IP Library Granted Patent US 12701106
Granted Patent B2
US 12701106 · App. 18/789,647 · Granted Aug 4, 2026

Ongoing trigger-based scanning of cyber-physical assets

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/0428G06F16/909G06F16/951G06N7/01H04L9/14H04L9/3236H04L9/3297H04L63/061H04L63/12H04L63/123H04L63/1408H04L63/1433H04L67/52G06N5/01G06N5/045G06N5/046G06N20/00H04L9/50H04L63/0442H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12701106
App. No.
18/789,647
Granted
Aug 4, 2026
Kind
B2
Abstract

A system and method for trigger-based scanning of cyber-physical assets, including a distributed operating system, parameter evaluation engine, at least one cyber-physical asset, at least one crypt-ledger, a network, and a scanner that detects trigger conditions and events and performs scans of cyber-physical assets based on the trigger and any relevant stored scan rules before storing scan results as time-series data.

Claims (74)

1 . A computing system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising:

a first computing device comprising a first processor, a first memory, and a first plurality of programming instructions, when operating on the first computing device, cause the first computing device to:

determine a location of an asset;

generate an encrypted message comprising an identifier of the first computing device and the location of the asset; and

transmit the encrypted message to a second computing device;

the second computing device comprising a second processor, a second memory, and a second plurality of programming instructions, when operating on the second computing device, cause the second computing device to:

receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieve rules associated with the triggering event;

perform one or more port scans of the first computing device based on the retrieved rules;

produce scan results of the port scans;

attach time-series metadata to each scan result; and

generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.

2 . The system of claim 1 , further comprising a third computing device comprising a third processor, a third memory, and a third plurality of programming instructions, when operating on the third processor, cause the third computing device to:

receive an encrypted scan report message from the second computing device;

verify the report's authenticity;

update a graph with the scan results and the time-series metadata;

store the graph; and

establish data structures with data received from one or more network sources.

3 . The system of claim 1 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.

4 . A computer-implemented method for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, the computer-implemented method comprising the steps of:

determining, using a first computing device, a location of an asset;

generating, using the first computing device, an encrypted message comprising an identifier of the first computing device and the location of the asset;

transmitting, using the first computing device, the encrypted message to a second computing device;

receiving, at the second computing device, a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attaching, using the second computing device, metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieving, using the second computing device, rules associated with the triggering event;

performing, using the second computing device, one or more port scans of the first computing device based on the retrieved rules;

producing, using the second computing device, scan results of the port scans;

attaching, using the second computing device, time-series metadata to each scan result; and

generating and encrypting, using the second computing device, a report with the scan results and the time-series metadata attached to each scan result.

5 . The computer-implemented method of claim 4 , further comprising the steps of:

receiving an encrypted scan report message from the second computing device;

verifying the report's authenticity;

updating a graph with the scan results and the time-series metadata;

storing the graph; and

establishing data structures with data received from one or more network sources.

6 . The computer-implemented method of claim 4 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.

7 . A system for dynamic geospatially-referenced cyber-physical infrastructure inventory and asset management, comprising one or more computers with executable instructions that, when executed, cause the system to:

determine a location of an asset;

generate an encrypted message comprising an identifier of a first computing device and the location of the asset; and

transmit the encrypted message to a second computing device;

receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieve rules associated with the triggering event;

perform one or more port scans of the first computing device based on the retrieved rules;

produce scan results of the port scans;

attach time-series metadata to each scan result; and

generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.

8 . The system of claim 7 , wherein the executable instructions further cause the system to:

receive an encrypted scan report message from the second computing device;

verify the report's authenticity;

update a graph with the scan results and the time-series metadata;

store the graph;

establish data structures with data received from one or more network sources.

9 . The system of claim 7 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.

10 . Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system employing asset management for dynamic geospatially-referenced cyber-physical infrastructure inventory, cause the computing system to:

determine a location of an asset;

generate an encrypted message comprising an identifier of a first computing device and the location of the asset location;

transmit the encrypted message to a second computing device;

receive a triggering event from the first computing device, wherein the triggering event comprises the encrypted message from the first computing device;

attach metadata to the triggering event, wherein the metadata comprises a time at which the triggering event occurred;

retrieve rules associated with the triggering event;

perform one or more port scans of the first computing device based on the retrieved rules;

produce scan results of the port scans;

attach time-series metadata to each scan result; and

generate and encrypt a report with the scan results and the time-series metadata attached to each scan result.

11 . The non-transitory, computer-readable storage media of claim 10 , wherein the computer-executable instructions further cause the computing system to:

receive an encrypted scan report message from the second computing device;

verify the report's authenticity;

update a graph with the scan results and the time-series metadata;

store the graph;

establish data structures with data received from one or more network sources.

12 . The non-transitory, computer-readable storage media of claim 10 , wherein the second computing device periodically rescans the first computing device based on one or more triggers and updates the graph accordingly.