IP Library Granted Patent US 11,956,277
Granted Patent B1
US 11,956,277 · App. 17/893,244 · Granted Apr 9, 2024

Zero network-profile cryptographically secure network port access

Inventors: Christopher Edward Delaney (Front Royal, VA); Chava Louis Jurado (Chantilly, VA); Carl Bailey Jacobs (Fredericksburg, VA)
Assignee: Cyber IP Holdings, LLC
H04L63/20H04L9/0643H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,956,277
App. No.
17/893,244
Granted
Apr 9, 2024
Kind
B1
Abstract

Systems and methods for protecting access to network ports on a server are provided herein. A system comprises a server configured to receive a data packet comprising a cryptoken corresponding to a network port address. The server is further configured to generate a plurality of cryptokens based on a plurality of timecodes, a network port configuration, and the destination address. The server generates a plurality of hashes based on the plurality of cryptokens. The server generates, based on a comparison of each of the plurality of cryptokens to the cryptoken, a rule to allow inbound connections to a first network port corresponding to the network port address.

Claims (37)

1. A system for protecting access to network ports on a server, the system comprising:

a server configured to:

receive a data packet comprising a cryptoken corresponding to a network port address;

generate, by each of a plurality of service instances, a plurality of cryptokens based on a plurality of timecodes, a network port configuration, and a destination address;

generate a plurality of hashes based on the plurality of cryptokens; and

generate, based on a comparison of each of hash the plurality of cryptokens to a hash of the cryptoken to identify a match, a rule for a firewall to allow inbound connections to a first network port associated with the service instance having generating a matching cryptotoken.

2. The system of claim 1 , wherein the plurality of timecodes are based on a system time and a timing interval that accounts for discrepancies between the server and a client.

3. The system of claim 1 , wherein the network port configuration further comprises a port number, a shared secret, and a predetermined period of time.

4. The system of claim 1 , wherein the network port configuration further comprises a protocol, wherein a number of the plurality of cryptokens is based on the protocol.

5. The system of claim 1 , wherein the server is further configured to:

receive the data packet at a second network port that is different from the first network port, wherein the first network port is not directly accessible by a client.

6. The system of claim 1 , further comprising:

a client configured to generate the cryptoken and the packet based on the cryptoken and send the data packet to the server.

7. The system of claim 5 , wherein the server is further configured to route traffic.

8. The system of claim 3 , wherein the rule is further based on the shared secret and the predetermined period of time.

9. A method for protecting access to network ports on a server, the method comprising:

receiving, by the server, a data packet comprising a cryptoken corresponding to a network port address;

generating, by each of a plurality of server instances being executed by the server, a plurality of cryptokens based on a plurality of timecodes, a network port configuration, and a destination address;

generating, by the server, a plurality of hashes based on the plurality of cryptokens; and

generating, by the server, based on a comparison of each of hash the plurality of cryptokens to a hash of the cryptoken to identify a match, a rule for a firewall to allow inbound connections to a first network port associated with the service instance having generating a matching cryptotoken.

10. The method of claim 9 , wherein the plurality of timecodes are based on a system time and a timing interval that accounts for discrepancies between the server and a client.

11. The method of claim 9 , wherein the network port configuration further comprises a port number, a shared secret, and a predetermined period of time.

12. The method of claim 9 , wherein the network port configuration further comprises a protocol, wherein a number of the plurality of cryptokens is based on the protocol.

13. The method of claim 9 , further comprising:

receiving, by the server, the data packet at a second network port that is different from the first network port, wherein the first network port is not directly accessible by a client.

14. The method of claim 9 , further comprising:

generating, by a client, the cryptoken and the packet based on the cryptoken and send the data packet to the server.

15. The method of claim 13 , further comprising routing, by the server, traffic.

16. The method of claim 11 , wherein the rule is further based on the shared secret and the predetermined period of time.

17. A non-transitory computer readable storage medium storing one or more programs configured to be executed by one or more data processors, the one or more programs comprising instructions protecting access to network ports on a server, the instructions comprising:

receiving, by the server, a data packet comprising a cryptoken corresponding to a network port address;

generating, by each of a plurality of server instances being executed by the server, a plurality of cryptokens based on a plurality of timecodes, a network port configuration, and a destination address;

generating, by the server, a plurality of hashes based on the plurality of cryptokens; and

generating, by the server, based on a comparison of each of hash the plurality of cryptokens to a hash of the cryptoken to identify a match, a rule for a firewall to allow inbound connections to a first network port associated with the service instance having generating a matching cryptotoken.

18. The non-transitory computer readable storage medium of claim 17 , wherein the plurality of timecodes are based on a system time and a timing interval that accounts for discrepancies between the server and a client.

19. The non-transitory computer readable storage medium of claim 17 , wherein the network port configuration further comprises a port number, a shared secret, and a predetermined period of time.

20. The non-transitory computer readable storage medium of claim 17 , wherein the network port configuration further comprises a protocol, wherein a number of the plurality of cryptokens is based on the protocol.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2022
From: BERRYVILLE HOLDINGS, LLC
To: CYBER IP HOLDINGS, LLC
Reel/Frame 060880/0695 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2022
From: DELANEY, CHRISTOPHER EDWARD; JURADO, CHAVA LOUIS; JACOBS, CARL BAILEY
To: BERRYVILLE HOLDINGS, LLC
Reel/Frame 060864/0410 →
Continuity (2)
Continuation 16874767 · May 15, 2020
Provisional Application 62857527 · Jun 5, 2019
Cited By (1)
US 12,407,725