IP Library Granted Patent US 12695733
Granted Patent B2
US 12695733 · App. 18/669,529 · Granted Jul 28, 2026

Fingerprint-based network mapping of cyber-physical assets

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/0428G06F16/909G06F16/951G06N7/01H04L9/14H04L9/3236H04L9/3297H04L63/061H04L63/12H04L63/1408H04L63/1433G06N5/01G06N5/045G06N5/046G06N20/00H04L9/50H04L63/0442H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695733
App. No.
18/669,529
Granted
Jul 28, 2026
Kind
B2
Abstract

A system and method for fingerprint-based network mapping of cyber-physical assets, including a distributed operating system, parameter evaluation engine, at least one cyber-physical asset, at least one crypt-ledger, a network, and a scanner that retrieves stored fingerprint records and performs scans of cyber-physical assets to compare against corresponding fingerprints and update a cyber-physical graph based on the success or failure of fingerprint matching.

Claims (49)

1 . A computing system for fingerprint-based network mapping of cyber-physical assets, the computing system comprising:

one or more hardware processors configured for:

receiving a trigger event from a first computing device, the trigger event comprising a packet that is received over a network and that satisfies a preconfigured condition;

in response to the received trigger event, performing a scan of one or more ports of the first computing device, the scan being based on a stored fingerprint record associated with the first computing device;

if results of the scan do not match the fingerprint record associated with the first computing device, transmitting an encrypted failure notification to a second computing device;

if the results of the scan match the fingerprint record associated with the first computing device, transmitting an encrypted success notification to the second computing device; and

modifying an existing cyber-physical graph to include updated status information associated with the first computing device based on the verified encrypted success and failure notifications.

2 . The system of claim 1 , wherein the cyber-physical graph is stored in a multidimensional time-series database that is configured for receiving data asynchronously from multiple sources over a period of time, and establishing graph-series data structures with received data.

3 . The system of claim 2 , wherein the results of the scan are stored with attached time-series metadata.

4 . The system of claim 3 , wherein the attached time-series metadata comprises the time when the fingerprint record was created.

5 . The system of claim 3 , wherein the attached time-series metadata comprises the time at which the fingerprint record was retrieved for the scan.

6 . The system of claim 3 , wherein the attached time-series metadata comprises the time at which the scan was initiated.

7 . The system of claim 3 , wherein the attached time-series metadata comprises the time at which the scan was completed.

8 . A computer-implemented method for fingerprint-based network mapping of cyber-physical assets, the computer-implemented method comprising:

receiving a trigger event from a first computing device, the trigger event comprising a packet that is received over a network and that satisfies a preconfigured condition;

in response to the received trigger event, performing a scan of one or more ports of the first computing device, the scan being based on a stored fingerprint record associated with the first computing device;

if results of the scan do not match the fingerprint record associated with the first computing device, transmitting an encrypted failure notification to a second computing device;

if the results of the scan match the fingerprint record associated with the first computing device, transmitting an encrypted success notification to the second computing device; and

modifying an existing cyber-physical graph based on the verified encrypted success and failure notifications.

9 . The method of claim 8 , wherein the cyber-physical graph is stored in a multidimensional time-series database that is configured for receiving data asynchronously from multiple sources over a period of time, and establishing graph-series data structures with received data.

10 . The method of claim 9 , wherein the results of the scan are stored with attached time-series metadata.

11 . The method of claim 10 , wherein the attached time-series metadata comprises the time when the fingerprint record was created.

12 . The method of claim 10 , wherein the attached time-series metadata comprises the time at which the fingerprint record was retrieved for the scan.

13 . The method of claim 10 , wherein the attached time-series metadata comprises the time at which the scan was initiated.

14 . The method of claim 10 , wherein the attached time-series metadata comprises the time at which the scan was completed.

15 . A system for fingerprint-based network mapping of cyber-physical assets, comprising one or more computers with executable instructions that, when executed, cause the system to:

receive a trigger event from a first computing device, the trigger event comprising a packet that is received over a network and that satisfies a preconfigured condition;

in response to the received trigger event, perform a scan of one or more ports of the first computing device, the scan being based on a stored fingerprint record associated with the first computing device;

if results of the scan do not match the fingerprint record associated with the first computing device, transmit an encrypted failure notification to a second computing device;

if results of the scan match the fingerprint record associated with the first computing device, transmit an encrypted success notification to the second computing device;

modify an existing cyber-physical graph to include updated status information associated with the first computing device based on the verified encrypted success and failure notifications.

16 . The system of claim 15 , wherein the cyber-physical graph is stored in a multidimensional time-series database that is configured for receiving data asynchronously from multiple sources over a period of time, and establishing graph-series data structures with received data.

17 . The system of claim 16 , wherein the results of the scan are stored with attached time-series metadata.

18 . The system of claim 17 , wherein the attached time-series metadata comprises the time when the fingerprint record was created.

19 . The system of claim 17 , wherein the attached time-series metadata comprises the time at which the fingerprint record was retrieved for the scan.

20 . The system of claim 17 , wherein the attached time-series metadata comprises the time at which the scan was initiated.

21 . The system of claim 17 , wherein the attached time-series metadata comprises the time at which the scan was completed.

22 . Non-transitory, computer-readable storage media having computer executable instructions embodied thereon that, when executed by one or more processors of a computing system for fingerprint-based network mapping of cyber-physical assets, cause the computing system to:

receive a trigger event from a first computing device, the trigger event comprising a packet that is received over a network and that satisfies a preconfigured condition;

in response to the received trigger event, perform a scan of one or more ports of the first computing device, the scan being based on a stored fingerprint record associated with the first computing device;

if results of the scan do not match the fingerprint record associated with the first computing device, transmit an encrypted failure notification to a second computing device;

if the results of the scan match the fingerprint record associated with the first computing device, transmit an encrypted success notification to the second computing device; and

modifying an existing cyber-physical graph to include updated status information associated with the first computing device based on the verified encrypted success and failure notifications.

23 . The non-transitory, computer-readable storage media of claim 22 , wherein the cyber-physical graph is stored in a multidimensional time-series database that is configured for receiving data asynchronously from multiple sources over a period of time, and establishing graph-series data structures with received data.

24 . The non-transitory, computer-readable storage media of claim 23 , wherein the results of the scan are stored with attached time-series metadata.

25 . The non-transitory, computer-readable storage media of claim 24 , wherein the attached time-series metadata comprises the time when the fingerprint record was created.

26 . The non-transitory, computer-readable storage media of claim 24 , wherein the attached time-series metadata comprises the time at which the fingerprint record was retrieved for the scan.

27 . The non-transitory, computer-readable storage media of claim 24 , wherein the attached time-series metadata comprises the time at which the scan was initiated.

28 . The non-transitory, computer-readable storage media of claim 24 , wherein the attached time-series metadata comprises the time at which the scan was completed.