IP Library Granted Patent US 10,374,803
Granted Patent B2
US 10,374,803 · App. 16/153,409 · Granted Aug 6, 2019

Methods for internet communication security

Inventors: Mike Clark (Sterling, VA); Andrew Gordon (Alexandria, VA); Matt Clark (Sterling, VA)
Assignee: Stealthpath, Inc.
H04L9/3226G06F9/45558H04L45/745H04L63/0227H04L63/0428H04L63/0876H04L63/105H04L63/205H04L69/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,374,803
App. No.
16/153,409
Granted
Aug 6, 2019
Kind
B2
Abstract

The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.

Claims (42)

1. A product for authorizing network communications in a hypervisor, the product comprising a non-transitory computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code executable in a hypervisor to perform communication management operations, the communication management operations comprising:

i) intercepting a first network packet in the hypervisor, the first network packet comprising a first higher-than-OSI layer three portion;

ii) decrypting, with a single-use cryptographic key, at least a portion of the first higher-than-OSI layer three portion to obtain one or more first packet parameters;

iii) authorizing the first network packet in the hypervisor, comprising: comparing the one or more first packet parameters with one or more first expected values; and

iv) passing the authorized first network packet to a virtual device.

2. The product of claim 1 , wherein the communication management operations further comprise:

i) detecting negotiation of a secure communication pathway between a first remote node and the virtual device, the negotiation comprising a series of network packet communications between the first remote node and the virtual device;

ii) aligning a series of cryptographic keys utilized in the hypervisor with a series of cryptographic keys utilized in the virtual device;

iii) monitoring the series of network packet communications; and

iv) confirming success of the negotiation prior to the passing the authorized first network packet.

3. The product of claim 2 , wherein the monitoring comprises:

a) detecting a nonpublic first identification code sent from the virtual device to a software port on the first remote node via a pre-established communication pathway; followed by

b) further detecting a nonpublic second identification code sent from the remote node; and

c) comparing the nonpublic second identification code with a pre-established value for the first remote node.

4. The product of claim 3 , wherein the communication management operations comprise: determining the pre-established value for the first remote node from a software port number assigned to the software port.

5. The product of claim 3 , wherein the monitoring comprises:

a) detecting a first application identification code for a first user-application sent from the virtual device to the first remote node via the pre-established communication pathway; followed by

b) detecting a second application identification code for a second user-application sent from the first remote node; and

c) comparing the second application identification code with a pre-established value for the second user-application.

6. The product of claim 5 , wherein the communication management operations comprise: determining the pre-established value for the first remote node from the software port number.

7. The product of claim 1 , wherein the communication management operations comprise: determining the one or more first expected values from a one-to-one correspondence with an n-tuple comprising the one or more first expected values, a destination port number of the first network packet, and a destination network address of the first network packet.

8. The product of claim 7 , wherein the one or more first packet parameters comprise a source application identification code, the source application identification code referencing a source application program for the first network packet.

9. The product of claim 8 , wherein the one or more first packet parameters comprise a data model identification code.

10. The product of claim 9 , wherein the communication management operations comprise: confirming at least a portion of a payload of the first network packet conforms to a data range, the data range determined from the data model identification code.

11. The product of claim 9 , wherein the communication management operations comprise: confirming at least a portion of the payload of the first network packet conforms to a command type restriction, the command type restriction determined from the data model identification code.

12. The product of claim 9 , wherein the communication management operations comprise: translating a first payload of the first network packet from a first pre-established format to a second pre-established format, the first pre-established format and the second pre-established format determined from the data model identification code and/or the destination port number.

13. The product of claim 7 , wherein the communication management operations comprise: obtaining the one-to-one correspondence from an encrypted file loaded into memory of the hypervisor.

14. The product of claim 7 , wherein the communication management operations comprise: obtaining the one-to-one correspondence from the virtual device via at least one encrypted communication pathway.

15. The product of claim 1 , wherein the communication management operations further comprise:

i) intercepting a second network packet in the hypervisor, the second network packet ingressed from the virtual device, the second network packet comprising a second higher-than-OSI layer three portion;

ii) decrypting, with a single-use cryptographic key, at least a portion of the second higher-than-OSI layer three portion to obtain at least one packet parameter;

iii) authorizing the second network packet in the hypervisor, comprising: comparing the one or more second packet parameters with one or more second expected values; and

iv) passing the authorized second network packet to a remote second node.

16. The product of claim 1 , wherein the virtual device is a virtual machine.

17. The product of claim 1 , wherein the virtual device is a container.

18. The product of claim 1 , wherein the communication management operations comprise: obtaining the at least one packet parameter from a payload of the first network packet.

19. The product of claim 1 , wherein the first remote node is a bare metal device.

20. The product of claim 1 , wherein the first remote node is a further virtual device.

21. The product of claim 1 , wherein the hypervisor provides at least one virtual interface to the virtual device.

22. The product of claim 1 , wherein the communication management operations are configured for a Type 1 hypervisor.

23. The product of claim 1 , wherein the communication management operations are configured for a Type 2 hypervisor.

24. The product of claim 1 , wherein the communication management operations are transparent to the virtual device and all computer programs running on the virtual device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2025
From: STEALTHPATH, INC.
To: STEALTHPATH IP INC.
Reel/Frame 073141/0609 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2018
From: CLARK, MIKE; GORDON, ANDREW; CLARK, MATT
To: STEALTHPATH, INC.
Reel/Frame 047085/0534 →
Continuity (7)
Continuation In Part 15949749 · Apr 10, 2018
Provisional Application 62731529 · Sep 14, 2018
Provisional Application 62655633 · Apr 10, 2018
Provisional Application 62609252 · Dec 21, 2017
Provisional Application 62609152 · Dec 21, 2017
Provisional Application 62569300 · Oct 6, 2017
Related Publication 20190109714A1 · Apr 11, 2019