IP Library › Granted Patent US 12,563,063
Granted Patent B2
US 12,563,063 · App. 18/130,076 · Granted Feb 24, 2026

Policy based traffic inspection in zero trust private networks

Inventors: Kanti Varanasi (San Jose, CA); Jane Joseph (Leander, TX); Mohit Chawla (Punjab, IN); Nikhil Bhatia (San Jose, CA); Sunil Menon (Los Gatos, CA)
Assignee: Zscaler, Inc.
H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,063
App. No.
18/130,076
Granted
Feb 24, 2026
Kind
B2
Abstract

Systems and methods for policy based traffic inspection in zero trust private networks. Various embodiments include receiving a request for a workload; analyzing one or more criteria associated with the request; determining an inspection profile to utilize for the request based on the analyzing of the one or more criteria; applying the inspection profile to the request; and inspecting traffic associated with the request based on the inspection profile.

Claims (36)

1 . A method comprising steps of:

receiving a request for a workload;

analyzing one or more criteria associated with the request, the one or more criteria including at least one of a Security Assertion Markup Language (SAML) attribute, client posture, end user network, client type, or requested application segment;

determining an inspection profile to utilize for the request based on the analyzing of the one or more criteria, wherein the inspection profile defines one or more traffic inspection rules applied within a cloud-based enforcement node, the inspection profile being adaptively selected such that requests originating from a trusted network are assigned a first inspection profile with minimal inspection rules and requests originating from an untrusted network are assigned a second inspection profile with restrictive inspection rules;

applying the inspection profile to the request; and

inspecting traffic associated with the request based on the inspection profile,

wherein the steps are performed in a multi-tenant cloud-based system, the multi-tenant cloud-based system being a private cloud, a public cloud, or a hybrid cloud including one or more enforcement nodes operating as a zero trust platform and configured to perform deep packet inspection and zero-day exploits analysis.

2 . The method of claim 1 , wherein the analyzing is based on one or more predetermined rules based on a degree of trust assigned by an admin that govern how inspection profiles are assigned to different requests.

3 . The method of claim 1 , wherein the one or more criteria include any of Security Assertion Markup Language (SAML) attributes, client posture, end user network, client type, and requested application segment.

4 . The method of claim 3 , wherein a request originating from a trusted end user network is assigned an inspection profile with minimal traffic inspection rules.

5 . The method of claim 3 , wherein a request originating from an untrusted end user network is assigned an inspection profile with restrictive traffic inspection rules.

6 . The method of claim 1 , wherein the request is for a workload in a private network.

7 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

receiving a request for a workload;

analyzing one or more criteria associated with the request, the one or more criteria including at least one of a Security Assertion Markup Language (SAML) attribute, client posture, end user network, client type, or requested application segment;

determining an inspection profile to utilize for the request based on the analyzing of the one or more criteria, wherein the inspection profile defines one or more traffic inspection rules applied within a cloud-based enforcement node, the inspection profile being adaptively selected such that requests originating from a trusted network are assigned a first inspection profile with minimal inspection rules and requests originating from an untrusted network are assigned a second inspection profile with restrictive inspection rules;

applying the inspection profile to the request; and

inspecting traffic associated with the request based on the inspection profile

wherein the steps are performed in a multi-tenant cloud-based system, the multi-tenant cloud-based system being a private cloud, a public cloud, or a hybrid cloud including one or more enforcement nodes operating as a zero trust platform and configured to perform deep packet inspection and zero-day exploits analysis.

8 . The non-transitory computer-readable medium of claim 7 , wherein the analyzing is based on one or more predetermined rules that govern how inspection profiles are assigned to different requests.

9 . The non-transitory computer-readable medium of claim 7 , wherein the one or more criteria include any of Security Assertion Markup Language (SAML) attributes, client posture, end user network, client type, and requested application segment.

10 . The non-transitory computer-readable medium of claim 9 , wherein a request originating from a trusted end user network is assigned an inspection profile with minimal traffic inspection rules.

11 . The non-transitory computer-readable medium of claim 9 , wherein a request originating from an untrusted end user network is assigned an inspection profile with restrictive traffic inspection rules.

12 . The non-transitory computer-readable medium of claim 7 , wherein the request is for a workload in a private network.

13 . A multi-tenant cloud-based system comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to:

receive a request for a workload;

analyze one or more criteria associated with the request, the one or more criteria including at least one of a Security Assertion Markup Language (SAML) attribute, client posture, end user network, client type, or requested application segment;

determine an inspection profile to utilize for the request based on the analyzing of the one or more criteria, wherein the inspection profile defines one or more traffic inspection rules applied within a cloud-based enforcement node, the inspection profile being adaptively selected such that requests originating from a trusted network are assigned a first inspection profile with minimal inspection rules and requests originating from an untrusted network are assigned a second inspection profile with restrictive inspection rules;

apply the inspection profile to the request; and

inspect traffic associated with the request based on the inspection profile,

wherein the steps are performed in the multi-tenant cloud-based system, the multi-tenant cloud-based system being a private cloud, a public cloud, or a hybrid cloud including one or more enforcement nodes operating as a zero trust platform and configured to perform deep packet inspection and zero-day exploits analysis.

14 . The cloud-based system of claim 13 , wherein the analyzing is based on one or more predetermined rules that govern how inspection profiles are assigned to different requests.

15 . The cloud-based system of claim 13 , wherein the one or more criteria include any of Security Assertion Markup Language (SAML) attributes, client posture, end user network, client type, and requested application segment.

16 . The cloud-based system of claim 15 , wherein a request originating from a trusted end user network is assigned an inspection profile with minimal traffic inspection rules.

17 . The cloud-based system of claim 15 , wherein a request originating from an untrusted end user network is assigned an inspection profile with restrictive traffic inspection rules.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: VARANASI, KANTI; JOSEPH, JANE; CHAWLA, MOHIT; BHATIA, NIKHIL; MENON, SUNIL
To: ZSCALER, INC.
Reel/Frame 063204/0416 →
Continuity (1)
Related Publication 20240275803A1 · Aug 15, 2024
References Cited (18)
US 6636923B1 · Meirsman et al. · 2003 [cited by applicant]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 20060074618A1 · Miller et al. · 2006 [cited by applicant]
US 20070042756A1 · Perfetto et al. · 2007 [cited by applicant]
US 20080307519A1 · Curcio · 2008 [cited by applicant]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120023325A1 · Lai · 2012 [cited by applicant]
US 20120185913A1 · Martinez et al. · 2012 [cited by applicant]
US 20120281708A1 · Chauhan et al. · 2012 [cited by applicant]
US 20130347072A1 · Dinha · 2013 [cited by applicant]
US 20140022586A1 · Zehler · 2014 [cited by applicant]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20200236112A1 · Pularikkal · 2020 [cited by examiner]
US 20210336959A1 · Shah · 2021 [cited by examiner]
J. R. Vic Winkler, “Securing the Cloud: Cloud Computer Security Techniques and Tactics”, May 2011, Syngress Publishing, Full Text. [cited by applicant]
Stephen R. Smoot, “Private Cloud Computing: Consolidation, Virtualization, and Service-Oriented Infrastructure”, Oct. 2011, Morgan Kaufman Publishers, Inc. Full Text. [cited by applicant]