IP Library › Granted Patent US 12,519,631
Granted Patent B2
US 12,519,631 · App. 18/345,819 · Granted Jan 6, 2026

Out of band key exchange

Inventors: John G. Andrews (Cleveland Heights, OH); John P. Keyerleber (Richmond Heights, OH)
H04L9/088H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,631
App. No.
18/345,819
Granted
Jan 6, 2026
Kind
B2
Abstract

Examples of the disclosure provide for a scatter network device. In some examples, the scatter network device includes a non-transitory memory, at least one processor, and a key exchange application stored in the non-transitory memory. When executed by the at least one processor, the key exchange application generates a key exchange request, transmits the key exchange request to a first network endpoint via a first communication band, responsive to transmitting the key exchange request, receives a key exchange response, generates a symmetric encryption key based on the key exchange response, and transmits an authenticated message encrypted via the symmetric encryption key to a second network endpoint via a second communication band.

Claims (45)

1 . A scatter network device, comprising:

a non-transitory memory;

at least one processor; and

a key exchange application stored in the non-transitory memory that, when executed by the at least one processor:

generates a key exchange request;

transmits the key exchange request to a first network endpoint via a first communication band;

responsive to transmitting the key exchange request, receives a key exchange response, wherein the key exchange response includes one or more endpoint validation tokens uniquely identifying the scatter network device;

generates a symmetric encryption key based on the key exchange response; and

transmits an authenticated message encrypted via the symmetric encryption key to a second network endpoint via a second communication band, wherein the first communication band and the second band communication are different communication bands.

2 . The scatter network device of claim 1 , wherein the key exchange request and the key exchange response are asymmetrically encrypted.

3 . The scatter network device of claim 2 , wherein the asymmetric encryption of the key exchange request creates a padded uniform random blob.

4 . The scatter network device of claim 2 , wherein the asymmetric encryption of the key exchange response creates a padded uniform random blob.

5 . The scatter network device of claim 1 , wherein the symmetric encryption of the authenticated message creates a padded uniform random blob, and wherein executing the key exchange application further causes the processor to concatenate the authenticated message with one of the one or more endpoint validation tokens.

6 . The scatter network device of claim 1 , wherein the first communication band is a resource constrained communication protocol.

7 . A method of secure data routing, comprising:

receiving, at a first network endpoint, a key exchange request from a client device, the key exchange request being encrypted and including an identifier of the client device and an ephemeral public encryption key of the client device;

decrypting the key exchange request according to a private encryption key of the first network endpoint;

generating a key exchange response, the key exchange response including an ephemeral public encryption key of the first network endpoint and encrypted according to the ephemeral public encryption key of the client device, wherein the generating the key exchange response comprises:

generating one or more endpoint validation tokens; and

associating the one or more endpoint validation tokens with the identifier of the client device, wherein the key exchange response includes the one or more endpoint validation tokens;

transmitting, to the client device, the key exchange response, wherein the key exchange request is received via a first communication band;

generating a shared encryption key based on the private encryption key of the first network endpoint and the ephemeral public encryption key of the client;

storing the shared encryption key with an association to the identifier of the client device in a data store;

receiving, at a second network endpoint via a second communication band, an authenticated message from the client device, the authenticated message being symmetrically encrypted, wherein the first communication band and the second communication band are different communication bands; and

decrypting the authenticated message according to the shared encryption key.

8 . The method of claim 7 , wherein the key exchange request is asymmetrically encrypted according to a static public key of the first network endpoint and a private key of the client device, and wherein the key exchange response is asymmetrically encrypted according to a static public key of the client device and the private key of the first network endpoint.

9 . The method of claim 7 , wherein the key exchange response is transmitted via the first communication band.

10 . The method of claim 7 , wherein the key exchange response is transmitted via a third communication band.

11 . The method of claim 7 , further comprising establishing, by the second network endpoint, a secure tunnel with the client device through the second communication band based on the authenticated message.

12 . A computing device, comprising:

a non-transitory memory;

at least one processor; and

a key exchange application stored in the non-transitory memory that, when executed by the at least one processor:

receives an asymmetrically encrypted key exchange request from a client device, the asymmetrically encrypted key exchange request including an identifier of the client device and encrypted according to a static public key of the computing device;

decrypts the asymmetrically encrypted key exchange request according to a private encryption key of the computing device to obtain the identifier of the client device;

generate one or more endpoint validation tokens uniquely identifying the client device;

store the endpoint validation tokens with an association to the client device;

generate an asymmetrically encrypted key exchange response, the asymmetrically encrypted key exchange response encrypted according to a static public key of the client device and including the one or more endpoint validation tokens;

transmits the asymmetrically encrypted key exchange response to the client device; and

generates a symmetric encryption key according to the static public key of the client device and a private key of the computing device, wherein the asymmetrically encrypted key exchange request is received from the client device via a communication band other than a second and different communication band over which the client device transmits authenticated messages which are authenticated according to the symmetric encryption key.

