IP Library Granted Patent US 12,574,413
Granted Patent B2
US 12,574,413 · App. 17/719,175 · Granted Mar 10, 2026

Systems and methods for implementing a family policy using a cooperative security fabric

Inventors: Michael Xie (Palo Alto, CA); Robert A. May (Burnaby, CA); Lino Xu (Vancouver, CA); Jordan E. Thompson (Vancouver, CA)
Assignee: Fortinet, Inc.
H04L63/20H04L9/40H04L63/00H04L63/0209H04L63/0263H04L63/10H04L63/14H04L63/1441H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,413
App. No.
17/719,175
Granted
Mar 10, 2026
Kind
B2
Abstract

Systems, devices, and methods are discussed for treating a number of network security devices in a cooperative security fabric as a unified object for configuration purposes.

Claims (56)

1 . A method for providing network security across a cooperative security fabric, the method comprising:

receiving, by a processing resource associated with a root network security device in the cooperative security fabric, a security rule relevant to at least a first network security device and a second network security device in the cooperative security fabric;

creating, by the processing resource:

a first security message specific to the first network security device, wherein the first security message includes an instruction to implement a first portion of the security rule on the first network security device, the instruction of the first security message being specific to a hardware and software configuration of the first network security device; and

a second security message specific to the second network security device, wherein the second security message includes an instruction to implement a second portion of the security rule on the second network security device, the instruction of the second security message being specific to a hardware and software configuration of the second network security device, and wherein the hardware and software configuration of the second network security device is different from the hardware and software configuration of the first network security device;

transmitting, by the processing resource:

the first security message to the first network security device via the cooperative security fabric; and

the second security message to the second network security device via the cooperative security fabric;

identifying, by the processing resource, a number of network security devices in the cooperative security fabric to which the security rule is relevant, wherein

the number of network security devices includes at least one leaf network security device and at least one intermediate network security device along a path between the root network security device and the leaf network security device; and

a network security device is precluded from issuing queries to another network security device that is not downstream.

2 . The method of claim 1 , the method further comprising:

receiving, by the processing resource, a user request to enforce a family mode on the cooperative security fabric; and

precluding, by the processing resource, access to modifying security parameters of the first network security device and the second security device based at least in part on the user request to enforce the family mode.

3 . The method of claim 2 , the method further comprising:

receiving, by the processing resource, a user request to stop enforcing the family mode on the cooperative security fabric; and

allowing, by the processing resource, access to modifying the security parameters of the first network security device and the second security device based at least in part on the user request to stop enforcing the family mode.

4 . The method of claim 1 , wherein the first network security device protects access to a first network and the second security device protects access to a second network.

5 . The method of claim 1 , wherein the first network security device is a closest network security device to an endpoint in the cooperative security fabric and wherein a portion of the security rule relevant to the endpoint is implemented on the first network security device.

6 . The method of claim 1 , wherein the security rule is an intent based security rule, and wherein the method further comprises:

translating, by the processing resource, the intent based security rule into a plurality of hardware specific security modifications.

7 . The method of claim 6 , wherein the intent based security rule defines a subset of users using a particular subset of networks protected within the cooperative security fabric for accessing particular sites.

8 . The method of claim 7 , wherein network devices impacted by the rule is limited to network devices closest to endpoints for which the security rule is being implemented.

9 . The method of claim 6 , wherein a network address is translated only at an egress from the cooperative security fabric.

10 . The method of claim 9 , wherein traffic within the cooperative security fabric is only logged when the network address is translated.

11 . A system for providing network security across a cooperative security fabric, the system comprising:

a root network security device in the cooperative security fabric including a processing resource;

a non transient non-transitory computer readable medium coupled to the processing resource and having stored therein instructions that when executed by the processing resource cause the processing resource to:

receive a security rule relevant to at least a first network security device and a second network security device in the cooperative security fabric;

create a first security message specific to the first network security device, wherein the first security message includes an instruction to implement a first portion of the security rule on the first network security device, the instruction of the first security message being specific to a hardware and software configuration of the first network security device;

create a second security message specific to the second network security device, wherein the second security message includes an instruction to implement a second portion of the security rule on the second network security device, the instruction of the second security message being specific to a hardware and software configuration of the second network security device, and wherein the hardware and software configuration of the second network security device is different from the hardware and software configuration of the first network security device;

transmit the first security message to the first network security device and the second security message to the second network security device via the cooperative security fabric;

identify a number of network security devices in the cooperative security fabric to which the security rule is relevant, wherein

the number of network security devices includes at least one leaf network security device and at least one intermediate network security device along a path between the root network security device and the leaf network security device; and

a network security device is precluded from issuing queries to another network security device that is not downstream.

