IP Library Patent Application 16509618
Patent Application
App. No. 16/509,618

DYNAMIC ENDPOINT ISOLATION IN A CRYPTOGRAPHICALLY-SEGMENTED NETWORK

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/509,618
Abstract

In a cryptographically-segmented network, a server establishes a cryptographically-segmented communication channel for use by authorized endpoints in an operationally-deployed configuration. In response to a received endpoint-isolation command to isolate a first endpoint, the server de-authorizes the first endpoint from the channel of the operationally-deployed configuration. In response to the de-authorization, the server issues a configuration instruction to the first endpoint to join a first cryptographically-segmented isolation communication channel that is communicatively coupled with at least one monitoring endpoint configured to monitor operation of the first endpoint via the first cryptographically-segmented isolation communication channel.

Claims (45)

1 . A server for use in a cryptographically-segmented network, the server comprising:

computing hardware including at least one processor and memory circuitry, the memory circuitry comprising instructions that, when executed by the server, cause the server to:

establish at least one cryptographically-segmented communication channel for use by authorized endpoints in an operationally-deployed configuration;

in response to a received endpoint-isolation command to isolate a first endpoint, de-authorize the first endpoint from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration; and

in response to the de-authorization of the first endpoint from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration, issue a configuration instruction to the first endpoint to join a first cryptographically-segmented isolation communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration, wherein the first cryptographically-segmented isolation communication channel is communicatively coupled with at least one monitoring endpoint configured to monitor operation of the first endpoint via the first cryptographically-segmented isolation communication channel.

2 . The server of claim 1 , wherein the at least one cryptographically-segmented communication channel of the operationally-deployed configuration and the first cryptographically-segmented isolation communication channel are defined according to respective community-of-interest (COI) configurations.

3 . The server of claim 1 , wherein the endpoint-isolation command is based on an application programming interface (API) call.

4 . The server of claim 1 , wherein the instructions, when executed by the server, cause the server to perform endpoint access-control operations including endpoint authentication operations.

5 . The server of claim 4 , wherein the endpoint authentication operations include endpoint authentication based on machine ID, and endpoint authentication based on user ID.

6 . The server of claim 4 , wherein the endpoint authentication operations are performed via a cryptographically-segmented licensing communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel and from the first cryptographically-segmented isolation communication channel.

7 . The server of claim 1 , wherein the instructions, when executed, cause the computing hardware to further:

receive monitored operational information about the first endpoint from the at least one monitoring endpoint via a cryptographically-segmented communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel and from the first cryptographically-segmented isolation communication channel.

8 . The server of claim 1 , wherein the instructions, when executed, cause the computing hardware to further:

remotely command the at least one monitoring endpoint, via a cryptographically-segmented communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel and from the first cryptographically-segmented isolation communication channel, to probe or reconfigure the first endpoint.

9 . The server of claim 1 , wherein the instructions, when executed, cause the computing hardware to further:

establish a plurality of cryptographically-segmented isolation communication channels, each of which is cryptographically isolated from the at least one cryptographically-segmented communication channel, and from other ones of the plurality of cryptographically-segmented isolation communication channels, wherein the first cryptographically-segmented isolation communication channel is one of the plurality of the cryptographically-segmented isolation communication channels.

10 . The server of claim 9 , wherein the plurality of cryptographically-segmented isolation communication channels include a honeypot communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel, and from the first cryptographically-segmented isolation communication channel, wherein the honeypot communication channel is communicatively coupled to at least one honeypot endpoint and to the first endpoint.

11 . The server of claim 10 , wherein the plurality of cryptographically-segmented isolation communication channels include a honeypot-control communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel, from the first cryptographically-segmented isolation communication channel, and from the from the honeypot communication channel, wherein the honeypot-control communication channel is communicatively coupled to the at least one honeypot endpoint and to the at least one monitoring endpoint.

12 . The server of claim 1 , wherein the instructions, when executed, cause the computing hardware to further:

issue a un-isolation command to de-authorize the first endpoint from the first cryptographically-segmented isolation communication channel; and

in response to the de-authorization of the first endpoint from the first cryptographically-segmented isolation communication channel, issue a configuration instruction to the first endpoint to rejoin the at least one cryptographically-segmented communication channel in the operationally-deployed configuration.

