IP Library Granted Patent US 11,444,981
Granted Patent B1
US 11,444,981 · App. 16/874,767 · Granted Sep 13, 2022

Zero network-profile cryptographically secure network port access

Inventors: Christopher Edward Delaney (Front Royal, VA); Chava Louis Jurado (Leesburg, VA); Carl Bailey Jacobs (Fredericksburg, VA)
Assignee: Cyber IP Holdings, LLC
H04L63/20H04L9/0643H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,444,981
App. No.
16/874,767
Granted
Sep 13, 2022
Kind
B1
Abstract

Systems and methods for protecting access to network ports on a server are provided herein. A system comprises a server configured to receive a data packet comprising a cryptoken corresponding to a network port address. The server is further configured to generate a plurality of cryptokens based on a plurality of timecodes, a network port configuration, and the destination address. The server generates a plurality of hashes based on the plurality of cryptokens. The server generates, based on a comparison of each of the plurality of cryptokens to the cryptoken, a rule to allow inbound connections to a first network port corresponding to the network port address.

Claims (41)

1. A system for protecting access to network ports on a server, the system comprising:

a server configured to:

receive, from a client, a data packet comprising a cryptoken corresponding to a network port address;

generate, by each of a plurality of running instances of a service to protect virtual network ports, a plurality of seed strings based on a plurality of timecodes, a network port configuration, and the destination address;

generate, by each of the running instances of the service to protect virtual network ports, a plurality of cryptokens by hashing the corresponding plurality of seed strings;

compare, by each of the running instances of the service to protect virtual network ports, the corresponding generated plurality of cryptokens to the cryptoken in the data packet to identify a match corresponding to a matching instance; and

generate, by the matching instance, a rule to allow inbound connections to a first network port for the matching instance corresponding to the network port address.

2. The system of claim 1 , wherein the plurality of timecodes are based on a system time and a timing interval that accounts for discrepancies between the server and the client.

3. The system of claim 1 , wherein the network port configuration further comprises a port number, a shared secret, and a predetermined period of time.

4. The system of claim 1 , wherein the network port configuration further comprises a protocol, wherein a number of the plurality of generated cryptokens is based on the protocol.

5. The system of claim 1 , wherein the server is further configured to:

receive the data packet at a second network port that is different from the first network port, wherein the first network port is not directly accessible by the client.

6. The system of claim 1 , further comprising:

the client, the client being configured to generate the received cryptoken and the packet based on the received cryptoken and send the data packet to the server.

7. The system of claim 5 , wherein the server is further configured to route traffic.

8. The system of claim 3 , wherein the rule is further based on the shared secret and the predetermined period of time.

9. A method for protecting access to network ports on a server, the method comprising:

receiving, by the server from a client, a data packet comprising a cryptoken corresponding to a network port address;

generating, by each of a plurality of running instances of a service executed by the server to protect virtual network ports, a plurality of seed strings based on a plurality of timecodes, a network port configuration, and the destination address;

generating, by each of a plurality of running instances of a service executed by the server to protect virtual network ports, a plurality of cryptokens by hashing the plurality of seed strings;

comparing, by each of the running instances of the service executed by the server to protect virtual network ports, the corresponding generated plurality of cryptokens to the cryptoken in the data packet to identify a match corresponding to a matching instance; and

generating, by the matching instance, a rule to allow inbound connections to a first network port for the matching instance corresponding to the network port address.

10. The method of claim 9 , wherein the plurality of timecodes are based on a system time and a timing interval that accounts for discrepancies between the server and the client.

11. The method of claim 9 , wherein the network port configuration further comprises a port number, a shared secret, and a predetermined period of time.

12. The method of claim 9 , wherein the network port configuration further comprises a protocol, wherein a number of the plurality of generated cryptokens is based on the protocol.

13. The method of claim 9 , further comprising:

receiving, by the server, the data packet at a second network port that is different from the first network port, wherein the first network port is not directly accessible by the client.

14. The method of claim 9 , further comprising:

generating, by the client, the received cryptoken and the packet based on the received cryptoken; and

sending the data packet to the server.

15. The method of claim 13 , further comprising routing, by the server, traffic.

16. The method of claim 11 , wherein the rule is further based on the shared secret and the predetermined period of time.

17. A non-transitory computer readable storage medium storing one or more programs configured to be executed by one or more data processors, the one or more programs comprising instructions protecting access to network ports on a server, the instructions comprising:

receiving, by a server from a client, a data packet comprising a cryptoken corresponding to a network port address;

generating, by each of a plurality of running instances of a service executed by the server to protect virtual network ports, a plurality of seed strings based on a plurality of timecodes, a network port configuration, and the destination address;

generating, by each of the running instances of the service executed by the server to protect virtual network ports, a plurality of cryptokens by hashing the corresponding plurality of seed strings;

comparing, by each of the running instances of the service executed by the server to protect virtual network ports, the corresponding generated plurality of cryptokens to the cryptoken in the data packet to identify a match corresponding to a matching instance; and

generating, by the matching instance, a rule to allow inbound connections to a first network port for the matching instance corresponding to the network port address.

18. The non-transitory computer readable storage medium of claim 17 , wherein the plurality of timecodes are based on a system time and a timing interval that accounts for discrepancies between the server and the client.

19. The non-transitory computer readable storage medium of claim 17 , wherein the network port configuration further comprises a port number, a shared secret, and a predetermined period of time.

20. The non-transitory computer readable storage medium of claim 17 , wherein the network port configuration further comprises a protocol, wherein a number of the plurality of generated cryptokens is based on the protocol.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2022
From: BERRYVILLE HOLDINGS, LLC
To: CYBER IP HOLDINGS, LLC
Reel/Frame 059797/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2020
From: DELANEY, CHRISTOPHER EDWARD; JURADO, CHAVA LOUIS; JACOBS, CARL BAILEY
To: BERRYVILLE HOLDINGS, LLC
Reel/Frame 052670/0133 →
Continuity (1)
Provisional Application 62857527 · Jun 5, 2019
Cited By (1)
US 12,407,725