IP Library Granted Patent US 12,513,073
Granted Patent B2
US 12,513,073 · App. 18/587,699 · Granted Dec 30, 2025

Data access via secure tunnels in multi-tenant cloud native control plane system

Inventors: Parag Pritam Thakore (Los Gatos, CA); Sunil Mukundan (Chennai, IN); Anupam Rai (Fremont, CA)
Assignee: Netskope, Inc.
H04L45/02H04L12/4633
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,073
App. No.
18/587,699
Filed
Feb 26, 2024
Granted
Dec 30, 2025
Kind
B2
Art Unit
2465
USPC
370/389
Abstract

A method for providing data exchange using secure tunnel in a multi-tenant cloud native control plane system. A request is received by cloud control plane for accessing data. The cloud control plane provisions network connection to service endpoint at cloud provider for providing access using data plane and control plane. The control plane identifies routing information of network traffic from multiple end-user devices to establish the connection. Resiliency of the network is identified based on control plane or data plane failure and maintains the connection. Network patterns are identified for network traffic. These patterns are used by the cloud control plane to determine network policy for data access and routing. The secure tunnel is chosen from multiple tunnels based on the network policy, routing information. Data packets are forwarded by the data plane on the secure tunnel and data access is provided to the client endpoint using the secure tunnel.

Claims (59)

1 . A method for providing a data exchange using a secure tunnel in a multi-tenant cloud native control plane system, the method comprises:

receiving by a cloud control plane via a gateway device, a request for accessing data from a client endpoint of an end-user device, wherein the request is provided by sending data packets, wherein the cloud control plane provisions a network connection to a service endpoint at a cloud provider for providing access to the data using a data plane and a control plane;

identifying by the control plane, routing information of network traffic from a plurality of end-user devices to establish the network connection for the request;

identifying a resiliency of a network of the multi-tenant cloud native control plane system based on whether the control plane or the data plane has failed, wherein based on a failure of the control plane, the data plane maintains the network connection, and based on a failure of the data plane, the control plane maintains the network connection;

identifying network patterns associated with the network traffic from the plurality of end-user devices, wherein the network patterns are used by the cloud control plane to determine a network policy associated with access to the data, and the network policy specifies routing for access to the data;

determining the secure tunnel from a plurality of tunnels for providing access to the data based on the network policy and the network patterns from the routing information, wherein the secure tunnel connects the client endpoint and the service endpoint;

forwarding the data packets by the data plane for access to the data on the secure tunnel using the routing information; and

providing the access to the data from the cloud provider to the client endpoint on the gateway device using the secure tunnel.

2 . The method for providing a data exchange using a secure tunnel in a multi-tenant cloud native control plane system as recited in claim 1 , wherein the control plane is isolated from the data plane.

3 . The method for providing a data exchange using a secure tunnel in a multi-tenant cloud native control plane system as recited in claim 2 , further comprising:

identifying a tenant associated with the request, wherein the tenant is associated with a tenant identifier or a tenant ID; and

isolating the tenant from a plurality of tenants and tenant information by a multi-tenant controller of the cloud control plane.

4 . The method for providing a data exchange using a secure tunnel in a multi-tenant cloud native control plane system as recited in claim 1 , further comprising:

determining network policies from a policy store based on the request, wherein the policy store includes network policies and tag policies, and the network policies and the tag policies are predefined either by an administrator, an enterprise, or an end-user.

5 . The method for providing a data exchange using a secure tunnel in a multi-tenant cloud native control plane system as recited in claim 4 , wherein:

an orchestrator of the cloud control plane provides the data exchange, the data exchange is associated with the network policies, and

the network policies are based on tenant specific rules, applications, user locations, networks, preferences, and/or priorities.

6 . The method for providing a data exchange using a secure tunnel in a multi-tenant cloud native control plane system as recited in claim 1 , wherein the network patterns include connections between end-user devices, gateway endpoints, user location, and device address.

7 . The method for providing a data exchange using a secure tunnel in a multi-tenant cloud native control plane system as recited in claim 1 , wherein routes and the secure tunnel are associated with past and current network patterns and network policies.

