IP Library › Granted Patent US 12,438,854
Granted Patent B2
US 12,438,854 · App. 18/653,582 · Granted Oct 7, 2025

Communicating securely between network nodes

Inventors: Jeffrey Jay Johnson (Logan, UT); Robert Foster Houghton (Pocatello, ID)
Assignee: Utah State University
H04L63/0428H04L67/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,854
App. No.
18/653,582
Granted
Oct 7, 2025
Kind
B2
Abstract

For communicating securely between network nodes, a method transmits a port knock sequence comprising ordered empty protocol packets from an origination node to a destination Internet Protocol (IP) address of a destination node. The port knock sequence encodes at least one vocabulary phrase. The method transmits the length of the at least one vocabulary phrase to first and second helper nodes. The method generates a corresponding substitute phrase for each at least one vocabulary phrase through communication between the first helper node and the second helper node. The method receives the corresponding substitute phrase for each at least one vocabulary phrase at the origination node and the destination node. The method generates a node nonce based on the at least one corresponding substitute phrase. The method securely communicates between the origination node and the destination node using the node nonce.

Claims (57)

1. A method comprising:

transmitting, by use of a processor, a port knock sequence comprising ordered empty protocol packets from an origination node to a destination Internet Protocol (IP) address of a destination node, wherein the origination node comprises an origination IP address, the destination IP address comprises a destination port number, and the port knock sequence encodes at least one vocabulary phrase;

transmitting the length of the at least one vocabulary phrase from the origination node to a first helper node;

transmitting the length of the at least one vocabulary phrase from the destination node to a second helper node;

generating a corresponding substitute phrase for each at least one vocabulary phrase through communication between the first helper node and the second helper node;

receiving the corresponding substitute phrase for each at least one vocabulary phrase from the first helper node at the origination node;

receiving the corresponding substitute phrase for each at least one vocabulary phrase from the second helper node at the destination node;

generating a node nonce based on the at least one corresponding substitute phrase at the origination node and based on the at least one corresponding substitute phrase at the destination node; and

securely communicating between the origination node and the destination node using the node nonce.

2. The method of claim 1 , the method further comprising:

sequentially establishing secure communications for a plurality of nodes comprising origination nodes and corresponding destination nodes between a start node and an end node; and

securely communicating between the start node and the end node using the node nonce for each origination node and destination node pair.

3. The method of claim 2 , the method further comprising:

communicating a path secret between the start node and the end node using the node nonce for each origination node and destination node pair; and

securely communicating between the start node and the end node using the path secret.

4. The method of claim 1 , wherein the node nonce comprises the at least one vocabulary phrase and the corresponding substitute phrase.

5. The method of claim 1 , wherein the node nonce is generated from the at least one vocabulary phrase and the corresponding substitute phrase.

6. The method of claim 1 , wherein a new node nonce is regenerated from a new at least one vocabulary phrase and corresponding new substitute phrase.

7. The method of claim 6 , wherein the new node nonce is regenerated after each specified number of communications between the origination node and the destination node.

8. The method of claim 7 , wherein the specified number of communications is one.

9. The method of claim 1 , the destination port number is protected by a firewall.

10. The method of claim 1 , wherein the protocol packets are selected from the group consisting of Transmission Control Protocol (TCP) packets, User Datagram Protocol (UPD), Internet Control Message Protocol (ICMP) packets, QUIC packets, Datagram Congestion Control Protocol (DCCP) packets, and Stream Control Transmission Protocol (SCTP) packets.

