IP Library › Granted Patent US 12,592,827
Granted Patent B2
US 12,592,827 · App. 18/520,009 · Granted Mar 31, 2026

Pairing methods in zero-trust networks

Inventors: Igor Stolbikov (Apex, NC); Sergei Rodionov (Plano, TX); Rod D Waltermann (Rougemont, NC); Scott Li (Cary, NC)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04L9/3226H04L9/0819H04L9/3066H04L67/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,827
App. No.
18/520,009
Granted
Mar 31, 2026
Kind
B2
Abstract

A method for communications in a network can include performing a pairing between a first device and a second device in the network. The method can include deriving a port knocking sequence from identification information of the pairing. The method can include providing port knocking according to the port knocking sequence. The method can include authorizing a connection between the first device and the second device responsive to detecting the port knocking sequence. Other devices and methods are described.

Claims (58)

1 . A method performed for communications in a network, the method comprising:

performing a pairing between a first device and a second device in the network;

deriving, during the pairing, a dynamic cryptographic identity for at least one of the first device and the second device using a key-negation function based on a Password-Authentication Key Exchange (PAKE) protocol;

deriving a port knocking sequence from the dynamic cryptographic identity identification information of the pairing;

providing port knocking according to the port knocking sequence; and

authorizing a connection between the first device and the second device responsive to detecting the port knocking sequence;

detecting a connection attempt from a third device that does not include the port knocking sequence;

marking the connection attempt as a malicious attempt responsive to the detection; and

refraining from transmitting the signals to the third device;

wherein the port knocking sequence specifies port numbers in an order that the port numbers should be knocked.

2 . The method of claim 1 , further comprising:

deriving the dynamic cryptographic identity subsequent to pairing based on an elliptic curve Diffie-Hellman Ephemeral (ECDHE) protocol.

3 . The method of claim 1 , further comprising:

detecting a connection attempt that does not include the port knocking sequence; and

marking the connection attempt as a malicious attempt responsive to the detecting.

4 . The method of claim 1 , further comprising:

hashing a device identity of the first device or the second device to a pre-authorize connectivity string prior to deriving the port knocking sequence.

5 . The method of claim 4 , further comprising:

hashing an application identity or a device location to the connectivity string prior to deriving the port knocking sequence.

6 . A device comprising:

communication circuitry; and

processing circuitry coupled to the communication circuitry and configured to:

provide a cryptographic identity over the communication circuitry to pair with a second device;

derive, during the pairing, a dynamic cryptographic identity for at least one of the first device and the second device using a key-negation function based on a Password-Authentication Key Exchange (PAKE) protocol;

derive a port knocking sequence from the dynamic cryptographic identity identification information of the pairing;

encode signals for port knocking according to the port knocking sequence in a subsequent communication with the second device; and

transmit the signals using the communication circuitry;

detect a connection attempt from a third device that does not include the port knocking sequence;

mark the connection attempt as a malicious attempt responsive to the detection; and

refrain from transmitting the signals to the third device;

wherein the port knocking sequence specifies port numbers in an order that the port numbers should be knocked.

7 . The device of claim 6 , wherein the processing circuitry is further configured to:

authorize a connection to the second device responsive to detecting the port knocking sequence in a communication from the second device.

8 . The device of claim 6 , wherein the identification information includes a dynamic cryptographic identity of the device.

9 . The device of claim 8 , wherein the processing circuitry is further configured to:

derive the dynamic cryptographic identity during the pairing using a key negation function based on a Password Authentication Key Exchange (PAKE) protocol.

10 . The device of claim 9 , wherein the processing circuitry is further configured to:

derive the cryptographic identity subsequent to pairing based on an elliptic curve Diffie-Hellman Ephemeral (ECDHE) protocol.

11 . The device of claim 6 , wherein the processing circuitry is further configured to:

hash a device identity of the device to a pre-authorize connectivity string prior to deriving the port knocking sequence.

12 . The device of claim 11 , wherein the processing circuitry is further configured to:

hash an application identity or a device location to the connectivity string prior to deriving the port knocking sequence.

13 . A non-transitory machine-readable medium including instructions that, when executed on processing circuitry, cause the processing circuitry to perform operations including:

performing a pairing between a first device and a second device in a network;

deriving, during the pairing, a dynamic cryptographic identity for at least one of the first device and the second device using a key-negation function based on a Password-Authentication Key Exchange (PAKE) protocol;

derive a port knocking sequence from the dynamic cryptographic identity identification information of the pairing;

encoding a signal to provide port knocking according to the port knocking sequence; and

authorizing a connection between the first device and the second device responsive to detecting the port knocking sequence;

detecting a connection attempt from a third device that does not include the port knocking sequence;

marking the connection attempt as a malicious attempt responsive to the detecting; and

refraining from transmitting the signals to the third device;

wherein the port knocking sequence specifies port numbers in an order that the port numbers should be knocked.

14 . The non-transitory machine-readable medium of claim 13 , wherein the identification information includes a dynamic cryptographic identity of at least one of the first device and the second device.

15 . The non-transitory machine-readable medium of claim 14 , wherein the operations further comprise:

prior to pairing, deriving the dynamic cryptographic identity using a key negation function based on a Password Authentication Key Exchange (PAKE) protocol; and

subsequent to pairing, deriving the cryptographic identity subsequent to pairing based on an elliptic curve Diffie-Hellman (ECDH) protocol.

16 . The non-transitory machine-readable medium of claim 13 , wherein the operations further comprise:

hashing at least one of a device identity, an application identity, or a device location to a pre-authorize connectivity string prior to deriving the port knocking sequence.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 26, 2023
From: LENOVO (UNITED STATES) INC.
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 066140/0696 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2023
From: STOLBIKOV, IGOR; RODIONOV, SERGEI; WALTERMANN, ROD D.; LI, SCOTT
To: LENOVO (UNITED STATES) INC.
Reel/Frame 065670/0538 →
Continuity (1)
Related Publication 20250175341A1 · May 29, 2025
References Cited (19)
US 8010085B2 · Apte · 2011 [cited by examiner]
US 8464335B1 · Sinha · 2013 [cited by examiner]
US 8656154B1 · Kailash · 2014 [cited by examiner]
US 8869259B1 · Udupa · 2014 [cited by examiner]
US 8869262B2 · Mullick · 2014 [cited by examiner]
US 8955091B2 · Kailash · 2015 [cited by examiner]
US 9065800B2 · Devarajan · 2015 [cited by examiner]
US 9100424B1 · Thomas · 2015 [cited by examiner]
US 9344393B2 · Boynton · 2016 [cited by examiner]
US 9531758B2 · Devarajan · 2016 [cited by examiner]
US 9654507B2 · Gangadharappa · 2017 [cited by examiner]
US 9882767B1 · Foxhoven · 2018 [cited by examiner]
US 9935955B2 · Desai · 2018 [cited by examiner]
US 10044719B2 · Desai · 2018 [cited by examiner]
US 10142362B2 · Weith · 2018 [cited by examiner]
US 20180109497A1 · Claes · 2018 [cited by examiner]
US 20180241718A1 · Stair · 2018 [cited by examiner]
US 20180309795A1 · Ithal · 2018 [cited by examiner]
US 20210345080A1 · Uy · 2021 [cited by examiner]