IP Library › Granted Patent US 12,567,966
Granted Patent B2
US 12,567,966 · App. 18/345,837 · Granted Mar 3, 2026

Endpoint validation security

Inventors: John G. Andrews (Cleveland Heights, OH); John P. Keyerleber (Richmond Heights, OH)
Assignee: SCATR CORP
H04L9/3213H04L9/0819
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,567,966
App. No.
18/345,837
Granted
Mar 3, 2026
Kind
B2
Abstract

Examples of the disclosure provide for a scatter network device. In some examples, the scatter network device includes a non-transitory memory, at least one processor, and a key exchange application stored in the non-transitory memory. When executed by the at least one processor, the key exchange application transmits a key exchange request to a first network endpoint, the key exchange request including an identifier of the scatter network device, receives a key exchange response from the first network endpoint, the key exchange response including a set of one-time-use endpoint validation tokens (EVTs) uniquely associated with the identifier of the scatter network device, and transmits an authenticated message to a second network endpoint, the authenticated message including a first of the set of one-time-use EVTs concatenated with an encrypted data portion.

Claims (56)

1 . A scatter network device, comprising:

a non-transitory memory;

at least one processor; and

a key exchange application stored in the non-transitory memory that, when executed by the at least one processor:

transmits a key exchange request to a first network endpoint, the key exchange request including an identifier of the scatter network device;

receives a key exchange response from the first network endpoint, the key exchange response including a set of one-time-use endpoint validation tokens (EVTs) uniquely associated with the identifier of the scatter network device;

transmits an authenticated message to a second network endpoint, the authenticated message including a first of the set of one-time-use EVTs concatenated with an encrypted data portion;

responsive to a number of EVTs remaining in the set of one-time-use EVTs decreasing to be less than a threshold number, transmit a second request to the second network endpoint, the second request including the identifier of the scatter network device; and

receive a second response from the second network endpoint, the second response including a second set of one-time-use EVTs uniquely associated with the identifier of the scatter network device.

2 . The scatter network device of claim 1 , wherein each EVT of the set of one-time-use EVTs includes an encrypted representation of the identifier of the scatter network device concatenated with a variable counter value.

3 . The scatter network device of claim 2 , wherein the encrypted data portion is symmetrically encrypted with an encryption key accessible to the second network endpoint with reference to the identifier of the scatter network device.

4 . The scatter network device of claim 1 , wherein executing the key exchange application further causes the processor to:

transmit a second authenticated message to the second network endpoint, the second authenticated message including a second of the set of one-time-use EVTs concatenated with a second encrypted data portion.

5 . The scatter network device of claim 1 , wherein executing the key exchange application further causes the processor to transmit a second authenticated message to a third network endpoint, the second authenticated message including a first of the second set of one-time-use EVTs concatenated with a second encrypted data portion.

6 . The scatter network device of claim 1 , wherein executing the key exchange application further causes the processor to transmit a second authenticated message to the second network endpoint in a same communication channel as the processor transmitted the authenticated message, the second authenticated message including a second encrypted data portion.

7 . A method of secure data routing, comprising:

receiving, at a first network endpoint, a key exchange request from a client device, the key exchange request including an identifier of the client device;

generating a set of one-time-use endpoint validation tokens (EVTs) uniquely associated with the identifier of the client device;

generating a key exchange response including the set of one-time-use EVTs;

transmitting, to the client device, the key exchange response;

receiving, at a second network endpoint and in a first communication channel, an authenticated message from the client device, the authenticated message including a first of the set of one-time-use EVTs concatenated with an encrypted data portion;

decrypting the first of the set of one-time-use EVTs to obtain the identifier of the client device;

associating the identifier of the client device with the first communication channel;

performing a database lookup based on the identifier of the client device to obtain a symmetric encryption key according to which the encrypted data portion is encrypted; and

decrypting the encrypted data portion according to the symmetric encryption key.

8 . The method of claim 7 , wherein each EVT of the set of one-time-use EVTs includes an encrypted representation of the identifier of the client device concatenated with a variable counter value.

9 . The method of claim 7 , further comprising:

receiving, at the second network endpoint and in the first communication channel, a second authenticated message from the client device, the second authenticated message including a second encrypted data portion;

performing a database lookup based on the association of the identifier of the client device to the first communication channel to obtain the symmetric encryption key according to which the second encrypted data portion is encrypted; and

decrypting the second encrypted data portion according to the symmetric encryption key.

10 . The method of claim 7 , further comprising:

receiving, at the second network endpoint and in a second communication channel, a second authenticated message from the client device, the second authenticated message including a second of the set of one-time-use EVTs concatenated with a second encrypted data portion;

performing a database lookup based on the second of the set of one-time-use EVTs to obtain the identifier of the client device;

performing a database lookup based on the identifier of the client device to obtain the symmetric encryption key according to which the second encrypted data portion is encrypted; and

decrypting the second encrypted data portion according to the symmetric encryption key.

