IP Library Granted Patent US 12,438,879
Granted Patent B2
US 12,438,879 · App. 18/142,572 · Granted Oct 7, 2025

Methods, systems, and computer readable media for zero trust network access (ZTNA) testing using application-independent authentication profiles

Inventors: Partha Majumdar (West Hills, CA); Tudor Simionescu (Bucharest, RO); Rudrarup Naskar (Kolkota, IN); Sawan Das (Kolkata, IN); Sirshendu Rakshit (West Bengal, IN); Andrei Daniel Safta (Ploiesti, RO); Tiberiu Viorel Barbu (Buzau, RO)
Assignee: KEYSIGHT TECHNOLOGIES, INC.
H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,879
App. No.
18/142,572
Granted
Oct 7, 2025
Kind
B2
Abstract

A method for ZTNA testing using application-independent authentication profiles includes providing, at a network traffic emulation platform, user-selectable application flows for generating emulated application traffic to send to an application and providing application-independent authentication profiles for emulating authentication messaging of different ZTNA systems. The method further includes selecting one of the application flows and receiving, at the network traffic emulation platform, user selection of one of the application-independent authentication profiles. The method further includes generating and transmitting emulated authentication traffic to a ZTNA system according to the selected authentication profile, and, in response to successful completion of exchanges required by the authentication profile, generating and transmitting emulated application traffic to a network application according to the user-selected application flow.

Claims (18)

1. A method for zero trust network access (ZTNA) testing using application-independent authentication profiles, the method comprising: providing, at a network traffic emulation platform, a user interface that enables a user to configure a mix of emulated application flows by selecting a plurality of different emulated network applications by name and specifying a weight value for each of the emulated network applications; providing, at the network traffic emulation platform, a plurality of user- selectable application-independent authentication profiles for emulating authentication messaging of different ZTNA systems, wherein providing the application-independent authentication profiles includes providing a profile for emulating a policy enforcement point (PEP) and providing a profile for emulating an identity provider (IdP); receiving, at the network traffic emulation platform, user configuration of the mix of the application flows; and receiving, at the network traffic emulation platform, an instruction from a user to execute a test of a device under test and executing the test by: selecting, at the network traffic emulation platform, one of the application-independent authentication profiles; generating and transmitting emulated authentication traffic to the ZTNA system according to the selected authentication profile; and in response to successful completion of exchanges required by the authentication profile, generating and transmitting, to a device under test, emulated application traffic according to the user- selected application flow configured mix of application flows.

2. The method of claim 1 wherein the emulated network applications include emulated applications for communicating with applications on one or more web servers.

3. The method of claim 1 wherein generating and transmitting emulated authentication traffic to the ZTNA system includes generating and transmitting emulated PEP traffic to a PEP according to the PEP profile and generating and transmitting emulated IdP traffic to an IdP according to the IdP profile.

4. The method of claim 1 wherein generating the emulated authentication traffic includes providing the authentication profile to a traffic generation engine.

5. The method of claim 4 wherein the authentication profile causes the traffic generation engine to listen for responses to the emulated authentication traffic and to proceed with generation of the emulated application traffic when the responses conform to expected exchanges of the authentication profile.

6. The method of claim 1 wherein generating the emulated application traffic includes generating the configured mix of emulated application flows using a traffic generation engine.

7. The method of claim 1 wherein providing the user-selectable application flows and the application-independent authentication profiles includes providing a user interface allowing the user to create different combinations of the application flows and the authentication profiles by separately selecting the application flows and the authentication profiles.

8. The method of claim 7 wherein the user interface allows the user to select more than one of authentication profiles and wherein selecting one of the application- independent authentication profiles includes transmitting an initial application message to the network application according to the user-selected application flow, receiving a response, and selecting the application-independent authentication profile dynamically at run time based on the response and from the application-independent authentication profiles selected by the user.

9. A system for zero trust network access (ZTNA) testing using application-independent authentication profiles, the system comprising: a network traffic emulation platform including at least one processor and a memory; a plurality of user-selectable application-independent authentication profiles stored in the memory and for emulating authentication messaging of different ZTNA systems, wherein at least one of the user-selectable application-independent authentication profiles includes a policy enforcement point (PEP) profile and at least another of the user-selectable application-independent authentication profiles includes an identity provider (IdP) profile; a user interface for enabling a user to configure a mix of emulated application flows by selecting a plurality of different emulated network applications by name and specifying a weight value for each of the emulated network applications and for receiving an instruction from a user to execute a test of a device under test; and a traffic generation engine for executing the test by: selecting one of the application-independent authentication profiles; generating and transmitting emulated authentication traffic to a ZTNA system according to the selected authentication profile, and, in response to successful completion of exchanges required by the authentication profile; and

generating and transmitting, to the device under test, emulated application traffic according to the configured mix of application flows.

10. The system of claim 9 wherein the emulated network applications include applications for communicating with applications on one or more web servers.

11. The system of claim 9 wherein the traffic generation engine is configured to generate and transmit emulated PEP traffic to a PEP according to the PEP profile and generate and transmit emulated IdP traffic to an IdP according to the IdP profile.

