IP Library Granted Patent US 12,470,522
Granted Patent B2
US 12,470,522 · App. 18/359,515 · Granted Nov 11, 2025

Techniques for providing a secure web gateway through a zero trust network environment

Inventors: Shachar Dekel (Tel Aviv, IL); Gil Azrielant (Tel Aviv, IL); Oran Gilboa (Tel Aviv, IL); Guy Sviry (Tel Aviv, IL); Yehoshua Haim Chen (Tel Aviv, IL); Shay Farhuma Gutman (Tel Aviv, IL)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/0272H04L63/0263H04L63/029H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,522
App. No.
18/359,515
Granted
Nov 11, 2025
Kind
B2
Abstract

A system and method for configuring a client device to communicate utilizing a secure web gateway. The method includes generating a virtual network interface having a namespace with a plurality of names, wherein a first name of the namespace is assigned to a client device; assigning a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment; and configuring the client device to communicate only through the virtual network interface.

Claims (57)

1 . A method comprising:

generating a virtual network interface having a namespace with a plurality of names, wherein a first name of the namespace is assigned to a client device;

assigning a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment;

configuring the client device to communicate only through the virtual network interface;

inspecting network traffic received from the client device;

determining a destination of the network traffic;

sending the network traffic to the destination in response to determining that the network traffic is allowable based on a policy of the zero trust network environment; and

altering a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.

2 . The method of claim 1 , further comprising:

receiving credentials of a user account associated with the user device;

providing access to the resource through the zero trust network in response to authenticating the received credentials.

3 . The method of claim 1 , wherein the virtual network interface further includes a routing table.

4 . The method of claim 1 , further comprising:

performing a deep packet inspection on the network traffic.

5 . The method of claim 1 wherein the resource is deployed in any one of: a private network, a public network, and any combination thereof.

6 . The method of claim 1 , wherein the resource is any one of: a web application, a remote desktop protocol (RDP) server, a secure shell (SSH) server, a file server, an object database, a transactional database, a SQL database, a NoSQL database, a web server, a data repository, and any combination thereof.

7 . The method of claim 1 , further comprising:

assigning a third name of the namespace to another resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a private network and the another resource is deployed in a public network; and

blocking network traffic to the another resource in response to determining that the client device requested content from the resource within a time period which is less than a predefined time period.

8 . The method of claim 1 , wherein the zero trust network environment includes any one of: a frontend SSH server, a frontend RDP server, an access portal server, a backend server, and any combination thereof.

9 . A non-transitory computer-readable medium comprising instructions executable by processing circuitry to:

assign a first name of a namespace of a virtual network interface having to a client device, the namespace having a plurality of names, and wherein the client device is configured to communicate only through the virtual network interface;

assign a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment;

inspect network traffic received from the client device;

determine a destination of the network traffic;

send the network traffic to the destination in response to determining that the network traffic is allowable based on a policy of the zero trust network environment; and

alter a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.

10 . The non-transitory computer-readable medium of claim 9 , wherein the instructions are executable to:

assign a third name of the namespace to another resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a private network and the another resource is deployed in a public network; and

block network traffic to the another resource in response to determining that the client device requested content from the resource within a time period which is less than a predefined time period.

11 . The non-transitory computer-readable medium of claim 9 , wherein the instructions are executable to:

receive credentials of a user account associated with the user device; and

provide access to the resource through the zero trust network in response to authenticating the received credentials.

12 . The non-transitory computer-readable medium of claim 9 , wherein the virtual network interface further includes a routing table.

13 . The non-transitory computer-readable medium of claim 9 , wherein the instructions are executable to:

perform a deep packet inspection on the network traffic.

14 . A system comprising:

processing circuitry; and

a non-transitory machine readable storage medium comprising instructions executable by the processing circuitry to:

assign a first name of a namespace of a virtual network interface to a client device, the namespace having a plurality of names, and wherein the client device is configured to communicate only through the virtual network interface;

assign a second name of the namespace to a resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a secure network environment;

inspect network traffic received from the client device;

determine a destination of the network traffic;

send the network traffic to the destination in response to determining that the network traffic is allowable based on a policy of the zero trust network environment; and

alter a packet of the network traffic so that a response from the resource is directed to the zero trust network environment instead of the client device.

