IP Library Granted Patent US 11,722,295
Granted Patent B2
US 11,722,295 · App. 16/864,107 · Granted Aug 8, 2023

Methods, apparatus, and articles of manufacture to securely audit communications

Inventors: Arthur S. Zeigler (Gaston, OR); Eric Wuehler (Beaverton, OR); Jonathan B. King (Hillsboro, OR)
Assignee: Musarubra US LLC
H04L9/0819H04L9/085H04L9/14H04L63/0428H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,295
App. No.
16/864,107
Granted
Aug 8, 2023
Kind
B2
Abstract

Methods, apparatus, systems, and articles of manufacture are disclosed to securely audit communications. An example apparatus includes a participant list generator to, responsive to a command to provision a secured group of devices in a network to prevent malicious activity, generate a participant device list including one or more endpoint devices and a control plane server; a privilege controller to, based on a policy indicated in the command, set read and write privileges for the one or more endpoint devices and the control plane server; a command controller to, based on the command, determine whether to generate a shared communication key using a shared system key; and a communication processor to encrypt communications between the one or more endpoint devices and the control plane server using the shared communication key.

Claims (56)

1. An apparatus comprising:

a participant list generator to, responsive to a command to add a security device to a secured group of devices in a network to prevent malicious activity, add the security device to a participant device list including one or more endpoint devices and a control plane server to generate an updated participant device list;

a privilege controller to, based on a policy indicated in the command, set read and write privileges for the security device;

a command controller to:

based on the command, determine whether to generate a shared communication key using a shared system key; and

at least one of:

responsive to the command indicating to generate the shared communication key using the shared system key:

transmit the shared system key and the read and write privileges for the security device to the one or more endpoints; and

transmit the updated participant device list and the read and write privileges for the security device to the security device; or

responsive to the command indicating not to generate the shared communication key using the shared system key, transmit the updated participant device list and the read and write privileges for the security device to the one or more endpoint devices and the security device;

a key generator to at least one of:

based on the command indicating not to generate the shared communication key using the shared system key, generate the shared communication key using a private key;

or

based on the command indicating to generate the shared communication key using the shared system key, generate the shared communication key using the shared system key; and

a communication processor to encrypt communications with the one or more endpoint devices with the shared communication key.

2. The apparatus of claim 1 , wherein the key generator is to generate the shared system key via an asynchronous ratchet tree group key calculation when the command indicates not to generate the shared communication key using the shared system key.

3. The apparatus of claim 1 , wherein the command controller is configured to monitor an administrator for the command to add the security device to the secured group of devices in the network to prevent malicious activity.

4. The apparatus of claim 1 , wherein the privilege controller is to, based on the policy, set the read and write privileges for the security device so that the security device can read communications from any of the one or more endpoint devices and the control plane server but cannot send communications to any of the one or more endpoint devices.

5. The apparatus of claim 1 , wherein the security device includes a security information and event management server.

6. The apparatus of claim 1 , wherein the command is to indicate to (a) generate the shared communication key using the shared system key when computational burden of the one or more endpoint devices is to be reduced, and (b) not to generate the shared communication key using the shared system key when security is to be optimized.

7. A non-transitory computer readable storage medium comprising instructions which, when executed, cause one or more processors to at least:

responsive to a command to add a security device to a secured group of devices in a network to prevent malicious activity, add the security device to a participant device list including one or more endpoint devices and a control plane server to generate an updated participant device list;

based on a policy indicated in the command, set read and write privileges for the security device;

based on the command, determine whether to generate a shared communication key using a shared system key;

at least one of:

responsive to the command indicating to generate the shared communication key using the shared system key:

transmit the shared system key and the read and write privileges for the security device to the one or more endpoints; and

transmit the updated participant device list and the read and write privileges for the security device to the security device; or

responsive to the command indicating not to generate the shared communication key using the shared system key, transmit the updated participant device list and the read and write privileges for the security device to the one or more endpoint devices and the security device;

at least one of:

based on the command indicating not to generate the shared communication key using the shared system key, generate the shared communication key using a private key;

or

based on the command indicating to generate the shared communication key using the shared system key, generate the shared communication key using the shared system key; and

encrypt communications with the one or more endpoint devices with the shared communication key.

8. The computer readable storage medium of claim 7 , wherein the instructions cause the one or more processors to at least generate the shared system key via an asynchronous ratchet tree group key calculation when the command indicates not to generate the shared communication key using the shared system key.

9. The computer readable storage medium of claim 7 , wherein the instructions cause the one or more processors to at least monitor an administrator for the command to add the security device to the secured group of devices in the network to prevent malicious activity.

10. The computer readable storage medium of claim 7 , wherein the instructions cause the one or more processors to at least, based on the policy, set the read and write privileges for the security device so that the security device can read communications from any of the one or more endpoint devices and the control plane server but cannot send communications to any of the one or more endpoint devices.

11. The computer readable storage medium of claim 7 , wherein the security device includes a security information and event management server.

12. The computer readable storage medium of claim 7 , wherein the instructions cause the one or more processors to at least indicate to (a) generate the shared communication key using the shared system key when computational burden of the one or more endpoint devices is to be reduced, and (b) not to generate the shared communication key using the shared system key when security is to be optimized.

13. A method comprising:

responsive to a command to add a security device to a secured group of devices in a network to prevent malicious activity, adding the security device to a participant device list including one or more endpoint devices and a control plane server to generate an updated participant device list;

based on a policy indicated in the command, setting read and write privileges for the security device;

based on the command, determining whether to generate a shared communication key using a shared system key;

at least one of:

responsive to the command indicating to generate the shared communication key using the shared system key:

transmitting the shared system key and the read and write privileges for the security device to the one or more endpoints; and

transmitting the updated participant device list and the read and write privileges for the security device to the security device; or

responsive to the command indicating not to generate the shared communication key using the shared system key, transmitting the updated participant device list and the read and write privileges for the security device to the one or more endpoint devices and the security device;

at least one of:

based on the command indicating not to generate the shared communication key using the shared system key, generating the shared communication key using a private key; or

based on the command indicating to generate the shared communication key using the shared system key, generating the shared communication key using the shared system key; and

encrypting communications with the one or more endpoint devices with the shared communication key.

14. The method of claim 13 , wherein the generating of the shared system key includes generating the shared system key via an asynchronous ratchet tree group key calculation when the command indicates not to generate the shared communication key using the shared system key.

15. The method of claim 13 , further including monitoring an administrator for the command to add the security device to the secured group of devices in the network to prevent malicious activity.

16. The method of claim 13 , further including, based on the policy, setting the read and write privileges for the security device so that the security device can read communications from any of the one or more endpoint devices and the control plane server but cannot send communications to any of the one or more endpoint devices.

17. The method of claim 13 , wherein the security device includes a security information and event management server.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 057393/0546 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2020
From: ZEIGLER, ARTHUR S.; WUEHLER, ERIC; KING, JONATHAN B.
To: MCAFEE, LLC
Reel/Frame 053450/0325 →
Continuity (1)
Related Publication 20210344483A1 · Nov 4, 2021