12. The system of claim 9 wherein the network traffic generation platform is configured to generate the emulated authentication by providing the authentication profile to the traffic generation engine.

13. The system of claim 12 wherein the authentication profile causes the traffic generation engine to listen for responses to the emulated authentication traffic and to proceed with generation of the emulated application traffic when the responses conform to expected exchanges of the authentication profile.

14. The system of claim 9 wherein the user interface allows the user to select more than one of authentication profiles and wherein, in selecting one of the application-independent authentication profiles, the traffic generation engine is configured to transmit an initial application message to the network application according to the user-selected application flow, receive a response, and select the application-independent authentication profile dynamically at run time based on the response and from the application-independent authentication profiles selected by the user.

15. The system of claim 9 wherein the user interface is configured to allow the user to create different combinations of application flows and authentication profiles by separately selecting the application flows and the authentication profiles.

16. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising: providing, at a network traffic emulation platform, a user interface that enables a user to configure a mix of emulated application flows by selecting a plurality of different emulated network applications by name and specifying a weight value for each of the emulated network applications;

providing, at the network traffic emulation platform, a plurality of application-independent authentication profiles for emulating authentication messaging of different zero trust network access (ZTNA) systems, wherein providing the application-independent authentication profiles includes providing a profile for emulating a policy enforcement point (PEP) and providing a profile for emulating an identity provider (IdP); receiving, at the network traffic emulation platform, user configuration of the mix of the application flows; and receiving, at the network traffic emulation platform, an instruction from a user to execute a test of a device under test and executing the test by: selecting, at the network traffic emulation platform, one of the application-independent authentication profiles; generating and transmitting emulated authentication traffic to the ZTNA system according to the selected authentication profile; and in response to successful completion of exchanges required by the authentication profile, generating and transmitting, to a device under test, emulated application traffic according to the configured mix of application flows.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2023
From: KEYSIGHT TECHNOLOGIES RO SRL
To: KEYSIGHT TECHNOLOGIES, INC.
Reel/Frame 063944/0153 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2023
From: MAJUMDAR, PARTHA; NASKAR, RUDRARUP; DAS, SAWAN; RAKSHIT, SIRSHENDU
To: KEYSIGHT TECHNOLOGIES, INC.
Reel/Frame 063547/0692 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2023
From: SIMIONESCU, TUDOR; SAFTA, ANDREI DANIEL; BARBU, TIBERIU VIOREL
To: KEYSIGHT TECHNOLOGIES RO SRL
Reel/Frame 063547/0731 →
Priority Claims (1)
RO a 2023 00214 · Apr 28, 2023 · national
Continuity (1)
Related Publication 20240364691A1 · Oct 31, 2024
References Cited (27)
US 8392982B2 · Harris et al. · 2013 [cited by applicant]
US 11100503B2 · Iyer et al. · 2021 [cited by applicant]
US 11240225B1 · Seever et al. · 2022 [cited by applicant]
US 11323438B2 · Ray et al. · 2022 [cited by applicant]
US 11570172B2 · Specht · 2023 [cited by examiner]
US 11647010B2 · Cheng · 2023 [cited by examiner]
US 20100242105A1 · Harris et al. · 2010 [cited by applicant]
US 20100290476A1 · Brindle et al. · 2010 [cited by applicant]
US 20110225267A1 · Ohashi · 2011 [cited by applicant]
US 20160266915A1 · Morelli et al. · 2016 [cited by applicant]
US 20180295134A1 · Gupta et al. · 2018 [cited by applicant]
US 20210336959A1 · Shah · 2021 [cited by examiner]
US 20220210173A1 · Katmor · 2022 [cited by examiner]
US 20220239640A1 · Wang · 2022 [cited by examiner]
US 20220400114A1 · Sreedhar · 2022 [cited by examiner]
US 20230053702A1 · Gupta · 2023 [cited by examiner]
US 20230079444A1 · Parla · 2023 [cited by examiner]
US 20230123781A1 · Kaimal · 2023 [cited by examiner]
US 20230129466A1 · Moore · 2023 [cited by examiner]
US 20250016666A1 · Zaks · 2025 [cited by applicant]
US 20250112946A1 · Das et al. · 2025 [cited by applicant]
WO 2020207517A1 · 2020 [cited by applicant]
Zanasi et al, A Zero Trust approach for the cybersecurity of Industrial Control Systems, 2022, IEEE (Year: 2022). [cited by examiner]
Qazi, Study of Zero Trust Architecture for Applications and Network Security, 2022, IEEE (Year: 2022). [cited by examiner]
Non-Final Office Action for U.S. Appl. No. 18/375,245 (May 19, 2025). [cited by applicant]
Fu, et al., “Application Independent Identity Management”, IEEE, pp. 625-628 (2010). [cited by applicant]
Keysight Technologies, “Keysight CyPerf”, Distributed, Elastic Network Performance and Security Validation, pp. 1-12 (May 2021). [cited by applicant]