Configuring IoT devices for policy enforcement

US12470602B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12470602-B2
Application numberUS-202318484392-A
CountryUS
Kind codeB2
Filing dateOct 10, 2023
Priority dateJun 6, 2022
Publication dateNov 11, 2025
Grant dateNov 11, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The technology disclosed relates to configuring IoT devices for policy enforcement. In particular, the technology disclosed relates to configuring a plurality of special-purpose devices on a network segment of a network to steer outbound network traffic to an inline secure forwarder on the network segment instead of a default gateway on the network segment. The inline secure forwarder is configured to route the outbound network traffic to a policy enforcement point for a policy enforcement.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system, comprising: a device configurer on a network segment of a network, comprising: a configurer processor, and a configurer memory having stored thereon configuration instructions that, upon execution by the configurer processor, causes the configurer processor to: configure a plurality of special-purpose devices to steer outbound network traffic to an inline secure forwarder on the network segment instead of a default gateway on the network segment by transmitting a modified setting of each of the plurality of special-purpose devices to designate the inline secure forwarder as the default gateway; and the inline secure forwarder on the network segment, comprising: a forwarder processor, and a forwarder memory having stored thereon forwarding instructions that, upon execution by the forwarder processor, causes the forwarder processor to: route the outbound network traffic to a policy enforcement point for a policy enforcement, determine, from the outbound network traffic, metadata required for the policy enforcement, and append the metadata to the outbound network traffic and sends the outbound network traffic appended with the metadata to the policy enforcement point for the policy enforcement. 2 . The system of claim 1 , wherein the configuration instructions to configure the plurality of special-purpose devices comprises using static manual configuring. 3 . The system of claim 1 , wherein the configuration instructions to configure the plurality of special-purpose devices comprises using static automated configuring. 4 . The system of claim 1 , wherein the metadata includes a device classification of special-purpose devices in the plurality of special-purpose devices. 5 . The system of claim 1 , further comprising: the policy enforcement point, wherein the policy enforcement point is implemented as a cloud service. 6 . The system of claim 1 , wherein the metadata about a particular special-purpose device uniquely identifies the particular special-purpose device. 7 . The system of claim 1 , wherein the metadata includes media access control (MAC) addresses of special-purpose devices in the plurality of special-purpose devices. 8 . The system of claim 1 , wherein the metadata includes pre-network address translated (pre-NATed) IP addresses of the special-purpose devices. 9 . The system of claim 1 , wherein the metadata includes information about the network segment. 10 . The system of claim 1 , wherein the metadata includes manufacturing information of special-purpose devices in the plurality of special-purpose devices. 11 . The system of claim 1 , wherein the forwarding instructions comprise further forwarding instructions that, upon execution by the forwarder processor, cause the forwarder processor to: append the metadata to the outbound network traffic on a packet level. 12 . The system of claim 1 , further comprising: the policy enforcement point, comprising: one or more processors, and one or more memories having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to: classify the outbound network traffic based on the metadata, wherein the classifications comprise benign and malicious. 13 . The system of claim 12 , wherein the one or more memories of the policy enforcement point comprises further instructions that, upon execution by the one or more processors, cause the one or more processors to: based on a benign classification, send the outbound network traffic to one or more out-of-network destinations intended by the special-purpose devices. 14 . The system of claim 13 , wherein the out-of-network destinations include cloud applications. 15 . The system of claim 13 , wherein the out-of-network destinations include one of web applications and websites. 16 . The system of claim 12 , wherein the one or more memories of the policy enforcement point comprises further instructions that, upon execution by the one or more processors, cause the one or more processors to: based on a malicious classification, block the outbound network traffic. 17 . The system of claim 1 , wherein the device configurer is implemented in a dynamic host configuration protocol (DHCP) server. 18 . The system of claim 1 , wherein the configuration instructions comprise further configuration instructions that, upon execution by the configurer processor, cause the configurer processor to: intercept a dynamic host configuration protocol (DHCP) request from a special-purpose device of the special-purpose devices; and modify a DHCP response to the DHCP request with the modified setting. 19 . The system of claim 1 , wherein the configuration instructions comprise further instructions that, upon execution by the configurer processor, causes the configurer processor to: determine a classification of each of the plurality of special-purpose devices as special-purpose devices. 20 . The system of claim 19 , wherein the instructions to determine the classification comprise instructions to analyze data associated with the respective special-purpose device.

Assignees

Inventors

Classifications

  • at the network layer · CPC title

  • Filtering by information in the payload · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP] · CPC title

  • for supporting lawful interception, monitoring or retaining of communications or communication related information (circuit switched telephony call monitoring H04M3/2281) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12470602B2 cover?
The technology disclosed relates to configuring IoT devices for policy enforcement. In particular, the technology disclosed relates to configuring a plurality of special-purpose devices on a network segment of a network to steer outbound network traffic to an inline secure forwarder on the network segment instead of a default gateway on the network segment. The inline secure forwarder is config…
Who is the assignee on this patent?
Netskope Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 11 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).