IP Library › Granted Patent US 12,418,407
Granted Patent B2
US 12,418,407 · App. 17/954,971 · Granted Sep 16, 2025

Management, diagnostics, and security for network communications

Inventor: Nalini Joshi Elkins (Carmel Valley, CA)
Assignee: Outside the Stacks, Inc.
H04L9/0825H04L9/0894H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,407
App. No.
17/954,971
Granted
Sep 16, 2025
Kind
B2
Abstract

A system and method securely and selectively provide visibility along a communication path in end-to-end communications, while ensuring security of the transmission, and while further ensuring that unauthorized persons cannot view network packets. A separate parallel channel is used to provide visibility into data in transit to authorized parties, without revealing such data to unauthorized parties. In at least one embodiment, the separate parallel channel is implemented using a secure group messaging platform. In addition, all needed equipment is integrated in the end-to-end connection across layers and protocols into the secure messaging group. Secure, scalable messaging groups can be based on a ratchet tree protocol so as to guarantee forward as well as post-compromise security.

Claims (86)

1. A computer-implemented method for securely providing visibility along an electronic communication path between two endpoints, comprising:

establishing a secure separate channel in parallel to the electronic communication path;

collecting information about at least one communication taking place between the two endpoints;

encrypting the collected information;

making the collected information available via the secure separate channel;

obtaining a first portion of an authentication key;

storing the first portion of the authentication key in a first secure storage device; and

authenticating at least one party in order to provide the at least one party with access to the secure separate channel;

wherein authenticating the at least one party comprises:

retrieving the stored first portion of the authentication key;

obtaining a second portion of the authentication key associated with a session;

obtaining a key package from a second secure storage device;

generating a hash result from a subset of data obtained from the communication taking place between the two endpoints;

combining the first portion of the authentication key with the obtained key package and the generated hash result, to reconstruct the authentication key; and

using the reconstructed authentication key to authenticate the at least one party and to decrypt the encrypted collected information.

2. The method of claim 1 , wherein establishing a secure separate channel comprises establishing a group via a secure group messaging platform.

3. The method of claim 2 , wherein the group comprises a WhatsApp group.

4. The method of claim 1 , wherein retrieving the stored first portion of the authentication key, obtaining the second portion of the authentication key, obtaining the key package, and combining the first portion of the authentication key with the obtained key package and the generated hash result to reconstruct the authentication key are performed by a secret agent component.

5. The method of claim 1 , wherein authenticating the at least one party using the authentication key comprises authenticating the at least one party using at least one selected from the group consisting of:

an X-509 certificate; and

thumb printing based on characteristics of at least one device used by the at least one party.

6. The method of claim 1 , wherein providing the at least one party with access to the secure separate channel comprises:

receiving a request for information from the at least one party;

encrypting the requested information;

transmitting the encrypted information; and

decrypting the encrypted information.

7. The method of claim 6 , wherein encrypting and decrypting the information are performed using a ratchet tree protocol.

8. The method of claim 1 , wherein the first secure storage device comprises a hardware security module.

9. A non-transitory computer-readable medium for securely providing visibility along an electronic communication path between two endpoints, comprising instructions stored thereon, that when performed by a processor, perform the steps of:

establishing a secure separate channel in parallel to the electronic communication path;

collecting information about at least one communication taking place between the two endpoints;

encrypting the collected information;

making the collected information available via the secure separate channel;

obtaining a first portion of an authentication key;

causing the first portion of the authentication key to be stored in a first secure storage device; and

authenticating at least one party in order to provide the at least one party with access to the secure separate channel;

wherein authenticating the at least one party comprises:

retrieving the stored first portion of the authentication key;

obtaining a second portion of the authentication key associated with a session;

obtaining a key package from a second secure storage device;

generating a hash result from a subset of data obtained from the communication taking place between the two endpoints;

combining the first portion of the authentication key with the obtained key package and the generated hash result, to reconstruct the authentication key; and

using the reconstructed authentication key to authenticate the at least one party and to decrypt the encrypted collected information.

10. The non-transitory computer-readable medium of claim 9 , wherein establishing a secure separate channel comprises establishing a group via a secure group messaging platform.

