IP Library › Granted Patent US 12,309,268
Granted Patent B2
US 12,309,268 · App. 17/324,876 · Granted May 20, 2025

Indicating network-based consent contracts using packet-level data

Inventors: Ian James Wells (San Jose, CA); Kyle Andrew Donald Mestery (Woodbury, MN)
Assignee: Cisco Technology, Inc.
H04L9/088H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,268
App. No.
17/324,876
Granted
May 20, 2025
Kind
B2
Abstract

Techniques for creating consent contracts for devices that indicate whether the devices consent to receiving network-based communications from other devices. Further, the techniques include enforcing the consent contracts such that network-based communications are either allowed or disallowed in the network-communications layer prior to the network communications reaching the devices. Rather than simply allowing a device to communicate with any other device over a network, the techniques described herein include building in consent for network-based communications where the consent is consulted at one or more points in a communication process to make informed decisions about network-based traffic.

Claims (100)

1. A method for identifying, from a packet, consent that indicates a destination device has consented to receiving network communications, the method comprising:

receiving, at a consent-contract system, from the destination device in a network, an indication that the destination device has consented to receiving network communications from a sending device;

based at least in part on the indication, distributing, by the consent-contract system, a private key to the sending device, wherein the private key is usable to create signatures on consent data indicating that the destination device has consented to communicate with the sending device;

based at least in part on the indication, distributing, by the consent-contract system, a public key to a network device located in the network, wherein the public key is usable to verify signatures of consent data that have been signed using private keys provided to sending devices with which the destination device has consented to communicate;

receiving, at the network device, the packet that is to be sent over the network, the packet being sent from the sending device and to the destination device;

identifying, from the packet, consent data indicating that the destination device has consented to receiving the packet from the sending device;

using the public key, determining whether the consent data was signed by the sending device using the private key; and

in response to determining that the consent data was signed using the private key, sending the packet to a next-hop network device in the network such that the packet is being transmitted to the destination device; or

in response to determining that the consent data was not signed using the private key, dropping the packet.

2. The method of claim 1 , further comprising:

identifying, from the packet, a destination address associated with the destination device;

sending, to the consent-contract system, a request for a particular public key associated with the destination address of the destination device; and

receiving the public key from the consent-contract system.

3. The method of claim 1 , further comprising determining that the consent data indicates that the destination device has consented to receiving network communications from the sending device.

4. The method of claim 1 , further comprising:

receiving, from the consent-contract system, an indication of a range of destination addresses associated with the public key;

storing an association between the public key and the range of destination addresses;

determining that a destination address is included in the range of destination addresses; and

selecting the public key to verify that the consent data was signed using the private key based at least in part on the association.

5. The method of claim 4 , further comprising:

receiving a second packet that has a second destination address associated with a second destination device;

identifying, from the second packet, second consent data that was signed using the private key;

determining that the second destination address is included in the range of destination addresses; and

selecting the public key to verify that the second consent data was signed using the private key based at least in part on the association.

6. The method of claim 1 , wherein the network device comprises at least one of:

a network router;

a network switch;

a network modem;

a network hub;

a network gateway; or

a network access point.

7. The method of claim 1 , further comprising:

receiving, at the consent-contract system, first data that indicates the consent by the destination device to receive the network communications from the sending device;

receiving, at the consent-contract system, second data that includes a request by the sending device to communicate with the destination device;

using the private key, signing the consent data that indicates the consent by the destination device; and

sending the consent data to the sending device.

8. A method comprising:

receiving, at a consent-contract system, from a destination device in a network, an indication that the destination device has consented to receiving network communications from a sending device;

based at least in part on the indication, distributing, by the consent-contract system, a private key to the sending device, wherein the private key is usable to create signatures on consent data indicating that the destination device has consented to communicate with the sending device;

based at least in part on the indication, distributing, by the consent-contract system, a public key to a network device located in the network, wherein the public key is usable to verify signatures of consent data that have been signed using private keys provided to sending devices with which the destination device has consented to communicate;

receiving, at the network device, a packet that is to be sent over the network, the packet being sent from the sending device and to the destination device;

identifying, from the packet, consent data indicating that the destination device has consented to receiving the packet from the sending device;

determining whether the consent data was issued by the consent-contract system based at least in part on a signature by the sending device on the consent data, wherein the consent-contract system manages consent contracts indicating consent for network communications between devices; and

in response to determining that the consent data was issued by the consent-contract system, sending the packet to a next-hop network device in the network such that the packet is being transmitted to the destination device; or

in response to determining that the consent data was not issued by the consent-contract system, dropping the packet.

