IP Library Granted Patent US 10,673,852
Granted Patent B2
US 10,673,852 · App. 14/581,333 · Granted Jun 2, 2020

Self-organizing trusted networks

Inventors: Ned M. Smith (Beaverton, OR); Venkata Ramanan Sambandam (Sunnyvale, CA)
Assignee: McAfee, LLC
H04L63/10H04L63/0272H04L63/045H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,852
App. No.
14/581,333
Granted
Jun 2, 2020
Kind
B2
Abstract

Organizing a trusted network includes receive, by a local device, a message from a first remote trusted device identifying a first service hosted by the first remote trusted device, wherein the local device and the first remote trusted device are in a trusted network. Organizing a trusted network also includes indexing, by the local device, the first service in a registry comprising services available to the local device and a location of each service available, wherein the registry is local to the local device.

Claims (78)

1. A storage device or storage disk comprising instructions that, when executed by one or more processors, cause the one or more processors to at least:

during basic discovery, provide information from a local device to a first remote trusted device, the information to indicate the local device supports trusted discovery and to establish the local device as a second remote trusted device;

during the trusted discovery, access, by the local device a trusted discovery message received from the first remote trusted device, the trusted discovery message to identify: (a) security credentials for the first remote trusted device, (b) a first service hosted by the first remote trusted device, and (c) a second service hosted by a third remote trusted device;

verify the security credentials for the first remote trusted device; and

in response to verifying the security credentials for the first remote trusted device:

add the first remote trusted device to a trusted network including the local device; and

index, by the local device the first service and the second service in a registry including third services available to the local device and corresponding locations of the services, the registry to be local to the local device, and the third services in the registry to be opaque to devices that are not part of the trusted network.

2. The storage device or storage disk of claim 1 , wherein the instructions, when executed, further cause the one or more processors to:

identify a request on the local device to utilize the first service;

generate a secure channel between the local device and the first remote trusted device; and

access the first service through the secure channel.

3. The storage device or storage disk of claim 1 , wherein the first service is a security service.

4. The storage device or storage disk of claim 1 , wherein the instructions, when executed, further cause the one or more processors to:

send a response to the first remote trusted device identifying the third services available to the local device, the first remote trusted device to index the third services available to the local device in a second registry local to the first remote trusted device.

5. The storage device or storage disk of claim 1 , wherein the instructions, when executed, further cause the one or more processors to:

access, by the local device, a leave message received from the first remote trusted device; and

in response to the leave message, remove the first service from the registry.

6. The storage device or storage disk of claim 1 , wherein at least one of the third services available to the local device is hosted on a fourth remote trusted device.

7. The storage device or storage disk of claim 1 , wherein the trusted network is a network enclave in a larger network, and a network device that is not in the trusted network is to be prevented from accessing the third services.

8. A storage device or storage disk comprising instructions that, when executed by one or more processors, cause the one or more processors to at least:

during basic discovery, identify, by a local device, a first remote trusted device that supports trusted discovery;

during the trusted discovery, send a trusted discovery message from the local device to the first remote trusted device, the trusted discovery message to identify: (a) security credentials for the local device, (b) a first service hosted by the local device, and (c) a second service hosted by a second remote trusted device;

access an acceptance message received from the first remote trusted device, the acceptance message to indicate an acceptance of the local device to a trusted network including the first remote trusted device, and the acceptance message to include data identifying a third service hosted on the first remote trusted device; and

index, by the local device, the third service in a registry including fourth services available to the local device and corresponding locations of the fourth services, the registry to be local to the local device, and the fourth services in the registry to be opaque to devices that are not part of the trusted network.

9. The storage device or storage disk of claim 8 , wherein the instructions, when executed, further cause the one or more processors to:

send, by the local device, a response to the first remote trusted device identifying the fourth services available to the local device, the first remote trusted device to index the fourth services in a second registry local to the first remote trusted device.

10. The storage device or storage disk of claim 9 , wherein at least one of the fourth services available to the local device is hosted on a third remote trusted device.

11. The storage device or storage disk of claim 10 , wherein the instructions, when executed, further cause the one or more processors to:

identify a request on the local device to utilize the at least one of the fourth services;

generate a secure channel between the local device and the third remote trusted device; and

provide access to the at least one of the fourth services through the secure channel.

