IP Library Granted Patent US 12,568,085
Granted Patent B2
US 12,568,085 · App. 18/502,280 · Granted Mar 3, 2026

Systems and methods for generating sub-identities for workloads

Inventors: Arvind Nadendla (San Jose, CA); Subramanian Srinivasan (Milpitas, CA); Sanjay Kalra (San Jose, CA); Murat Bog (Fremont, CA)
Assignee: Zscaler, Inc.
H04L63/10H04L47/10H04L63/0227H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,085
App. No.
18/502,280
Granted
Mar 3, 2026
Kind
B2
Abstract

Systems and methods for generating sub-identities for workloads in a cloud-based system. Various embodiments include receiving a key from an external system; generating one or more sub-identities from the key; assigning the one or more sub-identities to one or more workloads; and enforcing policies on the one or more workloads and traffic associated therewith based on the one or more sub-identities.

Claims (40)

1 . A method comprising steps of:

receiving a key from an external system, the key is associated with a customer;

generating one or more sub-identities from the key, wherein the one or more sub-identities are specific to the customer and used only within a cloud-based system;

assigning the one or more sub-identities to one or more workloads of the customer, wherein the one or more sub-identities are used within the cloud-based system to prevent exposure of the key to the customer and the one or more workloads, and to enable lifecycle management of the key, granular security controls for the key, and centralized enforcement of access policies within the cloud-based system;

enforcing policies in the cloud-based system on the one or more workloads and one or more payloads associated therewith based on the one or more sub-identities; and

converting the sub-identity back to the key prior to the one or more payloads reaching the external system.

2 . The method of claim 1 , wherein the steps further comprise:

performing, via the cloud-based system, inline monitoring of the one or more workloads;

extracting identification information from one or more payloads originating from the one or more workloads, wherein the identification information includes a sub-identity of the one or more sub-identities; and

enforcing policies on the one or more payloads based thereon.

3 . The method of claim 1 , wherein the one or more payloads originate from the one or more workloads operating in a cloud-based system and are directed to the external system, and wherein the one or more payloads are intercepted by the cloud-based system.

4 . The method of claim 1 , wherein enforcing policies comprises rate limiting, and access control based on a sub-identity of the one or more sub-identities identified in traffic.

5 . The method of claim 1 , wherein the one or more workloads are associated with an enterprise having a plurality of departments, and wherein the steps further comprise:

assigning each of the plurality of departments a sub-identity of the one or more sub-identities to utilize in payloads originating from workloads associated therewith.

6 . The method of claim 5 , wherein the enforcing policy is based on a department to which a workload is assigned.

7 . The method of claim 5 , wherein the enforcing policy includes allowing or blocking traffic from a workload to the external system based on a department to which the workload is assigned.

8 . The method of claim 1 , wherein the one or more sub-identities are customer specific, and wherein the one or more sub-identities are only utilized within a cloud-based system.

9 . The method of claim 8 , wherein the steps further comprise:

converting a sub-identity of the one or more sub-identities within a payload to the key prior to the payload reaching the external system.

10 . The method of claim 1 , wherein the key is not shared with the one or more workloads.

11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

receiving a key from an external system, the key is associated with a customer;

generating one or more sub-identities from the key, wherein the one or more sub-identities are specific to the customer and used only within a cloud-based system;

assigning the one or more sub-identities to one or more workloads of the customer, wherein the one or more sub-identities are used within the cloud-based system to prevent exposure of the key to the customer and the one or more workloads and to enable lifecycle management of the key, granular security controls for the key, and centralized enforcement of access policies within the cloud-based system;

enforcing policies in the cloud-based system on the one or more workloads and one or more payloads associated therewith based on the one or more sub-identities; and

converting the sub-identity back to the key prior to the one or more payloads reaching the external system.

12 . The non-transitory computer-readable medium of claim 11 , wherein the steps further comprise:

performing, via the cloud-based system, inline monitoring of the one or more workloads;

extracting identification information from one or more payloads originating from the one or more workloads, wherein the identification information includes a sub-identity of the one or more sub-identities; and

enforcing policies on the one or more payloads based thereon.

13 . The non-transitory computer-readable medium of claim 11 , wherein the one or more payloads originate from the one or more workloads operating in a cloud-based system and are directed to the external system, and wherein the one or more payloads are intercepted by the cloud-based system.

14 . The non-transitory computer-readable medium of claim 11 , wherein enforcing policies comprises rate limiting, and access control based on a sub-identity of the one or more sub-identities identified in traffic.

15 . The non-transitory computer-readable medium of claim 11 , wherein the one or more workloads are associated with an enterprise having a plurality of departments, and wherein the steps further comprise:

assigning each of the plurality of departments a sub-identity of the one or more sub-identities to utilize in payloads originating from workloads associated therewith.

16 . The non-transitory computer-readable medium of claim 15 , wherein the enforcing policy is based on a department to which a workload is assigned.