9. The method of claim 8 , further comprising determining that the consent data indicates that the destination device has consented to receiving network communications from the sending device.

10. The method of claim 8 , wherein determining whether the consent data was issued by the consent-contract system includes:

using the public key, determining that the consent data was signed using the private key, wherein the public key was provided to the network device from the consent-contract system.

11. The method of claim 10 , further comprising:

identifying, from the packet, a destination address associated with the destination device;

sending, to the consent-contract system, a request for a particular public key associated with the destination address of the destination device; and

receiving the public key from the consent-contract system.

12. The method of claim 10 , further comprising:

receiving, from the consent-contract system, an indication of a range of destination addresses associated with the public key;

storing an association between the public key and the range of destination addresses;

determining that a destination address is included in the range of destination addresses; and

selecting the public key to verify that the consent data was signed using the private key based at least in part on the association.

13. The method of claim 12 , further comprising:

receiving a second packet that has a second destination address associated with a second destination device;

identifying, from the second packet, second consent data that was signed using the private key;

determining that the second destination address is included in the range of destination addresses; and

selecting the public key to verify that the second consent data was signed using the private key based at least in part on the association.

14. The method of claim 10 , further comprising:

receiving, at the consent-contract system, first data that indicates the consent by the destination device to receive the network communications from the sending device;

receiving, at the consent-contract system, second data that includes a request by the sending device to communicate with the destination device;

using the private key, signing the consent data that indicates the consent by the destination device; and

sending the consent data to the sending device.

15. A consent-contract system comprising:

one or more processors; and

one or more computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, from a destination device located in a network, an indication that the destination device has consented to receiving network communications from a sending device;

based at least in part on the indication, distributing a private key to the sending device, wherein the private key is usable to create signatures on consent data indicating that the destination device has consented to communicate with the sending device;

based at least in part on the indication, distributing a public key to a network device located in the network, wherein the public key is usable to verify signatures of consent data that have been signed using private keys provided to sending devices with which the destination device has consented to communicate;

receiving, at the network device, a packet that is to be sent over the network, the packet being sent from the sending device and to the destination device;

identifying, from the packet, consent data indicating that the destination device has consented to receiving the packet from the sending device;

verifying, using the public key, that the consent data was signed by the sending device using a private key;

determining that the destination device has consented to receiving the packet from the sending device based at least in part on the consent data being signed using the private key; and

sending the packet to a next-hop network device in the network such that the packet is being transmitted to the destination device.

16. The consent-contract system of claim 15 , the operations further comprising:

identifying, from the packet, a destination address associated with the destination device;

receiving, from the network device, a request for a particular public key associated with the destination address of the destination device; and

sending, to the network device, the particular public key from the consent-contract system.

17. The consent-contract system of claim 15 , further comprising determining that the consent data indicates that the destination device has consented to receiving network communications from the sending device.

18. The consent-contract system of claim 15 , the operations further comprising:

receiving an indication of a range of destination addresses associated with the public key;

storing an association between the public key and the range of destination addresses;

determining that a destination address is included in the range of destination addresses; and

selecting the public key to verify that the consent data was signed using the private key based at least in part on the association.

19. The consent-contract system of claim 18 , the operations further comprising:

receiving, at the network device, a second packet that has a second destination address associated with a second destination device;

identifying, from the second packet, second consent data that was signed using the private key;

determining that the second destination address is included in the range of destination addresses; and

selecting the public key to verify that the second consent data was signed using the private key based at least in part on the association.

