IP Library › Granted Patent US 12,634,295
Granted Patent B2
US 12,634,295 · App. 18/336,663 · Granted May 19, 2026

Time bound session management for operational technology (OT) applications

Inventors: Sunita Darbarwar (San Jose, CA); Dejan Mihajlovic (Sunnyvale, CA); Maneesh Sahu (San Francisco, CA); Abhijeet Malik (San Jose, CA); Sandip Davara (San Jose, CA); Monica Bhaskaran (Bengaluru, IN); Rakesh Adepu (Hyderabad, IN); Clifford Kahn (Sarasota, FL); Sunil Menon (Los Gatos, CA); Deepak Patel (Fremont, CA)
Assignee: Zscaler, Inc.
H04L63/108H04L63/102H04L67/143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,295
App. No.
18/336,663
Filed
Jun 16, 2023
Granted
May 19, 2026
Kind
B2
Art Unit
2441
USPC
709/225
Abstract

Systems and methods for time bound session management for Operational Technology (OT) applications using Cron expression policies over zero trust. Various embodiments include receiving a request to an end system from a user; determining that the request requires a time-based approval; performing one or more time-based policy checks associated with the request; and allowing or denying the request based on the one or more time-based policy checks. The steps can further include monitoring an active session between the user and the end system; and timing out the active session based on time-based policy checks.

Claims (34)

1 . A method comprising steps of:

receiving a request to an end system from a user;

determining that the request requires a time-based approval, wherein the time-based approval is defined using Cron expressions specifying at least one recurring time window for access to the end system and enforced via a zero trust network access (ZTNA) service;

performing one or more time-based policy checks associated with the Cron expressions and performing one or more additional zero trust policy checks related to the request, wherein the additional zero trust policy checks include evaluating at least user identity, and at least one of endpoint posture, device context, and least-privileged access; and

allowing or denying the request based on the one or more time-based policy checks and results of the one or more additional zero trust policy checks, wherein the end system comprises an Operational Technology (OT) device or application, and wherein allowing the request comprises dynamically establishing an on-demand outbound secure tunnel from a connector application associated with the OT device or application to the ZTNA service without requiring inbound firewall openings to an OT network hosting the OT device or application.

2 . The method of claim 1 , wherein the one or more time-based policy checks are associated with any of the user and the requested end system.

3 . The method of claim 1 , wherein the one or more time-based policy checks include looking up approval tables based on an identity of the user.

4 . The method of claim 3 , wherein responsive to no match being found in the approval tables, or if an appropriate approval table does not exist, the request is denied.

5 . The method of claim 1 , wherein the steps further include displaying one or more end systems to the user through a portal.

6 . The method of claim 5 , wherein the one or more end systems are marked as active, inactive, or expired based on time-based policy.

7 . The method of claim 1 , wherein the steps further include configuring time-based policies associated with any of a user, group of users, and specific end systems.

8 . The method of claim 7 , wherein the configuring is performed through calendar-based selections for designating allowed time windows.

9 . The method of claim 1 , wherein the one or more time-based policy checks include comparing a current time against a Coordinated Universal Time (UTC) start and end time of a given time window.

10 . The method of claim 1 , wherein the steps further comprise:

monitoring an active session between the user and the end system;

timing out the active session based on time-based policy checks, and

responsive to timing out the active session due to expiration of the recurring time window defined by the Cron expressions, transmitting a notification to the user explicitly indicating a time-based policy timeout.

11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

receiving a request to an end system from a user;

determining that the request requires a time-based approval, wherein the time-based approval is defined using Cron expressions specifying at least one recurring time window for access to the end system and enforced via a zero trust network access (ZTNA) service;

performing one or more time-based policy checks associated with the Cron expressions and performing one or more additional zero trust policy checks related to the request, wherein the additional zero trust policy checks include evaluating at least user identity, and at least one of endpoint posture, device context, and least-privileged access; and

allowing or denying the request based on the one or more time-based policy checks and results of the one or more additional zero trust policy checks, wherein the end system comprises an Operational Technology (OT) device or application, and wherein allowing the request comprises dynamically establishing an on-demand outbound secure tunnel from a connector application associated with the OT device or application to the ZTNA service without requiring inbound firewall openings to an OT network hosting the OT device or application.

12 . The non-transitory computer-readable medium of claim 11 , wherein the one or more time-based policy checks are associated with any of the user and the requested end system.

13 . The non-transitory computer-readable medium of claim 11 , wherein the one or more time-based policy checks include looking up approval tables based on an identity of the user.

