IP Library › Granted Patent US 12,470,602
Granted Patent B2
US 12,470,602 · App. 18/484,392 · Granted Nov 11, 2025

Configuring IoT devices for policy enforcement

Inventors: David Tze-Si Wu (Fremont, CA); Siying Yang (Saratoga, CA); Krishna Narayanaswamy (Saratoga, CA)
Assignee: Netskope, Inc.
H04L63/20H04L41/0886H04L61/5014H04L63/0236H04L63/0245H04L63/0876H04L63/1425H04L63/164H04L63/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,602
App. No.
18/484,392
Granted
Nov 11, 2025
Kind
B2
Abstract

The technology disclosed relates to configuring IoT devices for policy enforcement. In particular, the technology disclosed relates to configuring a plurality of special-purpose devices on a network segment of a network to steer outbound network traffic to an inline secure forwarder on the network segment instead of a default gateway on the network segment. The inline secure forwarder is configured to route the outbound network traffic to a policy enforcement point for a policy enforcement.

Claims (41)

1 . A system, comprising:

a device configurer on a network segment of a network, comprising:

a configurer processor, and

a configurer memory having stored thereon configuration instructions that, upon execution by the configurer processor, causes the configurer processor to:

configure a plurality of special-purpose devices to steer outbound network traffic to an inline secure forwarder on the network segment instead of a default gateway on the network segment by transmitting a modified setting of each of the plurality of special-purpose devices to designate the inline secure forwarder as the default gateway; and

the inline secure forwarder on the network segment, comprising:

a forwarder processor, and

a forwarder memory having stored thereon forwarding instructions that, upon execution by the forwarder processor, causes the forwarder processor to:

route the outbound network traffic to a policy enforcement point for a policy enforcement,

determine, from the outbound network traffic, metadata required for the policy enforcement, and

append the metadata to the outbound network traffic and sends the outbound network traffic appended with the metadata to the policy enforcement point for the policy enforcement.

2 . The system of claim 1 , wherein the configuration instructions to configure the plurality of special-purpose devices comprises using static manual configuring.

3 . The system of claim 1 , wherein the configuration instructions to configure the plurality of special-purpose devices comprises using static automated configuring.

4 . The system of claim 1 , wherein the metadata includes a device classification of special-purpose devices in the plurality of special-purpose devices.

5 . The system of claim 1 , further comprising:

the policy enforcement point, wherein the policy enforcement point is implemented as a cloud service.

6 . The system of claim 1 , wherein the metadata about a particular special-purpose device uniquely identifies the particular special-purpose device.

7 . The system of claim 1 , wherein the metadata includes media access control (MAC) addresses of special-purpose devices in the plurality of special-purpose devices.

8 . The system of claim 1 , wherein the metadata includes pre-network address translated (pre-NATed) IP addresses of the special-purpose devices.

9 . The system of claim 1 , wherein the metadata includes information about the network segment.

10 . The system of claim 1 , wherein the metadata includes manufacturing information of special-purpose devices in the plurality of special-purpose devices.

11 . The system of claim 1 , wherein the forwarding instructions comprise further forwarding instructions that, upon execution by the forwarder processor, cause the forwarder processor to:

append the metadata to the outbound network traffic on a packet level.

12 . The system of claim 1 , further comprising:

the policy enforcement point, comprising:

one or more processors, and

one or more memories having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to:

classify the outbound network traffic based on the metadata, wherein the classifications comprise benign and malicious.

13 . The system of claim 12 , wherein the one or more memories of the policy enforcement point comprises further instructions that, upon execution by the one or more processors, cause the one or more processors to:

based on a benign classification, send the outbound network traffic to one or more out-of-network destinations intended by the special-purpose devices.

14 . The system of claim 13 , wherein the out-of-network destinations include cloud applications.

15 . The system of claim 13 , wherein the out-of-network destinations include one of web applications and websites.

16 . The system of claim 12 , wherein the one or more memories of the policy enforcement point comprises further instructions that, upon execution by the one or more processors, cause the one or more processors to:

based on a malicious classification, block the outbound network traffic.

17 . The system of claim 1 , wherein the device configurer is implemented in a dynamic host configuration protocol (DHCP) server.

18 . The system of claim 1 , wherein the configuration instructions comprise further configuration instructions that, upon execution by the configurer processor, cause the configurer processor to:

intercept a dynamic host configuration protocol (DHCP) request from a special-purpose device of the special-purpose devices; and

modify a DHCP response to the DHCP request with the modified setting.

19 . The system of claim 1 , wherein the configuration instructions comprise further instructions that, upon execution by the configurer processor, causes the configurer processor to:

determine a classification of each of the plurality of special-purpose devices as special-purpose devices.

20 . The system of claim 19 , wherein the instructions to determine the classification comprise instructions to analyze data associated with the respective special-purpose device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: WU, DAVID TZE-SI; YANG, SIYING; NARAYANASWAMY, KRISHNA
To: NETSKOPE, INC.
Reel/Frame 066860/0890 →
Continuity (3)
Continuation 17887400 · Aug 12, 2022
Provisional Application 63349494 · Jun 6, 2022
Related Publication 20240039961A1 · Feb 1, 2024
References Cited (112)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11283768B1 · Li · 2022 [cited by examiner]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150082376A1 · McNair · 2015 [cited by examiner]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20190104110A1 · Kladivo · 2019 [cited by examiner]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20230128098A1 · Agrawal · 2023 [cited by examiner]
US 20230354143A1 · Schumacher · 2023 [cited by examiner]
EP 1063833A2 · 2000 [cited by applicant]
Li, Xin, et al. “Efficient routing for middlebox policy enforcement in software-defined networking.” Computer Networks 110 (2016): 243-252. (Year: 2016). [cited by examiner]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc.,U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” filed Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” filed Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management for Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]