11. The non-transitory computer-readable medium of claim 10 , wherein the group comprises a WhatsApp group.

12. The non-transitory computer-readable medium of claim 9 , wherein retrieving the stored first portion of the authentication key, obtaining the second portion of the authentication key, obtaining the key package, and combining the first portion of the authentication key with the obtained key package and the generated hash result to reconstruct the authentication key are performed by a secret agent component.

13. The non-transitory computer-readable medium of claim 9 , wherein authenticating the at least one party using the authentication key comprises authenticating the at least one party using at least one selected from the group consisting of:

an X-509 certificate; and

thumb printing based on characteristics of at least one device used by the at least one party.

14. The non-transitory computer-readable medium of claim 9 , wherein providing the at least one party with access to the secure separate channel comprises:

receiving a request for information from the at least one party;

encrypting the requested information;

transmitting the encrypted information; and

decrypting the encrypted information.

15. The non-transitory computer-readable medium of claim 14 , wherein encrypting and decrypting the information are performed using a ratchet tree protocol.

16. The non-transitory computer-readable medium of claim 9 , wherein the first secure storage device comprises a hardware security module.

17. A system for securely providing visibility along an electronic communication path between two endpoints, comprising:

a plurality of communication nodes, configured to establish a secure separate channel in parallel to the electronic communication path;

a capture device, configured to collect, encrypt, and store information about at least one communication taking place between the two endpoints and further configured to make the collected information available via the secure separate channel; and

a first secure storage device;

an authentication module, communicatively coupled to the first secure storage device and to the capture device, configured to:

obtain a first portion of an authentication key;

cause the first portion of the first portion of the authentication key to be stored in the first secure storage device; and

authenticate at least one party in order to provide the at least one party with access to the secure separate channel;

wherein authenticating the at least one party comprises:

retrieving the stored first portion of the authentication key;

obtaining a second portion of the authentication key associated with a session;

obtaining a key package from a second secure storage device;

generating a hash result from a subset of data obtained from the communication taking place between the two endpoints;

combining the first portion of the authentication key with the obtained key package and the generated hash result, to reconstruct the authentication key; and

using the reconstructed authentication key to authenticate the at least one party and to decrypt the encrypted collected information.

18. The system of claim 17 , wherein establishing a secure separate channel comprises establishing a group via a secure group messaging platform.

19. The system of claim 18 , wherein the group comprises a WhatsApp group.

20. The system of claim 17 , further comprising:

a secret agent component;

wherein retrieving the stored first portion of the authentication key, obtaining the second portion of the authentication key, obtaining the key package, and combining the first portion of the authentication key with the obtained key package and the generated hash result to reconstruct the authentication key are performed by the secret agent component.

21. The system of claim 17 , wherein authenticating the at least one party using the authentication key comprises authenticating the at least one authorized party using at least one selected from the group consisting of:

an X-509 certificate; and

thumb printing based on characteristics of at least one device used by the at least one party.

22. The system of claim 17 , wherein providing the at least one party with access to the secure separate channel comprises:

receiving a request for information from the at least one party;

encrypting the requested information;

transmitting the encrypted information; and

decrypting the encrypted information.

23. The system of claim 22 , wherein encrypting and decrypting the information are performed using a ratchet tree protocol.

24. The system of claim 17 , wherein the first secure storage device comprises a hardware security module.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2025
From: INSIDE PRODUCTS, INC.
To: OUTSIDE THE STACKS, INC.
Reel/Frame 070722/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2022
From: ELKINS, NALINI JOSHI
To: INSIDE PRODUCTS, INC.
Reel/Frame 061245/0500 →
Continuity (2)
Provisional Application 63252066 · Oct 4, 2021
Related Publication 20230108261A1 · Apr 6, 2023
References Cited (7)
US 10999260B1 · Silvestri · 2021 [cited by examiner]
US 11082217B1 · Donlan · 2021 [cited by examiner]
US 20180324155A1 · Leavy · 2018 [cited by examiner]
US 20190068564A1 · Putatunda · 2019 [cited by examiner]
US 20200213311A1 · Saha · 2020 [cited by examiner]
Hoyland, Jonathan “An Analysis of TLS 1.3 and its use in Composite Protocols”, 2018, pp. 1-273. [cited by applicant]
Polk, Tim et al., “Addressing Visibility Challenges With TLS 1.3”, May 2021, pp. 1-14. [cited by applicant]