12 . The system of claim 11 , wherein the non transient non-transitory computer readable medium further has stored thereon instructions that when executed by the processing resource cause the processing resource to:

receive a user request to enforce a family mode on the cooperative security fabric; and

preclude access to modifying security parameters of the first network security device and the second security device based at least in part on the user request to enforce the family mode.

13 . The system of claim 12 , wherein the non transient non-transitory computer readable medium further has stored thereon instructions that when executed by the processing resource cause the processing resource to:

receive a user request to stop enforcing the family mode on the cooperative security fabric; and

allow access to modifying security parameters of the first network security device and the second security device based at least in part on the user request to stop enforcing the family mode.

14 . The system of claim 11 , wherein the first network security device protects access to a first network and the second security device protects access to a second network.

15 . The system of claim 11 , wherein the first network security device is a closest network security device to an endpoint in the cooperative security fabric and wherein a portion of the security rule relevant to the endpoint is implemented on the first network security device.

16 . The system of claim 11 , wherein the security rule is an intent-based security rule and the non-transitory computer readable medium further has stored thereon instructions that when executed by the processing resource cause the processing resource to:

translate the intent based security rule into a plurality of hardware specific security modifications.

17 . The system of claim 16 , wherein the intent based security rule defines a subset of users using a particular subset of networks protected within the cooperative security fabric for accessing particular sites.

18 . The system of claim 17 , wherein network devices impacted by the rule is limited to network devices closest to endpoints for which the security rule is being implemented.

19 . The system of claim 16 , wherein a network address is translated only at an egress from the cooperative security fabric.

20 . A non-transitory computer readable medium having stored therein instructions that when executed by a processing resource cause the processing resource to:

receive a security rule relevant to at least a first network security device and a second network security device in a cooperative security fabric;

create a first security message specific to the first network security device, wherein the first security message includes an instruction to implement a first portion of the security rule on the first network security device, the instruction of the first security message being specific to a hardware and software configuration of the first network security device;

create a second security message specific to the second network security device, wherein the second security message includes an instruction to implement a second portion of the security rule on the second network security device, the instruction of the second security message being specific to a hardware and software configuration of the second network security device, and wherein the hardware and software configuration of the second network security device is different from the hardware and software configuration of the first network security device;

transmit the first security message to the first network security device and the second security message to the second network security device via the cooperative security fabric;

identify a number of network security devices in the cooperative security fabric to which the security rule is relevant, wherein

the number of network security devices includes at least one leaf network security device and at least one intermediate network security device along a path between the root network security device and the leaf network security device; and

a network security device is precluded from issuing queries to another network security device that is not downstream.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2022
From: XIE, MICHAEL; MAY, ROBERT A.; XU, LINO; THOMPSON, JORDAN E.
To: FORTINET, INC.
Reel/Frame 059578/0020 →
Continuity (1)
Related Publication 20230328105A1 · Oct 12, 2023
References Cited (8)
US 5351776A · Keller · 1994 [cited by examiner]
US 10686839B2 · Xie et al. · 2020 [cited by applicant]
US 20070294755A1 · Dadhia · 2007 [cited by examiner]
US 20110185085A1 · Perkins · 2011 [cited by examiner]
US 20160080399A1 · Harris · 2016 [cited by applicant]
US 20170005986A1 · Bansal · 2017 [cited by examiner]
US 20200034456A1 · Montgomery-Recht · 2020 [cited by examiner]
Office Action for U.S. Appl. No. 17/857,133, mailed Jun. 12, 2024, 36 pages. [cited by applicant]