IP Library Granted Patent US 10,476,851
Granted Patent B1
US 10,476,851 · App. 15/967,474 · Granted Nov 12, 2019

Unbounded sessions for secure communications

Inventors: William Joseph Adams (Everett, WA); Luis Gerardo Paris (Maple Valley, WA); Aldo Jose Nunez (Seattle, WA)
Assignee: Centri Technology, Inc.
H04L63/0428G06F21/602G06F21/606H04L63/0435H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,851
App. No.
15/967,474
Granted
Nov 12, 2019
Kind
B1
Abstract

Embodiments are directed towards encoding and transmitting data over a homogeneous network, heterogeneous network or without a network using secure sessions. An application generates a payload that includes information associated with the application and a another application. An encoding engine obtains a session bundle and the payload from the application. A message package that includes an encoded version of the payload such that the payload may be encoded based on the session bundle and the payload. The message package may be provided to the application. The application may select a communication facility to send the message package to the other application. The other application employs its communication facility to receive the message package from the application. The decoding engine may decode the message package based on a second session bundle. The decoding engine may provide the payload of the decoded message package to the other application.

Claims (159)

1. A method for encoding data over one or more networks or communications mechanisms using one or more processors of a network computer that execute instructions to perform the method, comprising:

instantiating a first application to perform actions, including:

generating a payload that includes information associated with the first application and a second application; and

instantiating an encoding engine to perform actions, including:

obtaining a first session bundle and the payload from the first application, wherein the first session bundle corresponds to a secure session;

generating a message package that includes an encoded version of the payload, wherein the payload is encoded based on the first session bundle and the payload; and

providing the message package to the first application; and

selecting one or more of a plurality of communication facilities available to the first application to send the message package to the second application, wherein two or more types of the communication facilities provide different modes of communication over different types of communication media, and wherein the different modes of communication include one or more manual actions that are performed with the message package to manually traverse one or more physical air gaps between two or more networks and to enable the secure session to continue communicating the message package to the second application on the one or more networks; and

instantiating the second application to perform actions, including:

employing one or more of the plurality of communication facilities that are available to the second application to receive the message package from the first application; and

instantiating a decoding engine to perform actions, including:

decoding the message package based on a second session bundle that is associated with the secure session, wherein state information associated with the secure session is discarded; and

providing the payload of the decoded message package without the state information for the secure session to the second application.

2. The method of claim 1 , wherein the first application performs further actions, including:

providing one or more session parameters to the encoding engine;

obtaining a handshake package from the encoding engine, wherein the handshake package is based on one or more session parameters;

selecting the one or more communication facility from the plurality of communication facilities; and

employing the one or more communication facility to send the handshake package to the second application.

3. The method of claim 1 , wherein the second application performs further actions, including:

obtaining a handshake package from the first application;

providing the handshake package to the decoding engine;

receiving a response handshake package and the second session bundle from the decoding engine, wherein the response handshake package and the second session bundle are based on the handshake package and one or more session parameters;

selecting the one or more communication facilities available to the second application from the plurality of communication facilities; and

employing the one or more communication facilities available to the second application to send the response handshake package to the first application.

4. The method of claim 1 , wherein the first application performs further actions, including:

obtaining a response handshake package from the second application;

providing the response handshake package to the encoding engine; and

receiving the first session bundle from the encoding engine, wherein the first session bundle is based on the response handshake package and one or more session parameters.

5. The method of claim 1 , wherein the second application performs further actions, including:

providing one or more second session parameters;

obtaining one or more first session parameters from the decoding engine based on a handshake package provided by the first application;

comparing the one or more first session parameters to the one or more second session parameters; and

accepting the handshake package based on an affirmative result of the comparison.

6. The method of claim 1 , wherein the decoding engine performs further actions, including:

comparing the message package with the second session bundle; and

rejecting the message package based on a negative result of the comparison, wherein the payload is discarded and the secure session is terminated.

7. The method of claim 1 , wherein receiving the message package from the first application, further comprises, introducing one or more of a delay, a communication interruption, or a network interruption before receiving the message package, wherein the delay, communication interruption, or the network interruption is of an unbounded duration.

8. The method of claim 1 , wherein receiving the message package from the first application, further comprises, selecting a communication facility that is different from the one or more communication facilities employed to establish the secure session or communicate other message packages between the first application and the second application.