17 . The non-transitory computer-readable medium of claim 15 , wherein the enforcing policy includes allowing or blocking traffic from a workload to the external system based on a department to which the workload is assigned.

18 . The non-transitory computer-readable medium of claim 11 , wherein the one or more sub-identities are customer specific, and wherein the one or more sub-identities are only utilized within a cloud-based system.

19 . The non-transitory computer-readable medium of claim 18 , wherein the steps further comprise:

converting a sub-identity of the one or more sub-identities within a payload to the key prior to the payload reaching the external system.

20 . The non-transitory computer-readable medium of claim 11 , wherein the key is not shared with the one or more workloads.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2023
From: NADENDLA, ARVIND; SRINIVASAN, SUBRAMANIAN; KALRA, SANJAY; BOG, MURAT
To: ZSCALER, INC.
Reel/Frame 065467/0536 →
Continuity (1)
Related Publication 20250150455A1 · May 8, 2025
References Cited (55)
US 5961593A · Gabber · 1999 [cited by examiner]
US 6407997B1 · Denap et al. · 2002 [cited by applicant]
US 6434150B1 · Bog et al. · 2002 [cited by applicant]
US 6490273B1 · Denap et al. · 2002 [cited by applicant]
US 6539386B1 · Athavale et al. · 2003 [cited by applicant]
US 6684251B1 · Qiu et al. · 2004 [cited by applicant]
US 7096189B1 · Srinivasan · 2006 [cited by applicant]
US 7254114B1 · Turner et al. · 2007 [cited by applicant]
US 7421483B1 · Kalra et al. · 2008 [cited by applicant]
US 7496750B2 · Kumar et al. · 2009 [cited by applicant]
US 7551567B2 · Anthias et al. · 2009 [cited by applicant]
US 7693131B2 · Kaplan et al. · 2010 [cited by applicant]
US 7729364B2 · Bog et al. · 2010 [cited by applicant]
US 7738396B1 · Turner et al. · 2010 [cited by applicant]
US 7792975B1 · Dashora et al. · 2010 [cited by applicant]
US 7869352B1 · Turner et al. · 2011 [cited by applicant]
US 7881967B1 · Srinivasan et al. · 2011 [cited by applicant]
US 8005000B1 · Srinivasan · 2011 [cited by applicant]
US 8612295B2 · Gidwani et al. · 2013 [cited by applicant]
US 10581891B1 · Kapoor et al. · 2020 [cited by applicant]
US 10616180B2 · Chanak et al. · 2020 [cited by applicant]
US 10848395B2 · Srinivasan · 2020 [cited by applicant]
US 10986114B1 · Singh et al. · 2021 [cited by applicant]
US 11075923B1 · Srinivasan et al. · 2021 [cited by applicant]
US 11188571B1 · Chen et al. · 2021 [cited by applicant]
US 11256759B1 · Chen et al. · 2022 [cited by applicant]
US 11537456B2 · Nadendla et al. · 2022 [cited by applicant]
US 11652872B1 · Parla · 2023 [cited by examiner]
US 20030140113A1 · Balasuriya · 2003 [cited by examiner]
US 20040002903A1 · Stolfo · 2004 [cited by examiner]
US 20050076248A1 · Cahill · 2005 [cited by examiner]
US 20080002592A1 · Yegani · 2008 [cited by examiner]
US 20100132031A1 · Zheng · 2010 [cited by examiner]
US 20140258860A1 · Subramanian · 2014 [cited by applicant]
US 20160301661A1 · Poirier et al. · 2016 [cited by applicant]
US 20170054622A1 · Mishra · 2017 [cited by examiner]
US 20170093812A1 · Schenk · 2017 [cited by examiner]
US 20190081983A1 · Teal · 2019 [cited by examiner]
US 20190245782A1 · Jin · 2019 [cited by examiner]
US 20210029119A1 · Raman · 2021 [cited by examiner]
US 20210318862A1 · Subramanian et al. · 2021 [cited by applicant]
US 20210360038A1 · Schlotman, Jr. et al. · 2021 [cited by applicant]
US 20220046059A1 · Pandurangi · 2022 [cited by examiner]
US 20220286854A1 · Howe et al. · 2022 [cited by applicant]
US 20220286894A1 · Howe et al. · 2022 [cited by applicant]
US 20220286912A1 · Howe et al. · 2022 [cited by applicant]
US 20230148392A1 · Yu · 2023 [cited by examiner]
US 20240283826A1 · Ganguli · 2024 [cited by examiner]
US 20240388606A1 · Mihajlovic · 2024 [cited by examiner]
US 20240422198A1 · Pampati · 2024 [cited by examiner]
US 20250147812A1 · Nadendla · 2025 [cited by examiner]
US 20250150455A1 · Nadendla · 2025 [cited by examiner]
EP 2357772B1 · 2017 [cited by applicant]
EP 1839176B1 · 2018 [cited by applicant]
EP 4167116A1 · 2023 [cited by applicant]