IP Library › Granted Patent US 12,495,062
Granted Patent B2
US 12,495,062 · App. 18/471,831 · Granted Dec 9, 2025

Continuous authentication in secure and isolated network environments

Inventors: Wyatt Cobb (Mission Hills, KS); Zach Dougherty (Merriam, KS); Micah Juhnke (Liberty, MO); Brandon Shannon (Lawrence, KS)
Assignee: SoftWarfare, LLC
H04L63/1433H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,062
App. No.
18/471,831
Granted
Dec 9, 2025
Kind
B2
Abstract

Embodiments of the current disclosure are directed to authorizing data transfers and permissions requests in secure networks. In some embodiments, requesting users may request data transfers and access to secure networks, data, resources, documents, and the like. Continuous monitoring, risk analysis, and authorization may be performed in real time in the secure networks by utilizing statistical and machine learning algorithms as well as rules engines to determine a likelihood of the requests being a threat and determine an overall risk level associated with the threat. Furthermore, the secure networks may comprise denied, disrupted, intermittent, and limited-bandwidth (DDIL) DDIL environments that are disconnected from network environments for extended periods. As such, various request authentication techniques may be implemented in the DDIL environments.

Claims (81)

1 . One or more non-transitory computer-readable media that store computer-executable instructions that, when executed by at least one processor, perform a method of authenticating a request on a secure network, the method comprising:

receiving the request to transfer data on the secure network from a requesting device by a requesting user,

wherein the request comprises requesting to communicatively connect to a denied, disrupted, intermittent, and limited-bandwidth (DDIL) environment,

generating an offline authorization token for the requesting user associated with the request to access the DDIL environment;

obtaining user ID data of the requesting user, behavioral data, and machine data from the requesting device;

comparing each of the user ID data, the behavioral data, and the machine data to corresponding historical data to determine a likelihood that the request is a threat;

comparing, by a rules engine, the likelihood that the request is the threat to a threshold value to determine a risk level associated with the request; and

authenticating the request based on the risk level and the offline authorization token.

2 . The media of claim 1 , wherein the method further comprises comparing the user ID data, the behavioral data, and the machine data to the corresponding historical data by a machine learning algorithm to determine the likelihood of the threat of the request.

3 . The media of claim 1 ,

wherein the DDIL environment comprises locally stored infrastructure from a cloud-based provider.

4 . The media of claim 3 , wherein the method further comprises:

storing the user ID data, the behavioral data, the machine data, the likelihood, and authentication data to a blockchain in the DDIL environment,

wherein, when connected to a network environment, the DDIL environment is configured to:

provide access to the blockchain to the network environment for verifying the authentication data;

update infrastructure and applications from the cloud-based provider; and

audit data logs stored on the blockchain.

5 . The media of claim 3 , wherein the method further comprises performing a peer-to-peer authentication of the request, the peer-to-peer authentication comprising:

randomly selecting a subset of approved users in the DDIL environment from a set of approved users authorized to access the DDIL environment;

providing at least a subset of the user ID data to the subset of approved users;

receiving feedback from the subset of approved users; and

modifying the likelihood of the request being the threat based on the feedback from the subset of approved users.

6 . The media of claim 3 , wherein the method further comprises a peer-to-peer authentication of the request, the peer-to-peer authentication comprising:

randomly selecting a subset of users from a set of users authorized to access the DDIL environment;

providing at least the user ID data to the subset of users;

receiving at least one denial of the request to communicatively connect to the DDIL environment;

denying the request to access the DDIL environment; and

storing denial data indicative of the user ID data, the at least one denial, and the at least one denial in a blockchain configured to be uploaded to a network environment when the DDIL environment is connected to the network environment.

7 . The media of claim 3 , wherein the DDIL environment comprises a local network of integrated mobile devices associated with military personnel.

8 . The media of claim 3 ,

wherein the request comprises requesting access to the DDIL environment,

wherein the method further comprises denying access to resources in the DDIL environment to a user associated with the request.

9 . A system for authenticating a request on a secure network, the system comprising:

at least one data store;

at least one processor; and

one or more non-transitory computer-readable media that store computer-executable instructions that, when executed by the at least one processor, perform a method of authenticating the request on the secure network, the method comprising:

receiving the request to transfer data on the secure network from a requesting device,

wherein the secure network is a denied, disrupted, intermittent, and limited-bandwidth (DDIL) environment,

wherein the DDIL environment comprises locally stored infrastructure from a cloud-based provider;

obtaining user ID data of a requesting user, behavioral data, and machine data from the requesting device;

comparing, within the DDIL environment, each of the user ID data, the behavioral data, and the machine data to corresponding historical data to determine a likelihood that the request is a threat;

comparing, by a rules engine within the DDIL environment, the likelihood that the request is the threat to a threshold value to determine a risk level associated with the request; and

authenticating the request based on the risk level.