9. A processor readable non-transitory storage media that includes instructions for encoding data over one or more networks or communications mechanisms using one or more computers, wherein execution of the instructions by the one or more network computers perform the method comprising:

instantiating a first application to perform actions, including:

generating a payload that includes information associated with the first application and a second application; and

instantiating an encoding engine to perform actions, including:

obtaining a first session bundle and the payload from the first application, wherein the first session bundle corresponds to a secure session;

generating a message package that includes an encoded version of the payload, wherein the payload is encoded based on the first session bundle and the payload; and

providing the message package to the first application; and

selecting one or more of a plurality of communication facilities available to the first application to send the message package to the second application, wherein two or more types of the communication facilities provide different modes of communication over different types of communication media, and wherein the different modes of communication include one or more manual actions that are performed with the message package to manually traverse one or more physical air gaps between two or more networks and to enable the secure session to continue communicating the message package to the second application on the one or more networks; and

instantiating the second application to perform actions, including:

employing one or more of the plurality of communication facilities that are available to the second application to receive the message package from the first application; and

instantiating a decoding engine to perform actions, including:

decoding the message package based on a second session bundle that is associated with the secure session, wherein state information associated with the secure session is discarded; and

providing the payload of the decoded message package without the state information for the secure session to the second application.

10. The media of claim 9 , wherein the first application performs further actions, including:

providing one or more session parameters to the encoding engine;

obtaining a handshake package from the encoding engine, wherein the handshake package is based on one or more session parameters;

selecting the one or more communication facility from the plurality of communication facilities; and

employing the one or more communication facility to send the handshake package to the second application.

11. The media of claim 9 , wherein the second application performs further actions, including:

obtaining a handshake package from the first application;

providing the handshake package to the decoding engine;

receiving a response handshake package and the second session bundle from the decoding engine, wherein the response handshake package and the second session bundle are based on the handshake package and one or more session parameters;

selecting the one or more communication facilities available to the second application from the plurality of communication facilities; and

employing the one or more communication facilities available to the second application to send the response handshake package to the first application.

12. The media of claim 9 , wherein the first application performs further actions, including:

obtaining a response handshake package from the second application;

providing the response handshake package to the encoding engine; and

receiving the first session bundle from the encoding engine, wherein the first session bundle is based on the response handshake package and one or more session parameters.

13. The media of claim 9 , wherein the second application performs further actions, including:

providing one or more second session parameters;

obtaining one or more first session parameters from the decoding engine based on a handshake package provided by the first application;

comparing the one or more first session parameters to the one or more second session parameters; and

accepting the handshake package based on an affirmative result of the comparison.

14. The media of claim 9 , wherein the decoding engine performs further actions, including:

comparing the message package with the second session bundle; and

rejecting the message package based on a negative result of the comparison, wherein the payload is discarded and the secure session is terminated.

15. The media of claim 9 , wherein receiving the message package from the first application, further comprises, introducing one or more of a delay, a communication interruption, or a network interruption before receiving the message package, wherein the delay, communication interruption, or the network interruption is of an unbounded duration.

16. The media of claim 9 , wherein receiving the message package from the first application, further comprises, selecting a communication facility that is different from the one or more communication facilities employed to establish the secure session or communicate other message packages between the first application and the second application.

17. A system for encoding data, comprising:

one or more network computers, comprising:

a transceiver that communicates over one or more networks;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a first application to perform actions, including:

generating a payload that includes information associated with the first application and a second application; and

instantiating an encoding engine to perform actions, including:

 obtaining a first session bundle and the payload from the first application, wherein the first session bundle corresponds to a secure session;

 generating a message package that includes an encoded version of the payload, wherein the payload is encoded based on the first session bundle and the payload; and

 providing the message package to the first application; and

selecting one or more of a plurality of communication facilities available to the first application to send the message package to the second application, wherein two or more types of the communication facilities provide different modes of communication over different types of communication media, and wherein the different modes of communication include one or more manual actions that are performed with the message package to manually traverse one or more physical air gaps between two or more networks and to enable the secure session to continue communicating the message package to the second application on the one or more networks; and one or more client computers, comprising:

a transceiver that communicates over the one or more networks;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating the second application to perform actions, including:

 employing one or more of the plurality of communication facilities that are available to the second application to receive the message package from the first application; and

 instantiating a decoding engine to perform actions, including:

 decoding the message package based on a second session bundle that is associated with the secure session, wherein state information associated with the secure session is discarded; and

 providing the payload of the decoded message package without the state information for the secure session to the second application.

18. The system of claim 17 , wherein the first application performs further actions, including:

providing one or more session parameters to the encoding engine;

obtaining a handshake package from the encoding engine, wherein the handshake package is based on one or more session parameters;

selecting the one or more communication facility from the plurality of communication facilities; and

employing the one or more communication facility to send the handshake package to the second application.