13 . The computing device of claim 12 , wherein executing the key exchange application further causes the processor to store the symmetric encryption key in a data store with an association to the client device.

14 . The computing device of claim 12 , wherein the asymmetrically encrypted key exchange request is received from the client device via a bandwidth constrained communication protocol.

15 . The computing device of claim 12 , wherein the computing device

receives a symmetrically encrypted authenticated message from the client device via the second communication band; and

decrypts the symmetrically encrypted authenticated message according to the symmetric encryption key.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2024
From: SCATR, LLC
To: SCATR, CORP
Reel/Frame 068117/0434 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: ANDREWS, JOHN G.; KEYERLEBER, JOHN P.
To: SCATR LLC
Reel/Frame 067433/0769 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: ANDREWS, JOHN G.; KEYERLEBER, JOHN P.
To: SCATR LLC
Reel/Frame 067435/0087 →
Continuity (1)
Related Publication 20250007707A1 · Jan 2, 2025
References Cited (140)
US 6502135B1 · Munger et al. · 2002 [cited by applicant]
US 6765866B1 · Wyatt · 2004 [cited by applicant]
US 6990111B2 · Lemoff et al. · 2006 [cited by applicant]
US 7382782B1 · Ferguson et al. · 2008 [cited by applicant]
US 7697528B2 · Parry et al. · 2010 [cited by applicant]
US 7782782B1 · Ferguson et al. · 2010 [cited by applicant]
US 7895348B2 · Twitchell, Jr. · 2011 [cited by applicant]
US 7984495B1 · Aravind · 2011 [cited by applicant]
US 8274980B2 · Sato et al. · 2012 [cited by applicant]
US 8358658B2 · Flynn et al. · 2013 [cited by applicant]
US 8416686B2 · Ferguson et al. · 2013 [cited by applicant]
US 8924716B2 · Miyabayashi et al. · 2014 [cited by applicant]
US 8955110B1 · Twitchell, Jr. · 2015 [cited by applicant]
US 9116734B1 · Twitchell, Jr. et al. · 2015 [cited by applicant]
US 9185046B2 · Ferguson et al. · 2015 [cited by applicant]
US 9225699B2 · Biradar et al. · 2015 [cited by applicant]
US 9241026B2 · Twitchell, Jr. · 2016 [cited by applicant]
US 9495194B1 · Twitchell, Jr. et al. · 2016 [cited by applicant]
US 9535805B2 · Ananthanarayanan et al. · 2017 [cited by applicant]
US 9629063B2 · Brown et al. · 2017 [cited by applicant]
US 9794797B2 · Hoffberg · 2017 [cited by applicant]
US 10356061B2 · Fiske · 2019 [cited by applicant]
US 10432526B2 · Gafni et al. · 2019 [cited by applicant]
US 10469375B2 · Twitchell, Jr. · 2019 [cited by applicant]
US 10541907B2 · Twitchell, Jr. et al. · 2020 [cited by applicant]
US 10637685B2 · Goel et al. · 2020 [cited by applicant]
US 10686729B2 · Sindhu et al. · 2020 [cited by applicant]
US 10715327B1 · Ramanujan et al. · 2020 [cited by applicant]
US 10826711B2 · Barry · 2020 [cited by applicant]
US 10826876B1 · Sinn et al. · 2020 [cited by applicant]
US 10833972B2 · Vaughan et al. · 2020 [cited by applicant]
US 10904367B2 · Goel et al. · 2021 [cited by applicant]
US 10965586B2 · Goel et al. · 2021 [cited by applicant]
US 11153276B1 · Keyerleber · 2021 [cited by applicant]
US 11171934B2 · Fiske · 2021 [cited by applicant]
US 11178262B2 · Goel et al. · 2021 [cited by applicant]
US 11184147B2 · Ghorbani · 2021 [cited by applicant]
US 11381557B2 · Kim et al. · 2022 [cited by applicant]
US 11469922B2 · Goel et al. · 2022 [cited by applicant]
US 11533617B2 · Mihelich et al. · 2022 [cited by applicant]
US 11558422B2 · Twitchell, Jr. et al. · 2023 [cited by applicant]
US 11601359B2 · Goel et al. · 2023 [cited by applicant]
US 11637694B2 · Islamov · 2023 [cited by applicant]
US 11777839B2 · Sindhu et al. · 2023 [cited by applicant]
