IP Library › Granted Patent US 12,301,729
Granted Patent B2
US 12,301,729 · App. 17/183,825 · Granted May 13, 2025

Centralized consent vendors for managing network-based consent contracts

Inventors: Kyle Andrew Donald Mestery (Woodbury, MN); Ian James Wells (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L9/3263H04L61/4511H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,729
App. No.
17/183,825
Granted
May 13, 2025
Kind
B2
Abstract

Techniques for creating consent contracts for devices that indicate whether the devices consent to receiving network-based communications from other devices. Further, the techniques include enforcing the consent contracts such that network-based communications are either allowed or disallowed in the network-communications layer prior to the network communications reaching the devices. Rather than simply allowing a device to communicate with any other device over a network, the techniques described herein include building in consent for network-based communications where the consent is consulted at one or more points in a communication process to make informed decisions about network-based traffic.

Claims (55)

1. A method for managing consent contracts for network communications, the method comprising:

receiving, by a Domain Name System (DNS) provider and from a plurality of receiving devices, consent data comprising conditions associated with receiving the network communications from one or more sending devices;

in response to receiving the consent data, generating, by the DNS provider, the consent contracts for the plurality of receiving devices, wherein the consent contract indicates that a receiving device of the plurality of receiving devices has consented to receiving the network communications from one or more particular sending devices and is valid for a period of time;

storing, by DNS provider, the consent contracts;

receiving, from a first device, a DNS request at a DNS server of the DNS provider, the DNS request indicating a request to translate a domain name into an Internet Protocol (IP) address associated with a second device;

determining, at the DNS server, that a particular consent contract indicates that the second device has consented to receiving the network communications from the first device, the particular consent contract limiting the network communications to a particular communication type or a particular purpose associated with the network communication;

in response to determining that the particular consent contract is valid and indicates that the second device has consented to receiving the network communications of the particular communication type or the particular purpose from the first device:

determining, at the DNS server, that the IP address corresponds to the domain name; and

sending, from the DNS server, a DNS response to the first device that includes the IP address; or

in response to determining that the particular consent contract is invalid or indicates that the second device has not consented to receiving the network communications of the particular type or the particular purpose from the first device:

refraining, by the DNS server, from sending the IP address to the first device; or

sending, from the DNS server, a response to the first device indicating a rejection of the DNS request.

2. The method of claim 1 , further comprising:

receiving, from the first device, first data indicating a set of permissions granted to the first device; and

determining that the second device has provided second data indicating consent to receive the network communications from devices with the set of permissions.

3. The method of claim 1 , wherein the consent data further comprises one or more of:

a first range of addresses associated with the sending devices with which the second device has consented to communicating;

a second range of addresses associated with the sending devices with which the second device has restricted from communicating;

a first indication that that the second device consents to communicate with the sending devices that desire to send the network communications of the particular communication type; or

a second indication that that the second device consents to communicate with the sending devices that desire to establish a connection of a particular connection type.

4. The method of claim 1 , further comprising:

receiving the consent data indicating that the second device has consented to receiving the type of network communication comprising layer-3 or layer-4 traffic from the first device; and

generating the particular consent contract to allow the network communications where the network communications are the layer-3 or the layer-4 traffic from the first device.

5. The method of claim 1 , wherein:

the particular consent contract includes a mapping between a first device identifier associated with the first device and a second device identifier associated with the second device; and

determining that the particular consent contract indicates that the second device has consented to receiving the network communications from the first device includes:

determining that the DNS request includes the first device identifier;

using the first device identifier, identifying the mapping; and

determining, using the mapping, that the first device identifier is mapped to the second device identifier.

6. The method of claim 1 , further comprising:

receiving consent data indicating that the second device has consented to receiving the type of network communication comprising layer-5, layer-6, or layer-7 traffic from the first device; and

generating the particular consent contract using the consent data.