19. The system of claim 17 , wherein the second application performs further actions, including:

obtaining a handshake package from the first application;

providing the handshake package to the decoding engine;

receiving a response handshake package and the second session bundle from the decoding engine, wherein the response handshake package and the second session bundle are based on the handshake package and one or more session parameters;

selecting the one or more communication facilities available to the second application from the plurality of communication facilities; and

employing the one or more communication facilities available to the second application to send the response handshake package to the first application.

20. The system of claim 17 , wherein the first application performs further actions, including:

obtaining a response handshake package from the second application;

providing the response handshake package to the encoding engine; and

receiving the first session bundle from the encoding engine, wherein the first session bundle is based on the response handshake package and one or more session parameters.

21. The system of claim 17 , wherein the second application performs further actions, including:

providing one or more second session parameters;

obtaining one or more first session parameters from the decoding engine based on a handshake package provided by the first application;

comparing the one or more first session parameters to the one or more second session parameters; and

accepting the handshake package based on an affirmative result of the comparison.

22. The system of claim 17 , wherein the decoding engine performs further actions, including:

comparing the message package with the second session bundle; and

rejecting the message package based on a negative result of the comparison, wherein the payload is discarded and the secure session is terminated.

23. The system of claim 17 , wherein receiving the message package from the first application, further comprises, introducing one or more of a delay, a communication interruption, or a network interruption before receiving the message package, wherein the delay, communication interruption, or the network interruption is of an unbounded duration.

24. A network computer for encoding data, comprising:

a transceiver that communicates over a network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a first application to perform actions, including:

generating a payload that includes information associated with the first application and a second application; and

instantiating an encoding engine to perform actions, including:

obtaining a first session bundle and the payload from the first application, wherein the first session bundle corresponds to a secure session;

generating a message package that includes an encoded version of the payload, wherein the payload is encoded based on the first session bundle and the payload; and

providing the message package to the first application; and

selecting one or more of a plurality of communication facilities available to the first application to send the message package to the second application, wherein two or more types of the communication facilities provide different modes of communication over different types of communication media, and wherein the different modes of communication include one or more manual actions that are performed with the message package to manually traverse one or more physical air gaps between two or more networks and to enable the secure session to continue communicating the message package to the second application on the one or more networks; and instantiating the second application to perform actions, including:

employing one or more of the plurality of communication facilities that are available to the second application to receive the message package from the first application; and

instantiating a decoding engine to perform actions, including:

decoding the message package based on a second session bundle that is associated with the secure session, wherein state information associated with the secure session is discarded; and

providing the payload of the decoded message package without the state information for the secure session to the second application.

25. The network computer of claim 24 , wherein the first application performs further actions, including:

providing one or more session parameters to the encoding engine;

obtaining a handshake package from the encoding engine, wherein the handshake package is based on one or more session parameters;

selecting the one or more communication facility from the plurality of communication facilities; and

employing the one or more communication facility to send the handshake package to the second application.

26. The network computer of claim 24 , wherein the second application performs further actions, including:

obtaining a handshake package from the first application;

providing the handshake package to the decoding engine;

receiving a response handshake package and the second session bundle from the decoding engine, wherein the response handshake package and the second session bundle are based on the handshake package and one or more session parameters;

selecting the one or more communication facilities available to the second application from the plurality of communication facilities; and

employing the one or more communication facilities available to the second application to send the response handshake package to the first application.

27. The network computer of claim 24 , wherein the first application performs further actions, including:

obtaining a response handshake package from the second application;

providing the response handshake package to the encoding engine; and

receiving the first session bundle from the encoding engine, wherein the first session bundle is based on the response handshake package and one or more session parameters.

28. The network computer of claim 24 , wherein the second application performs further actions, including:

providing one or more second session parameters;

obtaining one or more first session parameters from the decoding engine based on a handshake package provided by the first application;

comparing the one or more first session parameters to the one or more second session parameters; and

accepting the handshake package based on an affirmative result of the comparison.

29. The network computer of claim 24 , wherein the decoding engine performs further actions, including:

comparing the message package with the second session bundle; and

rejecting the message package based on a negative result of the comparison, wherein the payload is discarded and the secure session is terminated.

30. The network computer of claim 24 , wherein receiving the message package from the first application, further comprises, selecting a communication facility that is different from the one or more communication facilities employed to establish the secure session or communicate other message packages between the first application and the second application.

Assignments (2)
SECURITY INTEREST Recorded Feb 20, 2020
From: CENTRI TECHNOLOGY, INC.
To: PERKINS COIE LLP
Reel/Frame 051870/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2018
From: ADAMS, WILLIAM JOSEPH; PARIS, LUIS GERARDO; NUNEZ, ALDO JOSE
To: CENTRI TECHNOLOGY, INC.
Reel/Frame 045674/0336 →
Cited By (1)
US 12,309,858