US 11805127B1 · Sundar · 2023 [cited by examiner]
US 11895015B1 · Budhia et al. · 2024 [cited by applicant]
US 12021972B2 · Wang et al. · 2024 [cited by applicant]
US 12120028B1 · Andrews et al. · 2024 [cited by applicant]
US 12335160B2 · Andrews et al. · 2025 [cited by applicant]
US 20010050914A1 · Akahane et al. · 2001 [cited by applicant]
US 20010054158A1 · Jarosz · 2001 [cited by applicant]
US 20020191797A1 · Perlman · 2002 [cited by examiner]
US 20030112755A1 · McDysan · 2003 [cited by applicant]
US 20040103205A1 · Larson et al. · 2004 [cited by applicant]
US 20060008082A1 · Gluck et al. · 2006 [cited by applicant]
US 20070217424A1 · Kim et al. · 2007 [cited by applicant]
US 20100149988A1 · Matsubara et al. · 2010 [cited by applicant]
US 20110179136A1 · Twitchell, Jr. · 2011 [cited by applicant]
US 20110271096A1 · Bharrat et al. · 2011 [cited by applicant]
US 20120204032A1 · Wilkins et al. · 2012 [cited by applicant]
US 20140115341A1 · Robertson · 2014 [cited by applicant]
US 20150326603A1 · Deisinger et al. · 2015 [cited by applicant]
US 20150350245A1 · Twitchell, Jr. et al. · 2015 [cited by applicant]
US 20150350246A1 · Bergman · 2015 [cited by applicant]
US 20160065370A1 · Le Saint · 2016 [cited by examiner]
US 20160119291A1 · Zollinger et al. · 2016 [cited by applicant]
US 20160255054A1 · Wan et al. · 2016 [cited by applicant]
US 20170019256A1 · Rhelimi · 2017 [cited by examiner]
US 20170033925A1 · DeNeut et al. · 2017 [cited by applicant]
US 20170126626A1 · Datta et al. · 2017 [cited by applicant]
US 20170149740A1 · Mansour et al. · 2017 [cited by applicant]
US 20170331794A1 · Lokman et al. · 2017 [cited by applicant]
US 20170372048A1 · Liu · 2017 [cited by examiner]
US 20180316598A1 · Twitchell, Jr. · 2018 [cited by applicant]
US 20180375663A1 · Le Saint · 2018 [cited by examiner]
US 20190014092A1 · Malek et al. · 2019 [cited by applicant]
US 20190294464A1 · Twitchell, Jr. et al. · 2019 [cited by applicant]
US 20190373458A1 · Dandekar et al. · 2019 [cited by applicant]
US 20200014619A1 · Shelar et al. · 2020 [cited by applicant]
US 20200154272A1 · Uy · 2020 [cited by examiner]
US 20200195439A1 · Suresh et al. · 2020 [cited by applicant]
US 20200211002A1 · Steinberg · 2020 [cited by applicant]
US 20200213111A1 · Leavy · 2020 [cited by examiner]
US 20200213151A1 · Srivatsan et al. · 2020 [cited by applicant]
US 20200226258A1 · Nix · 2020 [cited by applicant]
US 20200259640A1 · Leavy · 2020 [cited by examiner]
US 20210051146A1 · Stolbikov et al. · 2021 [cited by applicant]
US 20210105301A1 · Anderson et al. · 2021 [cited by applicant]
US 20210144004A1 · Gray · 2021 [cited by examiner]
US 20210168138A1 · Paruchuri · 2021 [cited by applicant]
US 20210184854A1 · Pizot et al. · 2021 [cited by applicant]
US 20210297351A1 · Vegesna et al. · 2021 [cited by applicant]
US 20210328779A1 · Ruan · 2021 [cited by examiner]
US 20210328976A1 · Leavy · 2021 [cited by examiner]
US 20210352471A1 · Hallock · 2021 [cited by applicant]
US 20210360026A1 · Anderson et al. · 2021 [cited by applicant]
US 20220247678A1 · Atwal et al. · 2022 [cited by applicant]
US 20220392286A1 · Elrad · 2022 [cited by examiner]
US 20230006993A1 · Bilgin et al. · 2023 [cited by applicant]
US 20230097712A1 · Sullivan · 2023 [cited by examiner]
US 20230164086A1 · York et al. · 2023 [cited by applicant]
US 20230188347A1 · Sarin · 2023 [cited by applicant]
US 20230198914A1 · Ranjan et al. · 2023 [cited by applicant]
US 20230208748A1 · Goel et al. · 2023 [cited by applicant]
US 20240007367A1 · Demchenko · 2024 [cited by applicant]
US 20240028367A1 · Mathew et al. · 2024 [cited by applicant]
US 20240214803A1 · Dandekar et al. · 2024 [cited by applicant]