7. A certificate authority (CA) system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

issuing a signed certificate to a server;

receiving consent data associated with the server, the consent data comprising conditions associated with the server receiving network communications;

in response to receiving the consent data, generating consent contracts for the server, wherein the consent contracts indicate that the server has agreed to receive the network communications of a particular communication type from one or more particular sending devices;

receiving, from a client device, a request to validate the signed certificate;

determining, by the CA system and using the consent contracts, whether the client device is permitted to send the network communications to the server and whether the network communications are of the particular communication type;

in response to determining that the client device is permitted to send the network communications to the server and that the network communications are of the particular communication type:

validating the signed certificate for the client device; and

notifying the client device that the signed certificate is valid; or

in response to determining that the client device is not permitted to send the network communications to the server:

refraining from validating the signed certificate; or

refraining from notifying the client device that the signed certificate is valid.

8. The CA system of claim 7 , the operations further comprising:

receiving, from the client device, first data indicating a set of permissions granted to the client device; and

determining that the server has provided second data indicating consent to receive receiving the network communications from devices with the set of permissions.

9. The CA system of claim 7 , the consent data further comprising at least one of:

a first range of addresses associated with devices with which the server has consented to communicating;

a second range of addresses associated with devices with which the server has restricted from communicating;

a first indication that that the server consents to communicate with devices that desire to send the network communications of the particular communication type;

a second indication that that the server consents to communicate with devices that desire to establish a connection of a particular connection type; or

