IP Library Granted Patent US 11,245,529
Granted Patent B2
US 11,245,529 · App. 16/450,262 · Granted Feb 8, 2022

Methods for internet communication security

Inventors: Mike Clark (Sterling, VA); Andrew Gordon (Alexandria, VA); Matt Clark (Sterling, VA)
Assignee: STEALTHPATH, INC.
H04L9/3226G06F9/45558G06F21/53H04L9/0894H04L9/3228H04L45/745H04L63/0227H04L63/0428H04L63/06H04L63/0876H04L63/105H04L63/1441H04L63/205H04L67/2823H04L69/08G06F21/602G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,245,529
App. No.
16/450,262
Granted
Feb 8, 2022
Kind
B2
Abstract

The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.

Claims (28)

1. A method for network packet payload authorization, comprising:

i) receiving a network packet at a hypervisor via a port-to-port communication pathway, the network packet comprising at least one packet parameter;

ii) obtaining at least one higher-than-OSI layer three connection status parameter for the port-to-port communication pathway from a virtual machine;

iii) authorizing the network packet in the hypervisor, comprising: comparing the at least one packet parameter with the at least one higher-than-OSI layer three connection status parameter; and

iv) passing the authorized network packet to a virtual machine.

2. The method of claim 1 , wherein the method comprises further passing, from the virtual machine, an updated connection status parameter for the port-to-port communication pathway to the hypervisor.

3. The method of claim 2 , wherein the further passing follows the passing.

4. The method of claim 1 , wherein the network packet traverses a PNIC prior to the authorizing.

5. The method of claim 4 , wherein the PNIC is controlled by a hypervisor driver.

6. The method of claim 1 , wherein the authorized network packet is passed from the hypervisor to the virtual machine via a VNIC or a passthrough NIC.

7. The method of claim 1 , wherein the at least one connection status parameter comprises a third value and the type of network packet is an open connection data packet.

8. The method of claim 1 , wherein the at least one connection status parameter specifies that the port-to-port communication pathway is closed to network packet traffic.

9. The method of claim 1 , wherein the obtained connection status parameter is added to a list maintained by the hypervisor.

10. The method of claim 9 , wherein the list comprises: (a) virtual machine identification codes, (b) authorized destination port numbers, (c) remote application codes, and (d) connection status parameters.

11. The method of claim 1 , wherein at least a portion of the authorizing is performed by the virtual machine prior to passing the authorized network packet to the virtual machine.

12. A method for network packet payload authorization, comprising:

i) intercepting a network packet in a hypervisor, the network packet comprising a higher-than-OSI layer three packet;

ii) decrypting, with a single-use cryptographic key, at least a portion of the higher-than-OSI layer three packet to obtain at least one packet parameter;

iii) authorizing the network packet in the hypervisor, comprising: comparing the at least one packet parameter with at least one expected value; and

iv) passing the authorized network packet to a virtual machine.

13. The method of claim 12 , wherein the network packet traverses a PNIC prior to the authorizing.

14. The method of claim 13 , wherein the PNIC is controlled by a hypervisor driver.

15. The method of claim 12 , wherein the authorized network packet is passed from the hypervisor to the virtual machine via a VNIC or a passthrough NIC.

16. The method of claim 12 , wherein at least a portion of the authorizing is performed by the virtual machine prior to passing the authorized network packet to the virtual machine.

17. The method of claim 12 , wherein the single-use cryptographic key is rotated for use in decrypting a subsequent network packet.

18. The method of claim 12 , wherein the at least one packet parameter is encrypted.

19. The method of claim 12 , wherein the method comprises further passing, from the virtual machine, an updated connection status parameter for the port-to-port communication pathway to the hypervisor.

20. The method of claim 19 , wherein the further passing follows the passing.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2025
From: STEALTHPATH, INC.
To: STEALTHPATH IP INC.
Reel/Frame 073141/0609 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2020
From: CLARK, MIKE; GORDON, ANDREW; CLARK, MATT
To: STEALTHPATH, INC.
Reel/Frame 051603/0029 →
Continuity (8)
Continuation 16153409 · Oct 5, 2018
Continuation In Part 15949749 · Apr 10, 2018
Provisional Application 62731529 · Sep 14, 2018
Provisional Application 62655633 · Apr 10, 2018
Provisional Application 62609252 · Dec 21, 2017
Provisional Application 62609152 · Dec 21, 2017
Provisional Application 62569300 · Oct 6, 2017
Related Publication 20200145217A1 · May 7, 2020
Cited By (11)
US 12,223,797 US 12,243,389 US 12,249,210 US 12,277,839 US 12,322,243 US 12,340,656 US 12,361,783 US 12,437,608 US 12,469,362 US 12,475,763 US 12,494,109