IP Library Granted Patent US 12,463,970
Granted Patent B2
US 12,463,970 · App. 18/117,064 · Granted Nov 4, 2025

Systems and methods for distributed remote access

Inventor: Abhinav Bansal (Vancouver, CA)
Assignee: Zscaler, Inc.
H04L63/10H04L63/0281H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,970
App. No.
18/117,064
Granted
Nov 4, 2025
Kind
B2
Abstract

Systems and methods for transparent proxy chaining for distributed remote access. The various embodiments described herein include intercepting network traffic associated with an end user device; identifying a request to a destination from the network traffic, the destination being in a distributed environment of a plurality of distributed environments; connecting the end user device to the destination based on access control policies associated with a user of the end user device; and logging all traffic associated with the plurality of distributed environments.

Claims (33)

1 . A method comprising steps of:

intercepting network traffic associated with an end user device;

identifying a request to a destination from the network traffic, the destination defining one of a public destination and a private destination being in a distributed environment of a plurality of public and private distributed environments;

connecting the end user device to the destination based on access control policies associated with a user of the end user device by transparently proxying the request to the destination via cloud-based system providing zero trust, the cloud-based system configured to broker the connection to the destination, wherein the destination is preconfigured with a remote proxy address and a protocol required for establishing the connection; and

logging all traffic associated with the plurality of distributed environments.

2 . The method of claim 1 , wherein the steps further include installing an agent on the end user device, wherein the agent is configured to intercept all the network traffic flowing in and out of and associated with the end user device.

3 . The method of claim 2 , wherein the agent is configured to authenticate the user and download any of configuration, policies, and traffic forwarding rules.

4 . The method of claim 1 , wherein the access control policies are enforced by a zero trust network exchange and govern which of the plurality of distributed environments the user has access to, and which destinations within the plurality of distributed environments the user has access to.

5 . The method of claim 4 , wherein the access control policies are preconfigured by an administrator.

6 . The method of claim 1 , wherein the destination is in a public distributed environment, and the steps include proxying the request directly to the destination.

7 . The method of claim 1 , wherein the destination is in a private distributed environment, and the steps include proxying the request to the destination based on the destination and a configured protocol.

8 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

intercepting network traffic associated with an end user device;

identifying a request to a destination from the network traffic, the destination defining one of a public destination and a private destination being in a distributed environment of a plurality of public and private distributed environments;

connecting the end user device to the destination based on access control policies associated with a user of the end user device by transparently proxying the request to the destination via a cloud-based system providing zero trust, the cloud-based system configured to broker the connection to the destination, wherein the destination is preconfigured with a remote proxy address and a protocol required for establishing the connection; and

logging all traffic associated with the plurality of distributed environments.

9 . The non-transitory computer-readable medium of claim 8 , wherein the steps further include installing an agent on the end user device, wherein the agent is configured to intercept the network traffic associated with the end user device.

10 . The non-transitory computer-readable medium of claim 9 , wherein the agent is configured to authenticate the user and download any of configuration, policies, and traffic forwarding rules.

11 . The non-transitory computer-readable medium of claim 8 , wherein the access control policies govern which of the plurality of distributed environments the user has access to, and which destinations within the plurality of distributed environments the user has access to.

12 . The non-transitory computer-readable medium of claim 11 , wherein the access control policies are preconfigured by an administrator.

13 . The non-transitory computer-readable medium of claim 8 , wherein the destination is in a public distributed environment, and the steps include proxying the request directly to the destination.

14 . The non-transitory computer-readable medium of claim 8 , wherein the destination is in a private distributed environment, and the steps include proxying the request to the destination based on the destination and a configured protocol.

15 . A cloud-based system comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to:

intercept network traffic associated with an end user device;

identify a request to a destination from the network traffic, the destination defining one of a public destination and a private destination being in a distributed environment of a plurality of public and private distributed environments;

connect the end user device to the destination based on access control policies associated with a user of the end user device by transparently proxying the request to the destination via the cloud-based system providing zero trust, the cloud-based system configured to broker the connection to the destination, wherein the destination is preconfigured with a remote proxy address and a protocol required for establishing the connection; and

log all traffic associated with the plurality of distributed environments.

16 . The cloud-based system of claim 15 , wherein an agent is installed on the end user device, and wherein the agent is configured to intercept the network traffic associated with the end user device.

17 . The cloud-based system of claim 16 , wherein the agent is configured to authenticate the user and download any of configuration, policies, and traffic forwarding rules.

18 . The cloud-based system of claim 15 , wherein the access control policies govern which of the plurality of distributed environments the user has access to, and which destinations within the plurality of distributed environments the user has access to.

19 . The cloud-based system of claim 15 , wherein the destination is in a public distributed environment, and the request is proxied directly to the destination.

20 . The cloud-based system of claim 15 , wherein the destination is in a private distributed environment, and the request is proxied to the destination based on the destination and a configured protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2023
From: BANSAL, ABHINAV
To: ZSCALER, INC.
Reel/Frame 062874/0663 →
Continuity (1)
Related Publication 20240297881A1 · Sep 5, 2024
References Cited (17)
US 9350644B2 · Desai et al. · 2016 [cited by applicant]
US 9621574B2 · Desai et al. · 2017 [cited by applicant]
US 10225740B2 · Bansal et al. · 2019 [cited by applicant]
US 10432673B2 · Bansal et al. · 2019 [cited by applicant]
US 10511607B2 · Bansal et al. · 2019 [cited by applicant]
US 10574652B2 · Desai et al. · 2020 [cited by applicant]
US 10630724B2 · Bansal · 2020 [cited by applicant]
US 10708233B2 · Goyal et al. · 2020 [cited by applicant]
US 10986094B2 · Desai et al. · 2021 [cited by applicant]
US 11134386B2 · Singh et al. · 2021 [cited by applicant]
US 11388177B2 · Bansal · 2022 [cited by applicant]
US 20180316684A1 · Desai et al. · 2018 [cited by applicant]
US 20210105275A1 · Bansal et al. · 2021 [cited by applicant]
US 20210234860A1 · Bansal · 2021 [cited by examiner]
US 20210367920A1 · Devarajan et al. · 2021 [cited by applicant]
US 20210377210A1 · Singh et al. · 2021 [cited by applicant]
US 20230188505A1 · Jensen · 2023 [cited by examiner]