, in IPR2024-00498, 8 pages. [cited by applicant]
Board's Decision Denying Institution of Inter Partes Review dated Aug. 7, 2024, Paper 16 in IPR2024-00270, 23 pages. [cited by applicant]
Deal, R., “Cisco Router Firewall Security,” 2005, excerpted (10 pages). [cited by applicant]
Frahim, J. et al., “Cisco ASA All-in-One Firewall, IPS, Anti-X, and VPN Adaptive Security Appliance 2nd Ed.,” 2010, excerpted (82 pages). [cited by applicant]
Katayama, M. et al., “A 10 Gb/s Firewall System for Network Security in Photonic Era,” dated May 2005, IEICE Trans. Commun., vol. E88-B, No. 5 (7 pages). [cited by applicant]
Vajaranta, M., “Security as a Service for Hybrid Clouds,” Master of Science Thesis, Tampere University of Technology, dated May 2014 (57 pages). [cited by applicant]
File History, U.S. Appl. No. 61/982,358, filed Apr. 22, 2014 (21 pages). [cited by applicant]
Qazi, Zafar Ayyub, et at, SIMPLE-fying Middlebox Policy Enforcement Using SDN, SIGCOMM'13, Aug. 12-16, 2013 {12 pages). [cited by applicant]