IP Library › Granted Patent US 12,034,765
Granted Patent B1
US 12,034,765 · App. 18/387,051 · Granted Jul 9, 2024

Securing network access with legacy computers

Inventor: Mordecai Barkan (Palo Alto, CA)
H04L63/145H04L63/0428H04L63/1475
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,034,765
App. No.
18/387,051
Granted
Jul 9, 2024
Kind
B1
Abstract

Off-the-shelf computing systems, even in the presence of malware infecting those computing systems, are used to access securely other network computing systems—Secured sites. The use may take shape in various ways and the potential use of two, three, or more computing systems is described. The use in a malware-infected environment is advantageous and exposes hacking attempts in real-time.

Claims (35)

1. A method for secure communication with a network node hosting a site by utilizing multiple computing devices, comprising the steps of:

configuring the site of the network node hosting the site to enable a user secured communication session by utilizing the multiple computing devices;

initiating the multiple computing devices and managing communication sessions between the user and the network node hosting the site;

utilizing multiple computing devices by the user to establish secure communication channels with the network node hosting the site;

splitting a session initiated by the user with the site of the network node hosting a site into multiple distinct sessions, where each session is carried out by one of the multiple computing devices used by the user to support a single session with the site of the network node hosting a site;

ensuring secure transmission of messages between each of the user's multiple computing devices and the network node hosting the site, maintaining data confidentiality and integrity during transmission by segregating and avoiding eavesdropping of the user communication of a combined session; and

implementing a security mechanism that, in the event of malware infecting a computing device of the multiple computing devices utilized by the user, restricts the malware's access to only a portion of the user's session on the infected computing device, thereby safeguarding the integrity of the overall communication between the user and the site of the network node hosting a site across the multiple computing devices.

2. The method according to claim 1 , further comprises the steps:

establishing communication between the multiple computing devices and the network node hosting a site, wherein said communication involves the utilization of a masking technique;

transmitting at least one mask from the network node hosting the site to a first computing device over the network;

integrating sensitive information with the transmitted mask to the first computing device by the user by means of a second computing device;

transmitting the integrated sensitive information with the mask from the second computing device to the network node hosting the site, using the second computing device, thereby preventing exposure of the sensitive information to malware that may infect the second computing device while preventing access by the first computing device to the integrated sensitive information; and

extracting the sensitive information at the network node hosting the site by removing the mask sent to the first computing device from the integrated sensitive information received from the second computing device.

3. The method according to claim 1 further comprises:

validating the operation at the network node hosting the site configured to carry out such operation by:

evaluating messages received from a first computing device, wherein the mask is integrated with seeded information;

evaluating messages received from the second computing system, wherein sensitive information is integrated with the mask; and

retrieving the sensitive information on the site and storing the seeded message for detection of hacking attempts.

4. The method according to claim 1 , wherein the site of the network node hosting the site is configured to detect hacking attempts by:

identifying messages that include messages received from the first computing system, where the mask is integrated with seeded information; and

identifying messages that include messages received from the second computing system, where sensitive information is integrated with the mask.

5. The method according to claim 1 , further comprising:

using more than two computing systems simultaneously and out-of-band communication; and

hardening and further securing user communication with the site of the network node hosting the site by splitting session portions between the multiple computing devices.

6. The method according to claim 1 , wherein:

at least two matched users communicate over the network with the site of the network node hosting the site;

the site of the network node hosting the site serves as a proxy; and

pairing, account opening, accessibility functions, and sharing of information are applied securely between the users and the site of the network node hosting the site.

7. A site hosted by a network node, to enable secure communication with the site by a user utilizing multiple computing devices, configured:

to initiate and manage a main session by the user;

allowing for multiple computing devices to access the site and be used by the user;

each of said multiple computing devices configured to establish secure communication channels with the network node hosting the site;

splitting the main session initiated by the user into multiple distinct secondary sessions, with each of the secondary sessions handled by one of the multiple computing devices utilized by the user to support a single session with the site of the network node hosting a site;

securing transmission of messages between each of the multiple computing devices and the site hosted by the network node, ensuring data confidentiality and integrity during transmission by segregating and avoiding eavesdropping of the user communication of a combined session; and

in the event of malware infecting one of the multiple computing devices utilized by the user, the malware access is restricted to only the secondary session carried by one of the multiple computing devices utilized by the user, thereby safeguarding the integrity of the overall communication between the user and the site hosted by the network node hosting a site across the multiple computing devices.

Continuity (1)
Provisional Application 63528582 · Jul 24, 2023
Cited By (4)
US 12,461,801 US 12,537,829 US 12,683,988 US 12,717,939