US 20240275596A1 · Stolbikov et al. · 2024 [cited by applicant]
US 20240380726A1 · Ban · 2024 [cited by examiner]
CN 112333152A · 2021 [cited by examiner]
EP 3651407A1 · 2020 [cited by examiner]
WO WO2018160863A1 · 2018 [cited by examiner]
WO WO2023134844A1 · 2023 [cited by examiner]
Notice of Allowance dated Jun. 22, 2021, U.S. Appl. No. 16/683,146, filed Nov. 13, 2019. [cited by applicant]
Office Action dated Apr. 12, 2023, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Final Office Action dated Jul. 24, 2023, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Keyerleber, John P., et al., “Secure Data Routing and Randomization,” filed Sep. 22, 2021, U.S. Appl. No. 17/481,914. [cited by applicant]
Andrews, John G., et al., “Secure Data Routing With Channel Resiliency,” filed Mar. 31, 2023, U.S. Appl. No. 18/194,413. [cited by applicant]
Andrews, John G., et al., “Network Traffic Obfuscation,” filed Jun. 30, 2023, U.S. Appl. No. 18/345,829. [cited by applicant]
Andrews, John G., et al., “Endpoint Validation Security,” filed Jun. 30, 2023, U.S. Appl. No. 18/345,837. [cited by applicant]
Andrews, John G., et al., “Secure Data Routing With Dynamic Packet Spoofing ,” filed Jun. 30, 2023, U.S. Appl. No. 18/345,847. [cited by applicant]
“Andrews, John G., et al., ““Secure Data Routing Andrandomization in Windows,”” filed Jul. 28, 2023, U.S. Appl. No. 18/361,721.” [cited by applicant]
Notice of Allowance dated Jun. 11, 2024, U.S. Appl. No. 18/194,413, filed Mar. 31, 2023. [cited by applicant]
Office Action dated Nov. 27, 2024, U.S. Appl. No. 18/345,829, filed Jun. 30, 2023. [cited by applicant]
Syed, et al., “Zero Trust Architecture (ZTA): A Comprehensive Survey”, IEEE Access—Digital Object Identifier, vol. 10, 37 pages, 2022. [cited by applicant]
Shu, et al., “Secure Data Collection in Wireless Sensor Networks Using Randomized Dispersive Routes”, IEEE Transactions on Mobile Computing, vol. 9, No. 7, Jul. 2010, 14 pages. [cited by applicant]
Andrews, John G., et al., “Secure Data Routing With Channel Resiliency,” filed Sep. 11, 2024, U.S. Appl. No. 11/882,552. [cited by applicant]
Advisory Action dated Oct. 5, 2023, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Examiner's Answer to Appeal Brief dated Feb. 23, 2024, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Office Action dated Feb. 13, 2024, U.S. Appl. No. 18/194,413, filed Mar. 31, 2023. [cited by applicant]
Keyerleber, John P., “Machine Learning Driven Network Traffic Obfuscation,” filed Jan. 24, 2024, U.S. Appl. No. 18/421,960. [cited by applicant]
Keyerleber, et al., “Optimizing Network Traffic Obfuscation Based On Network Performance Using Reinforcement Learning,” filed Jan. 24, 2024, U.S. Appl. No. 18/421,965. [cited by applicant]
Keyerleber, et al., “Optimizing Network Traffic Obfuscation Based On Aggregated Network Performance,” filed Jan. 24, 2024, Application No. Jan. 24, 2024. [cited by applicant]
Notice of Allowance dated May 20, 2025, U.S. Appl. No. 18/345,829, filed Jun. 30, 2023. [cited by applicant]
Office Action dated Jul. 11, 2025, U.S. Appl. No. 18/345,837, filed Jun. 30, 2023. [cited by applicant]
Notice of Allowance dated Feb. 21, 2025, U.S. Appl. No. 18/345,847, filed Jun. 30, 2023. [cited by applicant]
Office Action dated Apr. 23, 2025, U.S. Appl. No. 18/361,721, filed Jul. 28, 2023. [cited by applicant]
Notice of Allowance dated Dec. 9, 2025, U.S. Appl. No. 18/361,721, filed Jul. 28, 2023. [cited by applicant]
Notice of Allowance dated Oct. 27, 2025, U.S. Appl. No. 18/345,837, filed Jun. 30, 2023. [cited by applicant]
Decision on Appeal dated Nov. 18, 2025, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]