12. The storage device or storage disk of claim 8 , wherein the instructions, when executed, further cause the one or more processors to:

identify a request on the local device to utilize the first service;

generate a secure channel between the local device and the first remote trusted device; and

provide access to the first service through the secure channel.

13. The storage device or storage disk of claim 8 , wherein the instructions, when executed, further cause the one or more processors to:

access, by the local device, a leave message received from the first remote trusted device; and

in response to the leave message, remove the first service from the registry.

14. A method of organizing a trusted network, the method comprising:

during basic discovery, identifying, by a local device, a first remote trusted device that supports trusted discovery;

during the trusted discovery, sending, by the local device, a trusted discovery message to the first remote trusted device, the trusted discovery message to include: (a) security credentials for the local device, (b) a first service hosted by the local device, and (c) a second service hosted by a second remote trusted device;

accessing an acceptance message received from the first remote trusted device, the acceptance message to indicate an acceptance of the local device to a trusted network including the first remote trusted device, and the acceptance message to include data identifying a third service hosted on the first remote trusted device; and

indexing, by the local device, the third service in a registry including fourth services available to the local device and corresponding locations of the fourth services, the registry is local to the local device, and the fourth services in the registry to be opaque to devices that are not part of the trusted network.

15. The method of claim 14 , further including:

sending, by the local device, a response to the first remote trusted device identifying the fourth services available to the local device, the first remote trusted device to index the fourth services in a second registry local to the first remote trusted device.

16. The method of claim 14 , wherein at least one of the fourth services available to the local device is hosted on a third remote trusted device.

17. The method of claim 16 , further including:

identifying a request on the local device to utilize the at least one of the fourth services;

generating a secure channel between the local device and the third remote trusted device; and

providing access to the at least one of the fourth services through the secure channel.

18. The method of claim 14 , further including:

identifying a request on the local device to utilize the first service;

generating a secure channel between the local device and the first remote trusted device; and

providing access to the first service though the secure channel.

19. The method of claim 14 , further including:

accessing, by the local device, a leave message received from the first remote trusted device; and

in response to receiving the leave message, removing the third service from the registry.

20. A computer system to organize a trusted network, the computer system comprising:

one or more hardware processors; and

memory, in circuit with the one or more hardware processors, the memory including instructions which, when executed by the one or more hardware processors, cause the one or more hardware processors to at least:

during basic discovery, identify a first remote trusted device that supports trusted discovery;

during the trusted discovery, send a trusted discovery message to the first remote trusted device, the trusted discovery message to include: (a) security credentials for the computer system, (b) a first service hosted by the computer system, and (c) a second service hosted by a second remote trusted device;

access an acceptance message received from the first remote trusted device, the acceptance message to indicate an acceptance of the computer system to the trusted network, the trusted network including the first remote trusted device, and the acceptance message to include data identifying a third service hosted on the first remote trusted device; and

index the third service in a registry including fourth services available to the computer system and corresponding locations of the fourth services, the registry to be local to the computer system, and the fourth services in the registry to be opaque to devices that are not part of the trusted network.

21. The computer system of claim 20 , wherein the instructions further cause the one or more hardware processors to:

send a response to the first remote trusted device, the response to identify the fourth services available to the computer system, the first remote trusted device to index the fourth services in a second registry local to the first remote trusted device.

22. The computer system of claim 20 , wherein at least one of the fourth services available to the computer system is hosted on a third remote trusted device.

23. The computer system of claim 22 , wherein the instructions further cause the one or more hardware processors to:

identify a request to utilize the at least one of the fourth services;

generate a secure channel between the computer system and the third remote trusted device; and

provide access to the at least one of the fourth services through the secure channel.

24. The computer system of claim 20 , wherein the instructions further case the one or more hardware processors to:

identify a request to utilize the first service;

generate a secure channel between the computer system and the first remote trusted device; and

provide access to the first service through the secure channel.

25. The computer system of claim 20 , wherein the instructions further cause the one or more hardware processors to:

access a leave message received from the first remote trusted device; and

in response to the leave message, remove the third service from the registry.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2015
From: SMITH, NED M.; SAMBANDAM, VENKATA RAMANAN
To: MCAFEE, INC.
Reel/Frame 035619/0687 →