IP Library Granted Patent US 11,265,249
Granted Patent B2
US 11,265,249 · App. 16/350,200 · Granted Mar 1, 2022

Method for using authenticated requests to select network routes

Inventor: John William Hayes (Reno, NV)
Assignee: BLUE ARMOR TECHNOLOGIES, LLC
H04L45/745H04L45/02H04L45/20H04L45/42H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,265,249
App. No.
16/350,200
Granted
Mar 1, 2022
Kind
B2
Abstract

The present invention enables the selection of network routes based on a combination of traditional route table entries, identity policy information, and trust level information determined dynamically for each network session. This enables a network operator to apply different policies to network entities presenting differing identity credentials. It also allows network operators to block access to networks and network resources when identity credentials are not provided or are unauthorized.

Claims (43)

1. A method performed by a group of devices comprising the steps of:

providing a network;

providing a network resource; said network resource being connected to said network;

said network resource including an address;

providing a Trust Router; said Trust Router being connected to said network; said Trust Router including a route table; said route table having at least one route table entry to a network resource;

providing a network client; said network client being connected to said network;

conveying, by said network client, a resource request over said network to said Trust Router;

said resource request including the address of said network resource;

said resource request containing an authentication object;

said authentication object including identity information;

providing an Identity Policy Group; said Identity Policy Group being located within said Trust Router;

providing a Trust Level; said Trust Level being received by said Trust Router;

using said identity in said authentication object to authenticate said network client;

using, by said Trust Router, said authentication object to determine an Identity Policy Group and said Trust Level;

selecting a route table entry that matches the destination address of said resource request and that matches said Identity Policy Group and that matches said Trust Level;

identifying, by said Trust Router, a forwarding table entry that matches said destination address of said resource request and said Identity Policy Group and said Trust Level;

conveying, by said trust router, said resource request to said network resource via a next hop information in said selected route table entry; and

using said Identity Policy Group and said destination address to select a route for said resource request to said address of said network resource.

2. The method as recited in claim 1 , in which:

said resource request is a TCP-SYN packet.

3. The method as recited in claim 1 , in which:

said authentication object contained in said resource request is a statistical object.

4. The method as recited in claim 1 , in which:

said resource request is an IP packet.

5. The method as recited in claim 1 , in which:

said Trust Level is employed for the purpose of changing access to network resources without changing route table entries.

6. A method comprising the steps of: providing a network;

providing a network resource; said network resource being connected to said network;

said network resource including an address;

providing a Trust Router; said Trust Router being connected to said network; said Trust Router including a route table; said route table including a plurality of route table entries; each of said route table entries including an Identity Policy Group and a Trust Level;

providing a network client; said network client being connected to said network;

conveying, by said network client, a resource request over said network to said Trust Router;

said resource request containing an authentication object; and including a destination address;

said authentication object including identity information;

using, by said Trust Router, said authentication object to authenticate said network client and determining the associated Identity Policy Group and said associated Trust Level;

determining that none of said plurality of route table entries in said route table matches said destination address of said resource request and matches said Identity Policy Group and matches said Trust Level; and

discarding said resource request.

7. The method as recited in claim 6 , in which:

said resource request is a TCP-SYN packet.

8. The method as recited in claim 6 , in which:

said authentication object contained in said resource request is a statistical object.

9. The method as recited in claim 6 , in which:

said resource request is a IP packet.

Assignments (4)
CHANGE OF NAME Recorded Dec 14, 2022
From: BLUE ARMOR TECHNOLOGIES, LLC
To: INVISINET TECHNOLOGIES, LLC
Reel/Frame 062127/0638 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2020
From: BLACKRIDGE TECHNOLOGY INTERNATIONAL, INC.; BLACKRIDGE HOLDINGS, INC; BLACKRIDGE RESEARCH INC INC.
To: BLUE ARMOR TECHNOLOGIES LLC
Reel/Frame 054711/0521 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2019
From: BLACKRIDGE TECHNOLOGY HOLDINGS, INC
To: BLACKRIDGE RESEARCH, INC
Reel/Frame 049608/0895 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2019
From: HAYES, JOHN W.
To: BLACKRIDGE TECHNOLOGY HOLDINGS, INC.
Reel/Frame 048201/0731 →
Continuity (2)
Continuation In Part 14999317 · Apr 22, 2016
Related Publication 20210314260A1 · Oct 7, 2021