Wildcard based private application access

US12470520B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12470520-B2
Application numberUS-202318227595-A
CountryUS
Kind codeB2
Filing dateJul 28, 2023
Priority dateJul 28, 2023
Publication dateNov 11, 2025
Grant dateNov 11, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system, comprising: a processor configured to: receive a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determine if the request for access to the application matches a wildcard, comprising to: forward the request to a domain name server (DNS) proxy or a loopback address for DNS resolution, wherein the loopback address is configured as a nameserver/relay, wherein the DNS proxy forwards the request to the nameserver/relay; and determine whether the request is resolved or is not resolved, wherein in the event that the request is not resolved, drop the request, and wherein in the event that the request is resolved, resolve the request to obtain an IP address related to the request; and automatically configure access information for the application that matches the wildcard; and a memory coupled to the processor and configured to provide the processor with instructions. 2 . The system of claim 1 , wherein the application is a private application executed in a data center associated with the enterprise. 3 . The system of claim 1 , wherein the access information includes the IP address. 4 . The system of claim 1 , wherein the IP address includes a private IP address. 5 . The system of claim 1 , wherein the access information includes the IP address and a protocol. 6 . The system of claim 1 , wherein the access information includes the IP address, a protocol, and a destination port. 7 . The system of claim 1 , wherein the wildcard is configured by an administrator of the enterprise for matching one or more fully qualified domain names (FQDNs) for the application. 8 . The system of claim 1 , wherein policy enforcement includes routing of traffic associated with the request using a mobile user gateway or a remote network gateway. 9 . The system of claim 1 , wherein policy enforcement includes routing of traffic associated with the request using a mobile user gateway or a remote network gateway, and wherein the mobile user gateway or the remote network gateway comprises an SD-WAN. 10 . The system of claim 1 , wherein policy enforcement includes traffic steering of traffic associated with the request using a mobile user gateway or a remote network gateway. 11 . The system of claim 1 , wherein policy enforcement includes traffic steering of traffic associated with the request using a mobile user gateway or a remote network gateway, and wherein the mobile user gateway or the remote network gateway comprises an SD-WAN. 12 . The system of claim 1 , wherein the processor is further configured to: perform application discovery using probing. 13 . The system of claim 1 , wherein the processor is further configured to: monitor flow session data of user access. 14 . The system of claim 1 , wherein the processor is further configured to: periodically update a local IP address associated with the application to a virtual IP (VIP) address mapping. 15 . The system of claim 1 , wherein the processor is further configured to: map the request to the application executing in a local regional data center. 16 . A method, comprising: receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard, comprising: forwarding the request to a domain name server (DNS) proxy or a loopback address for DNS resolution, wherein the loopback address is configured as a nameserver/relay, wherein the DNS proxy forwards the request to the nameserver/relay; and determining whether the request is resolved or is not resolved, wherein in the event that the request is not resolved, dropping the request, and wherein in the event that the request is resolved, resolving the request to obtain an IP address related to the request; and automatically configuring access information for the application that matches the wildcard. 17 . The method of claim 16 , wherein the application is a private application executed in a data center associated with the enterprise. 18 . The method of claim 16 , wherein the access information includes the IP address and a protocol. 19 . The method of claim 16 , wherein the access information includes the IP address, a protocol, and a destination port. 20 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for: receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard, comprising: forwarding the request to a domain name server (DNS) proxy or a loopback address for DNS resolution, wherein the loopback address is configured as a nameserver/relay, wherein the DNS proxy forwards the request to the nameserver/relay; and determining whether the request is resolved or is not resolved, wherein in the event that the request is not resolved, dropping the request, and wherein in the event that the request is resolved, resolving the request to obtain an IP address related to the request; and automatically configuring access information for the application that matches the wildcard.

Assignees

Inventors

Classifications

  • using domain name system [DNS] · CPC title

  • Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title

  • Rule management · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12470520B2 cover?
Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the applicati…
Who is the assignee on this patent?
Palo Alto Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L12/4641. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 11 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).