10 . The system of claim 9 , wherein the method further comprises comparing the user ID data, the behavioral data, and the machine data to the corresponding historical data by a machine learning algorithm to determine the likelihood of the threat of the request.

11 . The system of claim 10 ,

wherein the request comprises requesting to communicatively connect to the DDIL environment,

wherein the method further comprises generating an offline authorization token for the requesting user associated with the request to access the DDIL environment.

12 . The system of claim 11 , wherein the rules engine generates an approval designation from an options list of approve, deny, and more information needed.

13 . The system of claim 12 , wherein the method further comprises:

continually analyzing and storing request data associated with the requesting device and the requesting user associated with the requesting device; and

authenticating actions associated with the requesting user and the requesting device after the request is authorized.

14 . A method of authenticating a request on a secure network, the method comprising:

receiving the request to transfer data on the secure network from a requesting device;

wherein the secure network is a denied, disrupted, intermittent, and limited-bandwidth (DDIL) environment comprising locally stored infrastructure from a cloud-based provider;

obtaining user ID data of a requesting user, behavioral data, and machine data from the requesting device;

comparing, within the DDIL environment, each of the user ID data, the behavioral data, and the machine data with corresponding historical data to determine a likelihood that the request is a threat;

comparing, by a rules engine within the DDIL environment, the likelihood that the request is the threat to a threshold value to determine a risk level associated with the request; and

authenticating the request based on the risk level.

15 . The method of claim 14 , further comprising:

storing the user ID data, the behavioral data, the machine data, the likelihood, and authentication data to a blockchain in the DDIL environment,

wherein, when connected to a network environment, the DDIL environment is configured to:

provide access to the blockchain to the network environment for verifying the authentication data; and

audit data logs stored on the blockchain.

16 . The method of claim 14 , further comprising:

randomly selecting a subset of approved users in the DDIL environment from a set of approved users authorized to access the DDIL environment;

providing at least a subset of the user ID data to the subset of approved users;

receiving feedback from the subset of approved users; and

modifying the likelihood of the request being the threat based on the feedback from the subset of approved users.

17 . The method of claim 14 , further comprising:

randomly selecting a subset of users from a set of users authorized to access the DDIL environment;

providing at least the user ID data to the subset of users;

receiving at least one denial of the request to communicatively connect to the DDIL environment;

denying the request to access the DDIL environment; and

storing denial data indicative of the user ID data and the at least one denial in a blockchain configured to be uploaded to a network environment when the DDIL environment is connected to the network environment.

18 . The method of claim 14 , wherein the DDIL environment comprises a local network of integrated mobile devices associated with military personnel.

19 . The method of claim 14 ,

wherein the request comprises requesting access to the DDIL environment,

wherein the method further comprises denying access to resources in the DDIL environment to the requesting user associated with the request.

20 . The method of claim 14 , wherein the method further comprises:

generating an offline authorization token for the requesting user associated with the request to access the DDIL environment; and

authenticating the request further based on the offline authorization token.

Assignments (2)
SECURITY INTEREST Recorded Mar 20, 2025
From: SOFTWARFARE, LLC
To: OUTDOOR BANK
Reel/Frame 070583/0259 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: COBB, WYATT; DOUGHERTY, ZACH; JUHNKE, MICAH; SHANNON, BRANDON
To: SOFTWARFARE, LLC
Reel/Frame 064986/0577 →
Continuity (1)
Related Publication 20250106236A1 · Mar 27, 2025
References Cited (20)
US 9521606B1 · Costa · 2016 [cited by examiner]
US 10044751B2 · Huston, III · 2018 [cited by examiner]
US 10171495B1 · Bowen · 2019 [cited by examiner]
US 20110314558A1 · Song · 2011 [cited by examiner]
US 20140143863A1 · Deb · 2014 [cited by examiner]
US 20160065598A1 · Modi · 2016 [cited by examiner]
US 20160065599A1 · Hovor · 2016 [cited by examiner]
US 20160330219A1 · Hasan · 2016 [cited by examiner]
US 20170180339A1 · Cheng · 2017 [cited by examiner]
US 20210203674A1 · Azaria · 2021 [cited by examiner]
US 20210352088A1 · Adams · 2021 [cited by examiner]
US 20210406402A1 · Seibel · 2021 [cited by examiner]
US 20220086175A1 · Bharrat · 2022 [cited by examiner]
US 20230135755A1 · Nakar · 2023 [cited by examiner]
US 20240223607A1 · Weber · 2024 [cited by examiner]
US 20240396894A1 · Fisher · 2024 [cited by examiner]
US 20250008328A1 · Smith · 2025 [cited by examiner]
US 20250039260A1 · Kharbanda · 2025 [cited by examiner]
US 20250106236A1 · Cobb · 2025 [cited by examiner]
WO WO2019164807A1 · 2019 [cited by examiner]