IP Library Granted Patent US 12,563,017
Granted Patent B2
US 12,563,017 · App. 18/662,783 · Granted Feb 24, 2026

Identity-based distributed cloud firewall for access and network segmentation

Inventors: Carlos Eliseo Salas Lumbreras (Vilnius, LT); Juta Gurinaviciute (Vilnius, LT)
Assignee: UAB 360 IT
H04L63/0272H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,017
App. No.
18/662,783
Granted
Feb 24, 2026
Kind
B2
Abstract

According to some embodiments, a method of controlling access to network resources includes: receiving an authentication request from a user device to a core security service; if the user is authenticated, authorizing the user device to connect to a private cloud, and connecting the user device with the private cloud and retrieving user-specific segmented firewall rules stored in the private cloud; routing, through the firewall rules, a request by the user device to access an outer resource; evaluating the request against the firewall rules; if the request meets the firewall rules, routing the request through security measures of the firewall; and if the request does not meet the firewall rules, denying the user device access to the outer resource.

Claims (53)

1 . A method of controlling access to network resources, the method comprising:

receiving an authentication request from a user device to a core security service;

upon authentication of the user device by the core security service, receiving a request from a user device at a core configuration service to connect to an outer resource, retrieving user-specific rule set, and sharing the user-specific rule set with the user device, wherein the user-specific rule set defines resources that are accessible directly over the internet and resources that require connectivity through an internal network;

adapting the shared rule set by the user device;

evaluating the request against the adapted rule set;

routing the connection to the outer resources directly via the internet when the adapted rule set indicates that the outer resource is accessible through the internet; and

routing the user's request to an internal network when the adapted rule set indicates that the outer resource is not accessible through the internet.

2 . The method of claim 1 , wherein the internal network is a private cloud comprising a gateway and a firewall and, wherein the method includes, upon authentication of the user device, retrieving user-specific, segmented firewall rules stored in the private cloud; and

wherein, if the user's request is routed to the private cloud, the method further includes:

routing a request by the user device to access an outer resource to the gateway;

evaluating the request against the segmented firewall rules;

if the request meets the segmented firewall rules, routing the request through security measures of the firewall; and

if the request does not meet the segmented firewall rules, denying the user device access to the outer resource.

3 . The method of claim 2 , wherein each private cloud includes a corresponding firewall, wherein the request is transmitted through a secure VPN tunnel established by the gateway before being received by the firewall.

4 . The method of claim 3 , wherein the segmented firewall rules include firewall rules associated with at least one of the user, a group of users, an organization, or the gateway.

5 . The method of claim 3 , further comprising forwarding the request to the outer resource and transmitting a response from the outer resource to the user device through the secure VPN tunnel if the request meets the segmented firewall rules and passes the security measures of the firewall.

6 . The method of claim 2 , wherein the core security service is located between the user device and at least one of the private cloud.

7 . The method of claim 2 , wherein the authentication request includes a request to connect to one or more private clouds associated with the user.

8 . An apparatus for controlling access to network resources, comprising at least one processor and at least one non-transient computer readable medium for storing instructions that, when executed by the at least one processor, causes the apparatus to perform operations comprising:

receiving an authentication request from a user device to a core security service;

upon authentication of the user by the core security service, receiving a request from a user device at a core configuration service to connect to an outer resource, retrieving user-specific rule set, and sharing the user-specific rule set with the user device, wherein the user-specific rule set defines resources that are accessible directly over the internet and resources that require connectivity through an internal network;

adapting the shared rule set by the user device;

evaluating the request against the adapted rule set;

routing the connection to the outer resources directly via the internet when the adapted rule set indicates that the outer resource is accessible through the internet; and

routing the user's request to an internal network when the adapted rule set indicates that the outer resource is not accessible through the internet.

9 . The apparatus according to claim 8 , wherein the internal network is a private cloud comprising a gateway and a firewall and, wherein the operations include, upon authentication of the user device, retrieving user-specific, segmented firewall rules stored in the private cloud; and

wherein, if the user's request is routed to the private cloud, the operations further includes:

routing a request by the user device to access an outer resource to the gateway;

evaluating the request against the segmented firewall rules;

if the request meets the segmented firewall rules, routing the request through security measures of the firewall; and

if the request does not meet the segmented firewall rules, denying the user device access to the outer resource.

10 . The apparatus of claim 9 , wherein each private cloud includes a corresponding firewall wherein the request is transmitted through a secure VPN tunnel established by the gateway before being received by the firewall.

11 . The apparatus of claim 10 , wherein the segmented firewall rules include firewall rules associated with at least one of the user, a group of users, an organization, or the gateway.

12 . The apparatus of claim 10 , further comprising forwarding the request to the outer resource and transmitting a response from the outer resource to the user device through the secure VPN tunnel if the request meets the segmented firewall rules and passes the security measures of the firewall.

13 . The apparatus of claim 9 , wherein the core security service is located between the user device and the private cloud.

14 . The apparatus of claim 9 , wherein the authentication request includes a request to connect to one or more private clouds associated with the user.

