IP Library Granted Patent US 11,645,538
Granted Patent B2
US 11,645,538 · App. 17/177,513 · Granted May 9, 2023

Physical layer authentication of electronic communication networks

Inventors: William Charles Suski (Mount Pleasant, SC); Christopher Alan Card (Sykesville, MD); Brian Richard Few (Sykesville, MD)
Assignee: APPLIED ENGINEERING CONCEPTS, INC.
G06N3/084G06F18/214G06F18/2411G06F18/24765G06N3/045G06V10/764
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,645,538
App. No.
17/177,513
Granted
May 9, 2023
Kind
B2
Abstract

A network authentication system can be configured for sampling a plurality of signal samples from a device on a network, providing the plurality of signal samples to a first machine-learned model that is configured to determine a device fingerprint based at least in part on the plurality of signal samples, and providing the device fingerprint to a second machine-learned model that is configured to classify the device based at least in part on the device fingerprint.

Claims (33)

1. A computer-implemented method for performing device authentication based on physical communication signal characteristics, the method comprising:

obtaining, by a computing system comprising one or more computing devices, a plurality of physical signal samples associated with physical communication signals of a device on or attempting to connect to a network;

processing, by the computing system, the plurality of physical signal samples with a first machine-learned model to generate a device fingerprint for the device based at least in part on the plurality of physical signal samples; and

processing, by the computing system, the device fingerprint with a second machine-learned model to generate an authentication classification for the device based at least in part on the device fingerprint.

2. The computer-implemented method of claim 1 , wherein the first machine-learned model and the second machine-learned model have been trained separately.

3. The computer-implemented method of claim 1 , wherein the first machine-learned model has been trained to perform a proxy classification task in which the first machine-learned model classifies input samples as being associated with a plurality of classes which respectively correspond to a plurality of observed devices.

4. The computer-implemented method of claim 1 , wherein the authentication classification comprises a determination of whether the device on or attempting to connect to the network is in-distribution.

5. The computer-implemented method of claim 1 , wherein the physical communication signals comprise electrical voltages transmitted over a wired connection.

6. The computer-implemented method of claim 1 , wherein the physical communication signals comprise electromagnetic emanations of the device transmitted over a wireless connection.

7. The computer-implemented method of claim 1 , further comprising: adjusting, by the computing device, access to the network for the device based at least in part on the authentication classification.

8. The computer-implemented method of claim 7 , wherein adjusting, by the computing system, access to the network for the device comprises providing restricted access in response to a negative authentication classification or providing a level of authenticated access in response to a positive authentication classification.

9. The computer-implemented method of claim 1 , wherein the device fingerprint comprises a collection of a plurality of classification scores respectively associated with a plurality of known devices.

10. The computer-implemented method of claim 1 , wherein the authentication classification comprises a binary output.

11. The computer-implemented method of claim 1 , wherein the authentication classification comprises a scalar output.

12. The computer-implemented method of claim 1 , wherein obtaining, by the computing system, the plurality of physical signal samples from the device on or attempting to connect to the network comprises:

obtaining, by the computing system, one or more physical signals; and

processing, by the computing system, the one or more signals with an analog-to-digital converter to generate the plurality of physical signal samples.

13. The computer-implemented method of claim 1 , wherein the first machine-learned model comprises a convolutional neural network.

14. The computer-implemented method of claim 1 , wherein the second machine-learned model comprises a support vector machine model.

15. A computing system for network authentication, the system comprising:

one or more sensors configured to collect a plurality of physical signal samples associated with physical communication signals of a device on a network;

one or more non-transitory computer-readable media that collectively store:

a first machine-learned model configured to process the plurality of physical signal samples to generate a device fingerprint for the device based at least in part on the plurality of physical signal samples; and

a second machine-learned model configured to process the device fingerprint to generate an authentication classification for the device based at least in part on the device fingerprint; and

a controller configured to control one or more ports of a network switch or router of the network based on the authentication classification for the device.

16. The computing system of claim 15 , wherein the one or more sensors are physically included within the network switch or router.

17. The computing system of claim 15 , wherein the one or more non-transitory computer-readable media are physically included within the controller.

18. The computing system of claim 17 , wherein the controller is physically included within the network switch or router.

19. One or more non-transitory computer readable media that collectively store instructions that, when executed by one or more processors, cause a computing system to perform operations, the operations comprising:

obtaining, by the computing system, a plurality of physical signal samples from a device on a network;

processing, by the computing system, the plurality of physical signal samples with a first machine-learned model to determine a device fingerprint based at least in part on the plurality of physical signal samples; and

processing, by the computing system, the device fingerprint with a second machine-learned model to generate a classification for the device based at least in part on the device fingerprint, wherein the classification comprises an authentication classification.

20. The one or more non-transitory computer readable media of claim 19 , wherein the first machine-learned model comprises a flattening sub-model.

Assignments (2)
CONFIRMATORY LICENSE Recorded Sep 2, 2022
From: APPLIED ENGINEERING CONCEPTS, INCORPORATED
To: UNITED STATES DEPARTMENT OF ENERGY
Reel/Frame 061375/0198 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2022
From: SUSKI, WILLIAM CHARLES; CARD, CHRISTOPHER ALAN; FEW, BRIAN RICHARD
To: APPLIED ENGINEERING CONCEPTS, INC.
Reel/Frame 059149/0947 →
Continuity (2)
Provisional Application 63011539 · Apr 17, 2020
Related Publication 20210326644A1 · Oct 21, 2021