15 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

receive credentials of a user account associated with the user device; and

provide access to the resource through the zero trust network in response to authenticating the received credentials.

16 . The system of claim 14 , wherein the virtual network interface further includes a routing table.

17 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

perform a deep packet inspection on the network traffic.

18 . The system of claim 14 , wherein the resource is deployed in any one of: a private network, a public network, and any combination thereof.

19 . The system of claim 14 , wherein the resource is any one of: a web application, a remote desktop protocol (RDP) server, a secure shell (SSH) server, a file server, an object database, a transactional database, a SQL database, a NoSQL database, a web server, a data repository, and any combination thereof.

20 . The system of claim 14 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

assign a third name of the namespace to another resource accessible to the client device through a zero trust network environment, wherein the resource is deployed in a private network and the another resource is deployed in a public network; and

block network traffic to the another resource in response to determining that the client device requested content from the resource within a time period which is less than a predefined time period.

21 . The system of claim 14 , wherein the zero trust network environment includes any one of: a frontend SSH server, a frontend RDP server, an access portal server, a backend server, and any combination thereof.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2024
From: DEKEL, SHACHAR; AZRIELANT, GIL; GILBOA, ORAN; SVIRY, GUY; HAIM CHEN, YEHOSHUA; FARHUMA GUTMAN, SHAY
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 068086/0009 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2024
From: AXIS CYBER SECURITY LTD
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 067407/0412 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: AXIS CYBER SECURITY LTD
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 066846/0574 →
Continuity (1)
Related Publication 20250039145A1 · Jan 30, 2025
References Cited (34)
US 9525672B2 · Cignetti · 2016 [cited by examiner]
US 10205657B2 · Chang · 2019 [cited by examiner]
US 11074091B1 · Nayakbomman · 2021 [cited by examiner]
US 11159366B1 · Gawade · 2021 [cited by examiner]
US 11240242B1 · Celik · 2022 [cited by examiner]
US 11316822B1 · Gawade · 2022 [cited by examiner]
US 11470100B1 · Christian · 2022 [cited by examiner]
US 11588859B2 · Keiser, Jr. · 2023 [cited by applicant]
US 11843577B2 · Singh et al. · 2023 [cited by applicant]
US 11902145B2 · Laplante et al. · 2024 [cited by applicant]
US 11943260B2 · Narayanaswamy et al. · 2024 [cited by applicant]
US 12034652B2 · Henkel et al. · 2024 [cited by applicant]
US 12068958B1 · Henkel et al. · 2024 [cited by applicant]
US 12101296B2 · Vemulpali · 2024 [cited by applicant]
US 20160182473A1 · Cignetti · 2016 [cited by examiner]
US 20160261496A1 · Chang · 2016 [cited by examiner]
US 20190141015A1 · Nellen · 2019 [cited by examiner]
US 20190238365A1 · Sudhakaran · 2019 [cited by examiner]
US 20200236112A1 · Pularikkal · 2020 [cited by examiner]
US 20200336466A1 · Goldschlag · 2020 [cited by examiner]
US 20220075889A1 · Friedman · 2022 [cited by examiner]
US 20220158926A1 · Wennerström · 2022 [cited by examiner]
US 20220278926A1 · Sharma · 2022 [cited by examiner]
US 20220278927A1 · Mariappan · 2022 [cited by examiner]
US 20220334864A1 · K N · 2022 [cited by examiner]
US 20230104568A1 · Miriyala · 2023 [cited by examiner]
US 20230107891A1 · Miriyala · 2023 [cited by examiner]
US 20230123781A1 · Kaimal · 2023 [cited by examiner]
US 20230224167A1 · Wang · 2023 [cited by examiner]
US 20230224302A1 · Sviri et al. · 2023 [cited by applicant]
US 20230224303A1 · Sviri et al. · 2023 [cited by applicant]
US 20230291726A1 · Dekel et al. · 2023 [cited by applicant]
US 20230388271A1 · Chen et al. · 2023 [cited by applicant]
US 20240422107A1 · Sharma · 2024 [cited by examiner]