20. The consent-contract system of claim 15 , wherein the network device comprises at least one of:

a network router;

a network switch;

a network modem;

a network hub;

a network gateway; or

a network access point.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: WELLS, IAN JAMES; MESTERY, KYLE ANDREW DONALD
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056291/0802 →
Continuity (2)
Continuation In Part 17183825 · Feb 24, 2021
Related Publication 20220271920A1 · Aug 25, 2022
References Cited (88)
US 6145084A · Zuili et al. · 2000 [cited by applicant]
US 9027136B2 · Be'ery · 2015 [cited by examiner]
US 9934544B1 · Whitfield et al. · 2018 [cited by applicant]
US 10153907B2 · Xu et al. · 2018 [cited by applicant]
US 10565666B2 · Veeramachaneni et al. · 2020 [cited by applicant]
US 10644889B1 · Govindaraj et al. · 2020 [cited by applicant]
US 10834141B1 · Chud · 2020 [cited by applicant]
US 20020069278A1 · Forsöw · 2002 [cited by applicant]
US 20020120866A1 · Mitchell et al. · 2002 [cited by applicant]
US 20020188656A1 · Patton · 2002 [cited by applicant]
US 20040088550A1 · Maste · 2004 [cited by applicant]
US 20050132060A1 · Mo et al. · 2005 [cited by applicant]
US 20070038765A1 · Dunn · 2007 [cited by applicant]
US 20080222307A1 · Bhakta et al. · 2008 [cited by applicant]
US 20090147684A1 · Majidi-Ahy · 2009 [cited by applicant]
US 20090172138A1 · Wang et al. · 2009 [cited by applicant]
US 20090245130A1 · Bing · 2009 [cited by applicant]
US 20100217856A1 · Falkena · 2010 [cited by applicant]
US 20110072137A1 · de oca et al. · 2011 [cited by applicant]
US 20120151557A1 · Ahmed et al. · 2012 [cited by applicant]
US 20120185578A1 · Perkuhn et al. · 2012 [cited by applicant]
US 20120221652A1 · Sainio et al. · 2012 [cited by applicant]
US 20120331530A1 · Chickering et al. · 2012 [cited by applicant]
US 20130151386A1 · Malaviya · 2013 [cited by applicant]
US 20130174223A1 · Dykeman · 2013 [cited by applicant]
US 20140096207A1 · Gilbert et al. · 2014 [cited by applicant]
US 20140136267A1 · Ristock · 2014 [cited by applicant]
US 20140281503A1 · Mills et al. · 2014 [cited by applicant]
US 20140351368A1 · Dudziak et al. · 2014 [cited by applicant]
US 20150067814A1 · Bu · 2015 [cited by applicant]
US 20150188887A1 · Thomas · 2015 [cited by examiner]
US 20150264040A1 · Schneider · 2015 [cited by applicant]
US 20150304448A1 · Mathew et al. · 2015 [cited by applicant]
US 20160006685A1 · Kitamuya · 2016 [cited by applicant]
US 20160112208A1 · Williams et al. · 2016 [cited by applicant]
US 20160191243A1 · Manning · 2016 [cited by applicant]
US 20160197935A1 · Jamison et al. · 2016 [cited by applicant]
US 20160226859A1 · Sondhi et al. · 2016 [cited by applicant]
US 20160330287A1 · Smith · 2016 [cited by applicant]
US 20170063557A1 · Chalmandrier-Perna · 2017 [cited by applicant]
US 20170063935A1 · Lim · 2017 [cited by applicant]
US 20180007178A1 · Subhraveti · 2018 [cited by applicant]
US 20180013793A1 · Belamaric et al. · 2018 [cited by applicant]
US 20180247385A1 · Whitfield et al. · 2018 [cited by applicant]
US 20190005210A1 · Wiederspohn et al. · 2019 [cited by applicant]
US 20190052994A1 · Dar · 2019 [cited by applicant]
US 20190114630A1 · Torkelson et al. · 2019 [cited by applicant]
US 20190188411A1 · Kroutik · 2019 [cited by applicant]
US 20190297114A1 · Panchalingam et al. · 2019 [cited by applicant]
US 20190349402A1 · Shukla et al. · 2019 [cited by applicant]
US 20190392171A1 · Barday et al. · 2019 [cited by applicant]
US 20200042625A1 · Balaraman et al. · 2020 [cited by applicant]
US 20200059786A1 · Farag · 2020 [cited by applicant]
US 20200228486A1 · Park et al. · 2020 [cited by applicant]
US 20200250295A1 · Padmanabhan · 2020 [cited by applicant]
US 20200280443A1 · Simons · 2020 [cited by applicant]
