IP Library Granted Patent US 12,388,900
Granted Patent B2
US 12,388,900 · App. 18/432,848 · Granted Aug 12, 2025

Universal session protocol

Inventor: Jonathon Anderson (Oswego, IL)
H04L67/146H04L9/3213H04L67/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,900
App. No.
18/432,848
Filed
Feb 5, 2024
Granted
Aug 12, 2025
Kind
B2
Art Unit
2446
USPC
709/227
Abstract

The invention comprises a universal session protocol configured to initiate, authenticate, and manage the session of an application data stream. The universal session protocol governs the interaction between sending applications and sending agents as well as receiving applications and receiving agents to establish authenticated data streams between applications or systems.

Claims (14)

1. A method of transmitting data through a data stream between a sending application having a sending agent and a receiving application having a receiving agent comprising the steps of:

the sending agent sending a message to the receiving agent stating an intention to establish a data stream, specifying the receiving application as a target application, and the sending agent enumerating authentication protocols supported by the sending agent, wherein the message includes either an invalid identity token or is missing an identity token;

the receiving agent determining that the target application is the application served by the receiving agent;

the receiving agent determining that the application data stream requires authentication;

the receiving agent determining that there is an invalid identity token or missing identity token;

the receiving agent determining an authentication protocol that is mutually supported by the receiving agent and the sending agent;

the receiving agent sending an authentication requirement message to sending agent, indicating the authentication protocol to be used to establish sending agent identity;

the sending agent adds invalid or missing authentication credentials to the data stream using the authentication protocol;

the receiving agent rejecting the credentials using the authentication protocol; and

the sending agent and receiving agent aborting the connection attempt.

2. The method of transmitting data through a data stream of claim 1 wherein the steps of the sending agent sending a message to the receiving agent stating the intention to connect, specifying the receiving application as the target application, and the sending agent enumerating authentication protocols supported by the sending agent further comprises the step of initiating a connection to the receiving agent.

3. The method of transmitting data through a data stream of claim 2 wherein the steps of the receiving agent determining that the specified target application is the application served by the receiving agent, the receiving agent determining that the application data stream requires authentication, the receiving agent determining that the identity token provided by the sending agent is invalid or missing, and receiving agent selecting a mutually supported authentication protocol according to what is enumerated by the sending agent and supported by the receiving agent comprise the steps of authentication protocol negotiation.

4. The method of transmitting data through a data stream of claim 3 wherein the steps of the receiving agent sending a message to the sending agent indicating the negotiated authentication protocol and the requirement to authenticate comprise the steps of initiating authentication.

5. The method of transmitting data through a data stream of claim 4 , the sending agent adding invalid or missing authentication credentials to the data stream according to the negotiated authentication protocol, and the receiving agent determining that the credentials are invalid or missing according to the negotiated authentication protocol comprise the steps of authentication failure.

Continuity (3)
Continuation 18219386 · Jul 7, 2023
Provisional Application 63420417 · Oct 28, 2022
Related Publication 20240179216A1 · May 30, 2024
References Cited (28)
US 10110585B2 · Ghafourifar et al. · 2018 [cited by applicant]
US 10205803B1 · Sharifi Mehr · 2019 [cited by examiner]
US 10771435B2 · Goldschlag et al. · 2020 [cited by applicant]
US 11159511B1 · Geusz · 2021 [cited by examiner]
US 11411958B2 · Pularikkal et al. · 2022 [cited by applicant]
US 11470100B1 · Christian · 2022 [cited by applicant]
US 11496461B2 · Tokuma et al. · 2022 [cited by applicant]
US 20030043991A1 · Kriechbaum et al. · 2003 [cited by applicant]
US 20060085862A1 · Witt et al. · 2006 [cited by applicant]
US 20090210707A1 · De Lutiis et al. · 2009 [cited by applicant]
US 20120060210A1 · Baker · 2012 [cited by examiner]
US 20140279358A1 · Rosenberg · 2014 [cited by examiner]
US 20150032863A1 · Sinha · 2015 [cited by examiner]
US 20160140663A1 · Greenberg et al. · 2016 [cited by applicant]
US 20160358108A1 · Sadovsky · 2016 [cited by examiner]
US 20170063946A1 · Quan et al. · 2017 [cited by applicant]
US 20190238546A1 · Petersen et al. · 2019 [cited by applicant]
US 20200027470A1 · Thurman · 2020 [cited by examiner]
US 20210306320A1 · Squire · 2021 [cited by examiner]
US 20220014553A1 · Dutta · 2022 [cited by applicant]
US 20220029842A1 · Onoue · 2022 [cited by examiner]
US 20220058037A1 · Ye · 2022 [cited by examiner]
US 20220343319A1 · Murao · 2022 [cited by examiner]
US 20220345491A1 · Luo et al. · 2022 [cited by applicant]
Decusatis et al., Implementing Zero Trust Cloud Networks with Transport Access Control and First Packet Authentication, 2016 IEEE International Conference on Smart Cloud (SmartCloud), Nov. 18, 2016. [cited by applicant]
Zaheer et al., eZTrust: Network-Independent Zero-Trust Perimeterization for Microservices, Apr. 3, 2019. [cited by applicant]
Sarkar et al., Security of Zero Trust Networks in Cloud Computing: A Comparative Review, Sustainability, Sep. 7, 2022, MDPI. [cited by applicant]
Eidle et al., Autonomic Security for Zero Trust Networks, 2017 IEEE 8th Annual Ubiquitous Computing, Electronics and Mobile Communication Conference (UEMCON), Oct. 19, 2017. [cited by applicant]