14 . The non-transitory computer-readable medium of claim 13 , wherein responsive to no match being found in the approval tables, or if an appropriate approval table does not exist, the request is denied.

15 . The non-transitory computer-readable medium of claim 11 , wherein the steps further include displaying one or more end systems to the user through a portal.

16 . The non-transitory computer-readable medium of claim 15 , wherein the one or more end systems are marked as active, inactive, or expired based on time-based policy.

17 . The non-transitory computer-readable medium of claim 11 , wherein the steps further include configuring time-based policies associated with any of a user, group of users, and specific end systems.

18 . The non-transitory computer-readable medium of claim 17 , wherein the configuring is performed through calendar-based selections for designating allowed time windows.

19 . The non-transitory computer-readable medium of claim 11 , wherein the one or more time-based policy checks include comparing a current time against a Coordinated Universal Time (UTC) start and end time of a given time window.

20 . The non-transitory computer-readable medium of claim 11 , wherein the steps further comprise:

monitoring an active session between the user and the end system; and

timing out the active session based on time-based policy checks; and

responsive to timing out the active session due to expiration of the recurring time window defined by the Cron expressions, transmitting a notification to the user explicitly indicating a time-based policy timeout.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: DARBARWAR, SUNITA; MIHAJLOVIC, DEJAN; SAHU, MANEESH; MALIK, ABHIJEET; DAVARA, SANDIP; BHASKARAN, MONICA; ADEPU, RAKESH; KAHN, CLIFFORD; MENON, SUNIL; PATEL, DEEPAK
To: ZSCALER, INC.
Reel/Frame 063978/0039 →
Priority Claims (1)
IN 202311030868 · Apr 29, 2023 · national
Continuity (1)
Related Publication 20240364704A1 · Oct 31, 2024
References Cited (36)
US 6636923B1 · Meirsman et al. · 2003 [cited by applicant]
US 8869259B1 · Udupa et al. · 2014 [cited by applicant]
US 8990585B2 · Grube · 2015 [cited by examiner]
US 10284415B1 · Alabsi · 2019 [cited by examiner]
US 12120127B1 · Grube · 2024 [cited by examiner]
US 20060074618A1 · Miller et al. · 2006 [cited by applicant]
US 20070042756A1 · Perfetto et al. · 2007 [cited by applicant]
US 20070208857A1 · Danner · 2007 [cited by examiner]
US 20080307519A1 · Curcio · 2008 [cited by applicant]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20110161679A1 · Grube · 2011 [cited by examiner]
US 20110296486A1 · Burch et al. · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120023325A1 · Lai · 2012 [cited by applicant]
US 20120185913A1 · Martinez et al. · 2012 [cited by applicant]
US 20120281708A1 · Chauhan et al. · 2012 [cited by applicant]
US 20130347072A1 · Dinha · 2013 [cited by applicant]
US 20140022586A1 · Zehler · 2014 [cited by applicant]
US 20140282817A1 · Singer et al. · 2014 [cited by applicant]
US 20140317349A1 · Resch · 2014 [cited by examiner]
US 20180084011A1 · Joseph · 2018 [cited by examiner]
US 20200336508A1 · Srivastava · 2020 [cited by examiner]
US 20210390516A1 · Bobbala · 2021 [cited by examiner]
US 20220012657A1 · Tammana · 2022 [cited by examiner]
US 20220321594A1 · Formicola · 2022 [cited by examiner]
US 20230063075A1 · Misra · 2023 [cited by examiner]
US 20230123781A1 · Kaimal · 2023 [cited by examiner]
US 20240064174A1 · Molzon · 2024 [cited by examiner]
US 20240103818A1 · Gallagher · 2024 [cited by examiner]
US 20240114036A1 · May · 2024 [cited by examiner]
US 20240154938A1 · Wu · 2024 [cited by examiner]
US 20240323686A1 · Kumar · 2024 [cited by examiner]
CN 117201112A · 2023 [cited by examiner]
CN 119520093A · 2025 [cited by examiner]
J. R. Vic Winkler, “Securing the Cloud: Cloud Computer Security Techniques and Tactics”, May 2011, Syngress Publishing, Full Text. [cited by applicant]
Stephen R. Smoot, “Private Cloud Computing: Consolidation, Virtualization, and Service-Oriented Infrastructure”, Oct. 2011, Morgan Kaufman Publishers, Inc. Full Text. [cited by applicant]