IP Library › Granted Patent US 12,506,711
Granted Patent B2
US 12,506,711 · App. 18/208,110 · Granted Dec 23, 2025

Systems and methods for network edge selection of network security processing

Inventors: Joseph R. Mihelich (Folsom, CA); Michael Xie (Sunnyvale, CA); Jordan Thompson (Burnaby, CA); Sandip Borle (Sunnyvale, CA); Sandeep Krishnamurthy (Sunnyvale, CA)
Assignee: Fortinet, Inc.
H04L63/029H04L61/2503H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,711
App. No.
18/208,110
Granted
Dec 23, 2025
Kind
B2
Abstract

Various embodiments provide embodiments provide systems and methods for performing edge processing using selectively suspended network security processing.

Claims (41)

1 . A method for selecting network security processing at a network edge, the method comprising:

providing, by an edge network device, a first network traffic to a non-edge network device, wherein the first network traffic is a first part of a network traffic session;

receiving, by the edge network device, a grant of suspended security review from the non-edge network device identifying the network traffic session, wherein the grant of suspended security review is given for network traffic that has been identified as having a likelihood of maliciousness below a pre-selected threshold based on historical instances of maliciousness identified in one or more of the identified source or destination;

receiving, by the edge network device, a second network traffic, wherein the second network traffic is a second part of the network traffic session; and

forwarding, by the edge network device, the second network traffic to a destination other than the non-edge network device without accessing the non-edge network device.

2 . The method of claim 1 , the method further comprising:

applying, by the edge network device, network address translation to the second network traffic to yield the destination.

3 . The method of claim 1 , wherein the non-edge network device is a network security appliance.

4 . The method of claim 1 , wherein the edge network device is a network router.

5 . The method of claim 4 , wherein the first network traffic is provided from a user device coupled directly to the network router.

6 . The method of claim 1 , wherein the grant of suspended security review from the non-edge network device indicates the network traffic session; the method further comprising:

receiving, by the non-edge network device, a termination point for the grant of suspended security review; and

revoking, by the non-edge network device, the grant of suspended security review based at least in part on the termination point.

7 . The method of claim 6 , wherein the termination point is the end of the network traffic session.

8 . The method of claim 6 , wherein the termination point is a defined number of bytes of the network traffic session.

9 . The method of claim 1 , wherein the indication that the edge network device is not required to transmit a second part of the network traffic session to the non-edge network device is a grant of suspended security review, the method further comprising:

receiving, by the edge network device, a revocation of the grant of suspended security review from the non-edge network device.

10 . An edge network device, the device comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, and having stored therein instructions that when executed by the processing resource cause the processing resource to:

provide a first network traffic to a non-edge network device, wherein the first network traffic is a first part of a network traffic session;

receive a grant of suspended security review from the non-edge network device identifying the network traffic session, wherein the grant of suspended security review is given for network traffic that has been identified as having a likelihood of maliciousness below a pre-selected threshold based on historical instances of maliciousness identified in one or more of the identified source or destination;

receive a second network traffic, wherein the second network traffic is a second part of the network traffic session; and

forward the second network traffic to a destination other than the non-edge network device without accessing the non-edge network device.

11 . The device of claim 10 , wherein the non-transitory computer-readable medium further includes therein instructions that when executed by the processing resource cause the processing resource to apply network address translation to the first network traffic to yield the destination.

12 . The device of claim 10 , wherein the non-edge network device is a network security appliance.

13 . The device of claim 10 , wherein the edge network device is a network router.

14 . The device of claim 13 , wherein the first network traffic is provided from a user device coupled directly to the network router.

15 . The device of claim 10 , wherein the non-transitory computer-readable medium further includes therein instructions that when executed by the processing resource cause the processing resource to:

receive a termination point for the grant of suspended security review; and

revoke the grant of suspended security review based at least in part on the termination point.

16 . The device of claim 15 , wherein the termination point is the end of the network traffic session.

17 . The device of claim 15 , wherein the termination point is a defined number of bytes of the network traffic session.

18 . The device of claim 10 , wherein the non-transitory computer-readable medium further includes therein instructions that when executed by the processing resource cause the processing resource to receive a revocation of the grant of suspended security review from the non-edge network device.

19 . A non-transitory computer-readable medium, the non-transitory computer readable medium having stored therein instructions that when executed by a processing resource cause the processing resource to perform a method comprising:

providing a first network traffic to a non-edge network device, wherein the first network traffic is a first part of a network traffic session;

receiving a grant of suspended security review from the non-edge network device identifying the network traffic session, wherein the grant of suspended security review is given for network traffic that has been identified as having a likelihood of maliciousness below a pre-selected threshold based on historical instances of maliciousness identified in one or more of the identified source or destination;

receiving a second network traffic, wherein the second network traffic is a second part of the network traffic session;

applying network address translation to the second network traffic to yield the destination; and

forwarding the second network traffic to a destination other than the non-edge network device without accessing the non-edge network device.

20 . The non-transitory computer-readable medium of claim 19 , wherein the non-edge network device is a network security appliance.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2023
From: XIE, MICHAEL
To: FORTINET, INC.
Reel/Frame 064858/0110 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2023
From: KRISHNAMURTHY, SANDEEP; BORLE, SANDIP; THOMPSON, JORDAN; MIHELICH, JOSEPH R.
To: FORTINET, INC.
Reel/Frame 063913/0941 →
Continuity (1)
Related Publication 20240414133A1 · Dec 12, 2024
References Cited (20)
US 11792116B1 · Dickinson et al. · 2023 [cited by applicant]
US 12081517B2 · Brecl et al. · 2024 [cited by applicant]
US 20120324533A1 · Conway et al. · 2012 [cited by applicant]
US 20170223058A1 · Barabash et al. · 2017 [cited by applicant]
US 20170331739A1 · Sharma · 2017 [cited by examiner]
US 20180337887A1 · Aluvala et al. · 2018 [cited by applicant]
US 20200374215A1 · Shah et al. · 2020 [cited by applicant]
US 20210006546A1 · Raza et al. · 2021 [cited by applicant]
US 20210234860A1 · Bansal et al. · 2021 [cited by applicant]
US 20220053024A1 · Byron et al. · 2022 [cited by applicant]
US 20220337555A1 · Gol · 2022 [cited by examiner]
US 20240137376A1 · Bogokovsky et al. · 2024 [cited by applicant]
US 20240137390A1 · Batson et al. · 2024 [cited by applicant]
US 20240244036A1 · Kandasamy · 2024 [cited by examiner]
US 20240388605A1 · Swaminathan · 2024 [cited by applicant]
US 20240414210A1 · Mihelich · 2024 [cited by examiner]
US 20240422179A1 · Metz · 2024 [cited by applicant]
CN 104704782A · 2015 [cited by examiner]
WO 2014042914A1 · 2014 [cited by applicant]
Office Action for U.S. Appl. No. 18/208,098 mailed Jul. 18, 2025, 28 pages. [cited by applicant]