8 . A multi-tenant cloud native control plane system for providing a data exchange using a secure tunnel between a plurality of gateway endpoints, the multi-tenant cloud native control plane system comprises:

an end-user device including a client endpoint, the client endpoint is configured to provide via a gateway device, a request for accessing data from the client endpoint, wherein the request is provided by sending data packets;

a cloud control plane coupled to the end-user device; and

a cloud provider configured to provide access to the data, wherein the cloud control plane is configured to:

receive the request from the client endpoint of the end-user device;

provision a network connection to a service endpoint at the cloud provider for providing access to the data using a data plane and a control plane;

identify by the control plane, routing information of network traffic from a plurality of end-user devices to establish the network connection for the request;

identify a resiliency of a network of the multi-tenant cloud native control plane system based on whether the control plane or the data plane has failed, wherein based on a failure of the control plane, the data plane maintains the network connection, and based on a failure of the data plane, the control plane maintains the network connection;

identify network patterns associated with the network traffic from the plurality of end-user devices, wherein the network patterns are used by the cloud control plane to determine a network policy associated with access to the data, and the network policy specifies routing for access to the data;

determine the secure tunnel from a plurality of tunnels for providing access to the data based on the network policy and the network patterns from the routing information, wherein the secure tunnel connects the client endpoint and the service endpoint;

forward the data packets by the data plane for access to the data on the secure tunnel using the routing information; and

provide the access to the data from the cloud provider to the client endpoint on the gateway device using the secure tunnel.

9 . The multi-tenant cloud native control plane system for providing a data exchange using a secure tunnel between a plurality of gateway endpoints as recited in claim 8 , wherein the control plane is isolated from the data plane.

10 . The multi-tenant cloud native control plane system for providing a data exchange using a secure tunnel between a plurality of gateway endpoints as recited in claim 9 , further configured to:

identify a tenant associated with the request, wherein the tenant is associated with a tenant identifier or a tenant ID; and

isolate the tenant from a plurality of tenants and tenant information by a multi-tenant controller of the cloud control plane.

11 . The multi-tenant cloud native control plane system for providing a data exchange using a secure tunnel between a plurality of gateway endpoints as recited in claim 8 , further configured to determine network policies from a policy store based on the request, wherein the policy store includes network policies and tag policies, and the network policies and the tag policies are predefined either by an administrator, an enterprise, or an end-user.

12 . The multi-tenant cloud native control plane system for providing a data exchange using a secure tunnel between a plurality of gateway endpoints as recited in claim 11 , wherein:

an orchestrator of the cloud control plane provides the data exchange, the data exchange is associated with the network policies, and

the network policies are based on tenant specific rules, applications, user locations, networks, preferences, and/or priorities.

13 . The multi-tenant cloud native control plane system for providing a data exchange using a secure tunnel between a plurality of gateway endpoints as recited in claim 8 , wherein the network patterns include connections between end-user devices, the gateway endpoints, user location, and device address.

14 . The multi-tenant cloud native control plane system for providing a data exchange using a secure tunnel between a plurality of gateway endpoints as recited in claim 8 , wherein routes and the secure tunnel are associated with past and current network patterns and network policies.

15 . A non-transitory computer-readable medium comprising computer-executable code, the computer-executable code configured for:

receiving by a cloud control plane via a gateway device of a multi-tenant cloud native control plane system, a request for accessing data from a client endpoint of an end-user device, wherein the request is provided by sending data packets, wherein the cloud control plane provisions a network connection to a service endpoint at a cloud provider for providing access to the data using a data plane and a control plane;

identifying by the control plane, routing information of network traffic from a plurality of end-user devices to establish the network connection for the request;

identifying a resiliency of a network of the multi-tenant cloud native control plane system based on whether the control plane or the data plane has failed, wherein based on a failure of the control plane, the data plane maintains the network connection, and based on a failure of the data plane, the control plane maintains the network connection;

identifying network patterns associated with the network traffic from the plurality of end-user devices, wherein the network patterns are used by the cloud control plane to determine a network policy associated with access to the data, and the network policy specifies routing for access to the data;

determining a secure tunnel from a plurality of tunnels for providing access to the data based on the network policy and the network patterns from the routing information, wherein the secure tunnel connects the client endpoint and the service endpoint;

forwarding the data packets by the data plane for access to the data on the secure tunnel using the routing information; and

providing the access to the data from the cloud provider to the client endpoint on the gateway device using the secure tunnel.

