IP Library › Patent Application 18928937
Patent Application
App. No. 18/928,937

Pebble-Ripple Attestation of Network Nodes

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/928,937
Abstract

Some embodiments improve the security of a network of IoT devices via a recurrent re-attestation of network nodes. The frequency of re-attestation may depend on a network role of the respective device (e.g., router vs. end node) and/or on a measure of connectivity of the respective node (e.g., node degree), with highly connected nodes re-attested more often than end nodes. Some embodiments employ a pebble-ripple attestation procedure wherein an administration device transmits an attestation probe to a device via one-to-one messaging (e.g., unicast), and the respective device replies via one-to-many messaging (e.g., multicast). The administration device then attests the identity and/or functionality of the respective device according to the timing of multiple replies from the attested device, each reply traversing the network via a distinct route.

Claims (41)

1 . A security appliance connected to a computer network comprising a plurality of interconnected client devices, the security appliance comprising at least one hardware processor configured to:

engage in an attestation session with a selected client device of the plurality of client devices, the attestation session comprising:

transmitting an attestation probe to the selected client device, and

determining a result of the attestation session according to a timing of a plurality of instances of a reply to the attestation probe, each instance of the reply received from the selected client device via a distinct network route; and

in response to a failure of the attestation session, determine whether the failure is indicative of a computer security threat.

2 . The security appliance of claim 1 , wherein determining the result of the attestation session comprises:

determining whether the plurality of instances of the reply match a reference reply pattern determined according to previous attestations of the selected client device;

in response, if yes, determining that the attestation session is successful; and

otherwise, determining that the attestation session has failed.

3 . The security appliance of claim 2 , wherein the at least one hardware processor is configured to determine whether the plurality of instances of the reply match the reference reply pattern according to a count of instances of the reply received within a pre-determined time window following transmission of the attestation probe.

4 . The security appliance of claim 2 , wherein the at least one hardware processor is configured to determine whether the plurality of instances of the reply match the reference reply pattern according to a likelihood for an instance of the reply to be received within a pre-determined time interval following transmission of the attestation probe.

5 . The security appliance of claim 2 , wherein the at least one hardware processor is configured to determine whether the plurality of instances of the reply match the reference reply pattern according to a network route followed by a selected instance of the plurality of instances of the reply.

6 . The security appliance of claim 1 , wherein the at least one hardware processor is configured to transmit the attestation probe to the selected client device using a one-to-one messaging protocol, and wherein the attestation probe is formulated to cause the selected client device to send the reply using a one-to-many messaging protocol.

7 . The security appliance of claim 1 , wherein the attestation probe includes an encrypted session ID identifying the attestation session from among a plurality of other attestation sessions.

8 . The security appliance of claim 7 , wherein the reply by the selected client device is formulated to include the session ID.

9 . The security appliance of claim 7 , wherein the security appliance is configured to determine a result of the attestation session according to a value of the session ID included in the reply.

10 . The security appliance of claim 1 , wherein the attestation probe is formulated to cause the selected client device to perform a service discovery procedure that includes sending the reply.

11 . The security appliance of claim 1 , wherein the timing of at least one of the plurality of instances of the reply is registered at a listener device distinct from the security appliance.

12 . A computer-implemented method comprising employing at least one hardware processor of a security appliance connected to a computer network comprising a plurality of interconnected client devices to:

engage in an attestation session with a selected client device of the plurality of client devices, the attestation session comprising:

transmitting an attestation probe to the selected client device, and

determining a result of the attestation session according to a timing of a plurality of instances of a reply to the attestation probe, each instance of the reply received from the selected client device via a distinct network route; and

in response to a failure of the attestation session, determine whether the failure is indicative of a computer security threat.

13 . The method of claim 12 , wherein determining the result of the attestation session comprises:

determining whether the plurality of instances of the reply match a reference reply pattern determined according to previous attestations of the selected client device;

in response, if yes, determining that the attestation session is successful; and

otherwise, determining that the attestation session has failed.

14 . The method of claim 13 , wherein the at least one hardware processor is configured to determine whether the plurality of instances of the reply match the reference reply pattern according to a count of instances of the reply received within a pre-determined time window following transmission of the attestation probe.

15 . The method of claim 13 , wherein the at least one hardware processor is configured to determine whether the plurality of instances of the reply match the reference reply pattern according to a likelihood for an instance of the reply to be received within a pre-determined time interval following transmission of the attestation probe.

16 . The method of claim 13 , wherein the at least one hardware processor is configured to determine whether the plurality of instances of the reply match the reference reply pattern according to a network route followed by a selected instance of the plurality of instances of the reply.

17 . The method of claim 13 , comprising transmitting the attestation probe to the selected client device using a one-to-one messaging protocol, and wherein the attestation probe is formulated to cause the selected client device to send the reply using a one-to-many messaging protocol.

18 . The method of claim 12 , wherein the attestation probe includes an encrypted session ID identifying the attestation session from among a plurality of other attestation sessions.

19 . The method of claim 18 , wherein the reply by the selected client device is formulated to include the session ID.

20 . The method of claim 18 , wherein the security appliance is configured to determine a result of the attestation session according to a value of the session ID included in the reply.

21 . The method of claim 12 , wherein the attestation probe is formulated to cause the selected client device to perform a service discovery procedure that includes transmitting the reply.

22 . The method of claim 12 , wherein the timing of at least one of the plurality of instances of the reply is registered at a listener device distinct from the security appliance.

23 . A non-transitory computer-readable medium storing instructions which, when executed by at least one hardware processor of a security appliance connected to a computer network comprising a plurality of interconnected client devices, cause the security appliance to:

engage in an attestation session with a selected client device of the plurality of client devices, the attestation session comprising:

transmitting an attestation probe to the selected client device, and

determining a result of the attestation session according to a timing of a plurality of instances of a reply to the attestation probe, each instance of the reply received from the selected client device via a distinct network route; and

in response to a failure of the attestation session, determine whether the failure is indicative of a computer security threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2024
From: GENGE, BELA; SZENTE, BALINT; TRIF, GEORGE M
To: BITDEFENDER IPR MANAGEMENT LTD.
Reel/Frame 069043/0830 →