15 . One or more non-transitory computer readable media having instructions stored thereon which, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving an authentication request from a user device to a core security service;

upon authentication of the user by the core security service receiving a request from a user device at a core configuration service to connect to an outer resource, retrieving user-specific rule set, and sharing the user-specific rule set with the user device, wherein the user-specific rule set defines resources that are accessible directly over the internet and resources that require connectivity through an internal network;

adapting the shared rule set by the user device;

evaluating the request against the adapted rule set;

routing the connection to the outer resources directly via the internet when the adapted rule set indicates that the outer resource is accessible through the internet; and

routing the user's request to an internal network when the adapted rule set indicates that the outer resource is not accessible through the internet.

16 . The computer readable media of claim 15 , wherein the internal network is a private cloud comprising a gateway and a firewall and, wherein the operations include, upon authentication of the user device, retrieving user-specific, segmented firewall rules stored in the private cloud; and

wherein, if the user's request is routed to the private cloud, the operations further includes:

routing a request by the user device to access an outer resource to the gateway;

evaluating the request against the segmented firewall rules;

if the request meets the segmented firewall rules, routing the request through security measures of the firewall; and

if the request does not meet the segmented firewall rules, denying the user device access to the outer resource.

17 . The computer readable media of claim 16 , wherein each private cloud includes a corresponding firewall, wherein the request is transmitted through a secure VPN tunnel established by the gateway before being received by the firewall.

18 . The computer readable media of claim 17 , wherein the segmented firewall rules include firewall rules associated with at least one of the user, a group of users, an organization, or the gateway.

19 . The computer readable media of claim 17 , forwarding the request to the outer resource and transmitting a response from the outer resource to the user device through the secure VPN tunnel if the request meets the segmented firewall rules and passes the security measures of the firewall.

20 . The computer readable media of claim 16 , wherein the authentication request includes a request to connect to one or more private clouds associated with the user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2026
From: UAB 360 IT
To: 720 IT, UAB
Reel/Frame 073446/0784 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2024
From: SALAS LUMBRERAS, CARLOS ELISEO; GURINAVICIUTE, JUTA
To: UAB 360 IT
Reel/Frame 067559/0835 →
Continuity (2)
Continuation In Part 18378370 · Oct 10, 2023
Related Publication 20250119408A1 · Apr 10, 2025
References Cited (37)
US 7752662B2 · Shulman et al. · 2010 [cited by applicant]
US 8010085B2 · Apte et al. · 2011 [cited by applicant]
US 8024804B2 · Shulman et al. · 2011 [cited by applicant]
US 8413238B1 · Sutton · 2013 [cited by applicant]
US 8458786B1 · Kailash et al. · 2013 [cited by applicant]
US 8464335B1 · Sinha et al. · 2013 [cited by applicant]
US 8484726B1 · Sutton · 2013 [cited by applicant]
US 8763071B2 · Sinha et al. · 2014 [cited by applicant]
US 9152789B2 · Natarajan et al. · 2015 [cited by applicant]
US 9350710B2 · Herle et al. · 2016 [cited by applicant]
US 9674202B1 · Marget et al. · 2017 [cited by applicant]
US 10154067B2 · Smith et al. · 2018 [cited by applicant]
US 10542029B2 · Lapidous · 2020 [cited by applicant]
US 10803192B2 · Margel et al. · 2020 [cited by applicant]
US 10834130B2 · Erez et al. · 2020 [cited by applicant]
US 10911472B2 · Niv et al. · 2021 [cited by applicant]
US 11003779B2 · Reich et al. · 2021 [cited by applicant]
US 11159486B2 · Pangeni et al. · 2021 [cited by applicant]
US 11271899B2 · Bareket et al. · 2022 [cited by applicant]
US 11277383B2 · Devarajan et al. · 2022 [cited by applicant]
US 11330016B2 · Arbel et al. · 2022 [cited by applicant]
US 11368490B2 · Kailash et al. · 2022 [cited by applicant]
US 11368496B2 · Nahas et al. · 2022 [cited by applicant]
US 11375441B2 · Nuwula et al. · 2022 [cited by applicant]
US 11436358B2 · Margel et al. · 2022 [cited by applicant]
US 11461484B2 · Anand et al. · 2022 [cited by applicant]
US 11483291B2 · Mantin et al. · 2022 [cited by applicant]
US 11533307B2 · Mahajan et al. · 2022 [cited by applicant]
US 11558184B2 · Bareket et al. · 2023 [cited by applicant]
US 11582192B2 · Devarajan et al. · 2023 [cited by applicant]
US 11595385B2 · Rozner et al. · 2023 [cited by applicant]
US 11601400B2 · Yehudai et al. · 2023 [cited by applicant]
US 11622313B1 · Yadov et al. · 2023 [cited by applicant]
US 11627148B2 · Desai · 2023 [cited by applicant]
US 20150207642A1 · Bradbary · 2015 [cited by applicant]
US 20170339165A1 · Be'ery et al. · 2017 [cited by applicant]
US 20230164117A1 · Wu · 2023 [cited by applicant]