US 20210044976A1 · Avetisov et al. · 2021 [cited by applicant]
US 20210135865A1 · Joseph · 2021 [cited by examiner]
US 20220027522A1 · Kasheshian et al. · 2022 [cited by applicant]
US 20220058706A1 · Gordon · 2022 [cited by examiner]
US 20220210147A1 · Galvin et al. · 2022 [cited by applicant]
US 20220271947A1 · Mestery et al. · 2022 [cited by applicant]
US 20220272044A1 · Wells et al. · 2022 [cited by applicant]
US 20220272102A1 · Mestery et al. · 2022 [cited by applicant]
EP 2556646A1 · 2013 [cited by applicant]
JP 202074188A · 2020 [cited by applicant]
WO WO2019153095A1 · 2019 [cited by applicant]
Enck, “TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones”, Jun. 2014, ACM, pp. 1-29 (Year: 2014). [cited by examiner]
Enck, “TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones”, Jun. 2014, ACM, Vo. 32, pp . 1-25 (Year: 2014). [cited by examiner]
Office Action for U.S. Appl. No. 17/183,900, mailed on Sep. 21, 2023, Kyle Andrew Donald Mestery, “Creating Network-Based Consent Contracts”, 19 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,977, mailed on Aug. 17, 2022, Wells, “Enforcing Consent Contracts to Manage Network Traffic”, 12 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,825, mailed on Aug. 9, 2022, Mestery, “Centralized Consent Vendors for Managing Network-Based Consent Contracts ”, 26 Pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,825, mailed on Feb. 15, 2023, Kyle Andrew Donald Mestery, “Centralized Consent Vendors for Managing Network-Based Consent Contracts”, 29 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,900, malled on Apr. 11, 2023, Kyle Mestery, “Creating Network-Based Consent Contracts”, 21 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,977, mailed on Feb. 21, 2023, Wells, “Enforcing Consent Contracts to Manage Network Traffic”, 14 Pages. [cited by applicant]
Copy of the PCT Search Report and Written Opinion mailed Jun. 7, 2022 for PCT application No. PCT/US2022/017698, 9 pages. [cited by applicant]
Alicherry, et al., “DIPLOMA: Distributed Policy Enforcement Architecture for MANETs”, 2010 Fourth International Conference on Network and System Security, 10 pages. [cited by applicant]
Alicherry, et al., “Misuse Detection in Consent-Based Networks”, Springer-Verlag Berlin Heidelberg 2011, 19 pages. [cited by applicant]
Naous, et al., “Verifying and enforcing network paths with ICING”, ACM CoNEXT 2011, Dec. 6-9, 2011, 14 pages. [cited by applicant]
Rosenberg et al., “A Framework for Consent-Based Communications in the Session Initiation Protocol (SIP)”, Oct. 2008, 62 pages. [cited by applicant]
Rosenberg, et al., “Requirements for Consent-Based Communications in the Session Initiation Protocol (SIP)”, Apr. 2006, 16 pages. [cited by applicant]
Seehra, et al., “A policy framework for the future Internet”, 2009, 6 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,977, mailed on Sep. 7, 2023, Ian James Wells, “Enforcing Consent Contracts to Manage Network Traffic”, 14 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,825, mailed on Jun. 27, 2023, Kyle Andrew Donald Mestery, “Centralized Consent Vendors for Managing Network-Based Consent Contracts”, 33 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,900, mailed on Jul. 24, 2024, Mestery, (Creating Network-Based Consent Contracts) 18 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,825, mailed on Jan. 5, 2024, Kyle Andrew Donald Mestery, “Centralized Consent Vendors for Managing Network-Based Consent Contracts”, 39 pages. [cited by applicant]
PCT International Preliminary Report on Patentability mailed Nov. 30, 2023 for PCT Application No. PCT/US2022/029769, 9 pages. [cited by applicant]
Office Action for U.S. Appl. No. 17/183,825, dated Aug. 29, 2024, 42 pages. [cited by applicant]