16 . The non-transitory computer-readable medium comprising computer-executable code as recited in claim 15 , wherein the control plane is isolated from the data plane.

17 . The non-transitory computer-readable medium comprising computer-executable code as recited in claim 16 , further comprising:

identifying a tenant associated with the request; and

isolating the tenant from a plurality of tenants and tenant information by a multi-tenant controller of the cloud control plane, wherein the tenant is associated with a tenant identifier or a tenant ID.

18 . The non-transitory computer-readable medium comprising computer-executable code as recited in claim 15 , further comprising:

determining network policies from a policy store based on the request, wherein the policy store includes network policies and tag policies, and the network policies and the tag policies are predefined either by an administrator, an enterprise, or an end-user.

19 . The non-transitory computer-readable medium comprising computer-executable code as recited in claim 18 , wherein:

an orchestrator of the cloud control plane provides a data exchange, the data exchange is associated with the network policies, and

the network policies are based on tenant specific rules, applications, user locations, networks, preferences, and/or priorities.

20 . The non-transitory computer-readable medium comprising computer-executable code as recited in claim 15 , wherein the network patterns include connections between end-user devices, gateway endpoints, user location, and device address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2024
From: THAKORE, PARAG PRITAM; MUKUNDAN, SUNIL; RAI, ANUPAM
To: NETSKOPE, INC.
Reel/Frame 066570/0677 →
Priority Claims (1)
IN 202311006913 · Feb 2, 2023 · national
Continuity (2)
Continuation 18185967 · Mar 17, 2023
Related Publication 20240333626A1 · Oct 3, 2024
References Cited (140)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6601186B1 · Fox et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 6742134B1 · Pothier et al. · 2004 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7583593B2 · Guichard et al. · 2009 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 8948001B2 · Guichard et al. · 2015 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9614737B1 · Brandwine · 2017 [cited by examiner]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 9912582B2 · Pourzandi · 2018 [cited by examiner]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10305757B2 · Yadav · 2019 [cited by examiner]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10802743B2 · Catthoor · 2020 [cited by examiner]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11070419B2 · Palavalli et al. · 2021 [cited by applicant]
US 11088944B2 · Allen et al. · 2021 [cited by applicant]
US 11159419B1 · Roersma · 2021 [cited by examiner]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11362932B2 · Hitz et al. · 2022 [cited by applicant]
US 11385975B2 · Dye et al. · 2022 [cited by applicant]
US 11888701B1 · Liu et al. · 2024 [cited by applicant]
US 11963248B2 · Palat et al. · 2024 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030120822A1 · Langrind · 2003 [cited by examiner]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy · 2014 [cited by examiner]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150207728A1 · Gagliano et al. · 2015 [cited by applicant]
US 20150317169A1 · Sinha · 2015 [cited by examiner]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20170264640A1 · Narayanaswamy · 2017 [cited by examiner]
US 20170359247A1 · Dixon · 2017 [cited by examiner]
US 20180026885A1 · Jeuk · 2018 [cited by examiner]
US 20190280964A1 · Michael · 2019 [cited by examiner]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20220045985A1 · Bareket · 2022 [cited by examiner]
US 20220191301A1 · Muller · 2022 [cited by examiner]
US 20220206908A1 · Brar et al. · 2022 [cited by applicant]
US 20220385534A1 · Cohen · 2022 [cited by examiner]
CN 106464531A · 2017 [cited by applicant]
CN 108768714 · 2018 [cited by applicant]
CN 110190996A · 2019 [cited by applicant]
CN 114035901 · 2022 [cited by applicant]
CN 115835259A · 2023 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
EP 3357216 · 2018 [cited by applicant]
EP 3382964A1 · 2018 [cited by applicant]
WO 2019196914A1 · 2019 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff Ending Clear Text Protocols, Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Nevvton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al. “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., Farsite: Federated, available, and reliable storage for an incompletely trusted environment, SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al. , Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” Tech Target, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?%20Offe… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1 , Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/%2010.1007/978-3-319… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al. “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]