a third indication that that the second device consents to communicate with devices that desire to send the network communications for a particular purpose.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2021
From: MESTERY, KYLE ANDREW DONALD; WELLS, IAN JAMES
To: CISCO TECHNOLOGY, INC.
Reel/Frame 055391/0796 →
Continuity (1)
Related Publication 20220271947A1 · Aug 25, 2022
References Cited (79)
US 9027136B2 · Be'Ery et al. · 2015 [cited by applicant]
US 9934544B1 · Whitfield et al. · 2018 [cited by applicant]
US 10153907B2 · Xu et al. · 2018 [cited by applicant]
US 10565666B2 · Veeramachaneni · 2020 [cited by examiner]
US 10644889B1 · Govindaraj et al. · 2020 [cited by applicant]
US 10834141B1 · Chud · 2020 [cited by applicant]
US 20020069278A1 · Forslöw · 2002 [cited by applicant]
US 20020120866A1 · Mitchell · 2002 [cited by examiner]
US 20020188656A1 · Patton et al. · 2002 [cited by applicant]
US 20040088550A1 · Maste · 2004 [cited by examiner]
US 20050132060A1 · Mo et al. · 2005 [cited by applicant]
US 20070038765A1 · Dunn · 2007 [cited by applicant]
US 20080222307A1 · Bhakta · 2008 [cited by examiner]
US 20090147684A1 · Majidi-Ahy · 2009 [cited by examiner]
US 20090172138A1 · Wang · 2009 [cited by examiner]
US 20100217856A1 · Falkena · 2010 [cited by examiner]
US 20110072137A1 · de oca et al. · 2011 [cited by applicant]
US 20120151557A1 · Ahmed et al. · 2012 [cited by applicant]
US 20120185578A1 · Perkuhn et al. · 2012 [cited by applicant]
US 20120331530A1 · Chickering et al. · 2012 [cited by applicant]
US 20130151386A1 · Malaviya · 2013 [cited by examiner]
US 20130174223A1 · Dykeman et al. · 2013 [cited by applicant]
US 20140096207A1 · Gilbert et al. · 2014 [cited by applicant]
US 20140136267A1 · Ristock · 2014 [cited by applicant]
US 20140281503A1 · Mills · 2014 [cited by examiner]
US 20140351368A1 · Dudziak et al. · 2014 [cited by applicant]
US 20150067814A1 · Bu · 2015 [cited by applicant]
US 20150188887A1 · Thomas et al. · 2015 [cited by applicant]
US 20150264040A1 · Schneider · 2015 [cited by examiner]
US 20150304448A1 · Mathew et al. · 2015 [cited by applicant]
US 20160006685A1 · Kitamuya · 2016 [cited by examiner]
US 20160112208A1 · Williams et al. · 2016 [cited by applicant]
US 20160191243A1 · Manning · 2016 [cited by examiner]
US 20160197935A1 · Jamison et al. · 2016 [cited by applicant]
US 20160226859A1 · Sondhi et al. · 2016 [cited by applicant]
US 20160330287A1 · Smith · 2016 [cited by examiner]
US 20170063557A1 · Chalmandrier-Perna · 2017 [cited by examiner]
US 20170063935A1 · Lim · 2017 [cited by applicant]
US 20180007178A1 · Subhraveti · 2018 [cited by applicant]
US 20180013793A1 · Belamaric · 2018 [cited by examiner]
US 20180247385A1 · Whitfield et al. · 2018 [cited by applicant]
US 20190005210A1 · Wiederspohn et al. · 2019 [cited by applicant]
US 20190052994A1 · Dar · 2019 [cited by applicant]
US 20190114630A1 · Torkelson et al. · 2019 [cited by applicant]
US 20190188411A1 · Kroutik · 2019 [cited by applicant]
US 20190297114A1 · Panchalingam · 2019 [cited by examiner]
US 20190349402A1 · Shukla et al. · 2019 [cited by applicant]
US 20190392171A1 · Barday et al. · 2019 [cited by applicant]
US 20200042625A1 · Balaraman et al. · 2020 [cited by applicant]
US 20200059786A1 · Farag · 2020 [cited by examiner]
US 20200228486A1 · Park et al. · 2020 [cited by applicant]
US 20200250295A1 · Padmanabhan · 2020 [cited by applicant]
US 20200280443A1 · Simons · 2020 [cited by applicant]
US 20210044976A1 · Avetisov · 2021 [cited by examiner]
US 20210135865A1 · Joseph · 2021 [cited by applicant]
US 20220027522A1 · Kasheshian · 2022 [cited by examiner]
US 20220210147A1 · Galvin · 2022 [cited by examiner]
US 20220271920A1 · Wells et al. · 2022 [cited by applicant]
US 20220272044A1 · Wells et al. · 2022 [cited by applicant]
US 20220272102A1 · Mestery et al. · 2022 [cited by applicant]
EP 2556646A1 · 2013 [cited by applicant]
JP 202074188A · 2020 [cited by applicant]
WO WO2019153095A1 · 2019 [cited by applicant]
Enck, “TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones”, Jun. 2014, ACM, vol. 32, pp. 1-25 (Year: 2014). [cited by examiner]
Alicherry, et al., “DIPLOMA: Distributed Policy Enforcement Architecture for MANETs”, 2010 Fourth International Conference on Network and System Security, 10 pages. [cited by applicant]
Alicherry, et al., “Misuse Detection in Consent-Based Networks”, Springer-Verlag Berlin Heidelberg 2011, 19 pages. [cited by applicant]
Naous, et al., “Verifying and enforcing network paths with ICING”, ACM CoNEXT 2011, Dec. 6-9, 2011, 14 pages. [cited by applicant]
Rosenberg. et al., “A Framework for Consent-Based Communications in the Session Initiation Protocol (SIP)”, Oct. 2008, 62 pages. [cited by applicant]
Rosenberg, et al., “Requirements for Consent-Based Communications in the Session Initiation Protocol (SIP)”, Apr. 2006, 16 pages. [cited by applicant]
Seehra, et al., “A policy framework for the future Internet”, 2009, 6 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,977, mailed on Aug. 17, 2022, Wells, “Enforcing Consent Contracts to Manage Network Traffic”, 12 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,900, mailed on Apr. 11, 2023, Kyle Mestery, “Creating Network-Based Consent Contracts”, 21 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,977, mailed on Feb. 21, 2023, Wells, “Enforcing Consent Contracts to Manage Network Traffic”, 14 Pages. [cited by applicant]
PCT Search Report and Written Opinion mailed Jun. 7, 2022 for PCT application No. PCT/US2022/017698, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,977, mailed on Sep. 7, 2023, Ian James Wells, “Enforcing Consent Contracts to Manage Network Traffic”, 14 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,900, mailed on Sep. 21, 2023, Kyle Andrew Donald Mestery, “Creating Network-Based Consent Contracts”, 19 pages. [cited by applicant]
PCT International Preliminary Report on Patentability mailed Nov. 30, 2023 for PCT Application No. PCT/US2022/029769, 9 pages. [cited by applicant]
Enck W., et al., “TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones”, Computer Systems, vol. 32, Issue. 2, Article No. 5, Jun. 2014, 29 Pages. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/324,876, dated Feb. 16, 2024, 35 Pages. [cited by applicant]