IP Library › Granted Patent US 12,099,594
Granted Patent B1
US 12,099,594 · App. 18/600,220 · Granted Sep 24, 2024

Socket connection verification

Inventors: Chuck Doerr (New York, NY); Andrew Westacott (East Lothian, GB)
Assignee: Here Enterprise Inc.
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,099,594
App. No.
18/600,220
Granted
Sep 24, 2024
Kind
B1
Abstract

Disclosed is a method and apparatus for verifying socket connections. The method includes receiving a socket connection request and determining a process executable that initiated the socket connection request. The method further includes determining, by a processing device, whether verification data associated with the process executable corresponds to expected verification data of the process executable. Finally, the method includes in response to the verification data corresponding to the expected verification data, permitting a socket connection corresponding to the socket connection request.

Claims (36)

1. A method comprising:

receiving a socket connection request;

utilizing a software development kit to determine a process executable that initiated the socket connection request, wherein the process executable operates within a software process;

determining, by a processing device, whether verification data associated with the process executable corresponds to expected verification data of the process executable; and

in response to the verification data corresponding to the expected verification data, permitting a socket connection corresponding to the socket connection request.

2. The method of claim 1 , further comprising in response to the verification data not corresponding to the expected verification data, terminating the socket connection corresponding to the socket connection request.

3. The method of claim 1 , wherein the verification data includes a certificate or signature that validates that the process executable is authentic.

4. The method of claim 3 , wherein the expected verification data includes a predefined list of one or more known certificates or known signatures, each associated with a verified process executable, and wherein determining whether the verification data corresponds to the expected verification data includes determining whether the certificate or signature is on the predefined list of one or more known certificates or known signatures.

5. The method of claim 1 , further comprising determining whether the process executable includes any verification data; and

in response to the process executable not having verification data, terminating the socket connection corresponding to the socket connection request; and

in response to the process executable having verification data, extracting the verification data and comparing the verification data to the expected verification data to determine whether the verification data associated with the process executable corresponds to the expected verification data of the process executable.

6. The method of claim 1 , further comprising extracting the verification data of the process executable and storing the verification data in memory and associating the stored verification data with the socket connection.

7. The method of claim 1 , further comprising filtering traffic communicated across the socket connection based on the verification data.

8. An apparatus comprising:

a memory; and

a processing device operatively coupled to the memory to:

receive a socket connection request;

utilize a software development kit to determine a process executable that initiated the socket connection request, wherein the process executable operates within a software process;

determine whether verification data associated with the process executable corresponds to expected verification data of the process executable; and

in response to the verification data corresponding to the expected verification data, permit a socket connection corresponding to the socket connection request.

9. The apparatus of claim 8 , wherein the processing device is further to, in response to the verification data not corresponding to the expected verification data, terminate the socket connection corresponding to the socket connection request.

10. The apparatus of claim 8 , wherein the verification data includes a certificate or signature that validates that the process executable is authentic.

11. The apparatus of claim 10 , wherein the expected verification data includes a predefined list of one or more known certificates or known signatures, each associated with a verified process executable, and wherein the processing device is further to determine whether the certificate or signature is on the predefined list of one or more known certificates or known signatures.

12. The apparatus of claim 8 , wherein the processing device is further to:

determine whether the process executable includes any verification data; and

in response to the process executable not having verification data, terminate the socket connection corresponding to the socket connection request; and

in response to the process executable having verification data, extract the verification data and compare the verification data to the expected verification data to determine whether the verification data associated with the process executable corresponds to the expected verification data of the process executable.

13. The apparatus of claim 8 , wherein the processing device is further to extract the verification data of the process executable and store the verification data in memory and associate the stored verification data with the socket connection.

14. The apparatus of claim 8 , wherein the processing device is further to filter traffic communicated across the socket connection based on the verification data.

15. A non-transitory computer readable storage medium to store instructions executable by a processing device, cause the processing device to:

receive a socket connection request;

utilize a software development kit to determine a process executable that initiated the socket connection request, wherein the process executable operates within a software process;

determine, by the processing device, whether verification data associated with the process executable corresponds to expected verification data of the process executable; and

in response to the verification data corresponding to the expected verification data, permit a socket connection corresponding to the socket connection request.

16. The non-transitory computer readable storage medium of claim 15 , wherein the processing device is further to, in response to the verification data not corresponding to the expected verification data, terminate the socket connection corresponding to the socket connection request.

17. The non-transitory computer readable storage medium of claim 15 , wherein the verification data includes a certificate or signature that validates that the process executable is authentic.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2024
From: DOERR, CHUCK; WESTACOTT, ANDREW
To: OPENFIN INC.
Reel/Frame 067926/0678 →
CHANGE OF NAME Recorded Jul 3, 2024
From: OPENFIN INC.
To: HERE ENTERPRISE INC.
Reel/Frame 068122/0430 →
Continuity (1)
Continuation 18408316 · Jan 9, 2024