11. The method of claim 1 , wherein the destination IP address is not accessible to the origination node.

12. An apparatus comprising:

a processor executing code stored by a memory to perform:

transmitting a port knock sequence comprising ordered empty protocol packets from an origination node to a destination Internet Protocol (IP) address of a destination node, wherein the origination node comprises an origination IP address, the destination IP address comprises a destination port number, and the port knock sequence encodes at least one vocabulary phrase;

transmitting the length of the at least one vocabulary phrase from the origination node to a first helper node;

transmitting the length of the at least one vocabulary phrase from the destination node to a second helper node;

generating a corresponding substitute phrase for each at least one vocabulary phrase through communication between the first helper node and the second helper node;

receiving the corresponding substitute phrase for each at least one vocabulary phrase from the first helper node at the origination node;

receiving the corresponding substitute phrase for each at least one vocabulary phrase from the second helper node at the destination node;

generating a node nonce based on the at least one corresponding substitute phrase at the origination node and based on the at least one corresponding substitute phrase at the destination node; and

securely communicating between the origination node and the destination node using the node nonce.

13. The apparatus of claim 12 , the processor further:

sequentially establishing secure communications for a plurality of nodes comprising origination nodes and corresponding destination nodes between a start node and an end node; and

securely communicating between the start node and the end node using the node nonce for each origination node and destination node pair.

14. The apparatus of claim 13 , the processor further:

communicating a path secret between the start node and the end node using the node nonce for each origination node and destination node pair; and

securely communicating between the start node and the end node using the path secret.

15. The apparatus of claim 12 , wherein the node nonce comprises the at least one vocabulary phrase and the corresponding substitute phrase.

16. The apparatus of claim 12 , wherein the node nonce is generated from the at least one vocabulary phrase and the corresponding substitute phrase.

17. The apparatus of claim 12 , wherein a new node nonce is regenerated from a new at least one vocabulary phrase and corresponding new substitute phrase.

18. A computer program product comprising a non-transitory computer readable storage medium storing code executable by processor to perform:

transmitting a port knock sequence comprising ordered empty protocol packets from an origination node to a destination Internet Protocol (IP) address of a destination node, wherein the origination node comprises an origination IP address, the destination IP address comprises a destination port number, and the port knock sequence encodes at least one vocabulary phrase;

transmitting the length of the at least one vocabulary phrase from the origination node to a first helper node;

transmitting the length of the at least one vocabulary phrase from the destination node to a second helper node;

generating a corresponding substitute phrase for each at least one vocabulary phrase through communication between the first helper node and the second helper node;

receiving the corresponding substitute phrase for each at least one vocabulary phrase from the first helper node at the origination node;

receiving the corresponding substitute phrase for each at least one vocabulary phrase from the second helper node at the destination node;

generating a node nonce based on the at least one corresponding substitute phrase at the origination node and based on the at least one corresponding substitute phrase at the destination node; and

securely communicating between the origination node and the destination node using the node nonce.

19. The computer program product of claim 18 , the processor further:

sequentially establishing secure communications for a plurality of nodes comprising origination nodes and corresponding destination nodes between a start node and an end node; and

securely communicating between the start node and the end node using the node nonce for each origination node and destination node pair.

20. The computer program product of claim 19 , the processor further:

communicating a path secret between the start node and the end node using the node nonce for each origination node and destination node pair; and

securely communicating between the start node and the end node using the path secret.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2024
From: JOHNSON, JEFFREY JAY; HOUGHTON, ROBERT FOSTER
To: UTAH STATE UNIVERSITY
Reel/Frame 067919/0292 →
Continuity (2)
Provisional Application 63463828 · May 3, 2023
Related Publication 20240372839A1 · Nov 7, 2024
References Cited (8)
US 11647003B2 · Soman · 2023 [cited by examiner]
US 20060168136A1 · Bethlehem · 2006 [cited by examiner]
US 20070162861A1 · Friedlander · 2007 [cited by examiner]
US 20160094523A1 · Houghton · 2016 [cited by examiner]
US 20170223045A1 · Claes · 2017 [cited by examiner]
US 20240380737A1 · Brown · 2024 [cited by examiner]
US 20250175341A1 · Stolbikov · 2025 [cited by examiner]
J. Johnson, R. F. Houghton and A. Jensen, “Communication without Connection,” 2022 Intermountain Engineering, Technology and Computing (IETC), Orem, UT, USA, 2022, pp. 1-3, doi: 10.1109/IETC54973.2022.9796946. Published… [cited by examiner]