13 . The server of claim 1 , wherein the instructions, when executed, cause the computing hardware to further:

store a data structure representing endpoints to be isolated; and

in response to the received endpoint-isolation command to isolate the first endpoint, update the data structure to include the first endpoint as one of the endpoints to be isolated.

14 . An automated method for operating a cryptographically-segmented network, the method being carried out by a server and comprising:

establishing at least one cryptographically-segmented communication channel for use by authorized endpoints in an operationally-deployed configuration;

in response to a received endpoint-isolation command to isolate a first endpoint, de-authorizing the first endpoint from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration; and

in response to the de-authorizing of the first endpoint from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration, issuing a configuration instruction to the first endpoint to join a first cryptographically-segmented isolation communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration, wherein the first cryptographically-segmented isolation communication channel is communicatively coupled with at least one monitoring endpoint configured to monitor operation of the first endpoint via the first cryptographically-segmented isolation communication channel.

15 . The method of claim 14 , further comprising:

performing endpoint access-control operations including endpoint authentication operations, wherein the endpoint authentication operations include endpoint authentication based on machine ID, and endpoint authentication based on user ID.

16 . The method of claim 14 , further comprising:

receiving monitored operational information about the first endpoint from the at least one monitoring endpoint via a cryptographically-segmented communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel and from the first cryptographically-segmented isolation communication channel.

17 . The method of claim 14 , further comprising:

remotely commanding the at least one monitoring endpoint, via a cryptographically-segmented communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel and from the first cryptographically-segmented isolation communication channel, to probe or reconfigure the first endpoint.

18 . The method of claim 14 , further comprising:

establishing a plurality of cryptographically-segmented isolation communication channels, each of which is cryptographically isolated from the at least one cryptographically-segmented communication channel, and from other ones of the plurality of cryptographically-segmented isolation communication channels, wherein the first cryptographically-segmented isolation communication channel is one of the plurality of the cryptographically-segmented isolation communication channels;

wherein the plurality of cryptographically-segmented isolation communication channels include a honeypot communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel, and from the first cryptographically-segmented isolation communication channel, wherein the honeypot communication channel is communicatively coupled to at least one honeypot endpoint and to the first endpoint; and

wherein the plurality of cryptographically-segmented isolation communication channels include a honeypot-control communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel, from the first cryptographically-segmented isolation communication channel, and from the from the honeypot communication channel, wherein the honeypot-control communication channel is communicatively coupled to the at least one honeypot endpoint and to the at least one monitoring endpoint.

19 . The method of claim 14 , further comprising:

issuing a un-isolation command to de-authorize the first endpoint from the first cryptographically-segmented isolation communication channel; and

in response to the de-authorization of the first endpoint from the first cryptographically-segmented isolation communication channel, issuing a configuration instruction to the first endpoint to rejoin the at least one cryptographically-segmented communication channel in the operationally-deployed configuration.

20 . A at least one non-transitory machine-readable storage medium containing instructions that, when executed by the a server of a network, cause the server to:

establish at least one cryptographically-segmented communication channel for use by authorized endpoints in an operationally-deployed configuration;

in response to a received endpoint-isolation command to isolate a first endpoint, de-authorize the first endpoint from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration; and

in response to the de-authorization of the first endpoint from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration, issue a configuration instruction to the first endpoint to join a first cryptographically-segmented isolation communication channel that is cryptographically isolated from the at least one cryptographically-segmented communication channel in the operationally-deployed configuration, wherein the first cryptographically-segmented isolation communication channel is communicatively coupled with at least one monitoring endpoint configured to monitor operation of the first endpoint via the first cryptographically-segmented isolation communication channel.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2020
From: SANDERSON, ANDREW F; FRENCH, ALBERT L; INFORZATO, SARAH K; KEIPER, LEMOINE D
To: UNISYS CORPORATION
Reel/Frame 051919/0670 →
SECURITY INTEREST Recorded Jan 31, 2020
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 051682/0760 →
SECURITY INTEREST Recorded Nov 21, 2019
From: UNISYS CORPORATION
To: WELLS FARGO NATIONAL ASSOCIATION
Reel/Frame 051075/0721 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2019
From: SANDERSON, ANDREW F; FRENCH, ALBERT L; INFORZATO, SARAH K; KEIPER, LEMOINE D, III
To: UNISYS CORPORATION
Reel/Frame 050427/0422 →