11 . A computing device, comprising:

a non-transitory memory;

at least one processor; and

a key exchange application stored in the non-transitory memory that, when executed by the at least one processor:

receives an authenticated message in a first communication channel from a client device, the authenticated message including a symmetrically encrypted data portion and at least one endpoint validation token (EVT) uniquely associated with an identifier of the client device;

associates the identifier of the client device with the first communication channel;

performs a database lookup based on the at least one EVT to obtain the identifier of the client device;

performs a database lookup based on the identifier of the client device to obtain a symmetric encryption key according to which the encrypted data portion is encrypted;

decrypts the encrypted data portion according to the symmetric encryption key;

receives a second authenticated message from the client device, the second authenticated message including a second encrypted data portion;

performs a database lookup based on the association of the identifier of the client device to the first communication channel to obtain the symmetric encryption key according to which the second encrypted data portion is encrypted; and

decrypts the second encrypted data portion according to the symmetric encryption key.

12 . The computing device of claim 11 , wherein the at least one EVT includes an encrypted representation of the identifier of the client device concatenated with a variable counter value.

13 . The computing device of claim 11 , wherein the authenticated message includes a second EVT, and wherein executing the key exchange application further causes the processor to:

receive, at the second network endpoint and in a second communication channel, a second authenticated message from the client device, the second authenticated message including the second EVT concatenated with a second encrypted data portion;

perform a database lookup based on the second EVT to obtain the identifier of the client device;

perform a database lookup based on the identifier of the client device to obtain the symmetric encryption key according to which the second encrypted data portion is encrypted; and

decrypt the second encrypted data portion according to the symmetric encryption key.

14 . The computing device of claim 11 , wherein the authenticated message includes a plurality of single-use EVTs including the at least one EVT.

15 . The computing device of claim 11 , wherein the at least one EVT is a timed-use EVT.

16 . The computing device of claim 11 , wherein the at least one EVT expires after a programmed number of transmissions by the client device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2024
From: SCATR, LLC
To: SCATR, CORP
Reel/Frame 068117/0434 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: ANDREWS, JOHN G.; KEYERLEBER, JOHN P.
To: SCATR LLC
Reel/Frame 067436/0718 →
Continuity (1)
Related Publication 20250007718A1 · Jan 2, 2025
References Cited (140)
US 6502135B1 · Munger et al. · 2002 [cited by applicant]
US 6765866B1 · Wyatt · 2004 [cited by applicant]
US 6990111B2 · Lemoff et al. · 2006 [cited by applicant]
US 7382782B1 · Ferguson et al. · 2008 [cited by applicant]
US 7697528B2 · Parry et al. · 2010 [cited by applicant]
US 7782782B1 · Ferguson et al. · 2010 [cited by applicant]
US 7895348B2 · Twitchell, Jr. · 2011 [cited by applicant]
US 7984495B1 · Aravind · 2011 [cited by applicant]
US 8274980B2 · Sato et al. · 2012 [cited by applicant]
US 8358658B2 · Flynn et al. · 2013 [cited by applicant]
US 8416686B2 · Ferguson et al. · 2013 [cited by applicant]
US 8924716B2 · Miyabayashi · 2014 [cited by examiner]
US 8955110B1 · Twitchell, Jr. · 2015 [cited by applicant]
US 9116734B1 · Twitchell, Jr. et al. · 2015 [cited by applicant]
US 9185046B2 · Ferguson et al. · 2015 [cited by applicant]
US 9225699B2 · Biradar et al. · 2015 [cited by applicant]
US 9241026B2 · Twitchell, Jr. · 2016 [cited by applicant]
US 9495194B1 · Twitchell, Jr. et al. · 2016 [cited by applicant]
US 9535805B2 · Ananthanarayanan et al. · 2017 [cited by applicant]
US 9629063B2 · Brown et al. · 2017 [cited by applicant]
US 9794797B2 · Hoffberg · 2017 [cited by applicant]
US 10356061B2 · Fiske · 2019 [cited by applicant]
US 10432526B2 · Gafni et al. · 2019 [cited by applicant]
US 10469375B2 · Twitchell, Jr. · 2019 [cited by applicant]
US 10541907B2 · Twitchell, Jr. et al. · 2020 [cited by applicant]
US 10637685B2 · Goel et al. · 2020 [cited by applicant]
US 10686729B2 · Sindhu et al. · 2020 [cited by applicant]
US 10715327B1 · Ramanujan · 2020 [cited by examiner]
US 10826711B2 · Barry · 2020 [cited by applicant]
US 10826876B1 · Sinn et al. · 2020 [cited by applicant]
US 10833972B2 · Vaughan et al. · 2020 [cited by applicant]
US 10904367B2 · Goel et al. · 2021 [cited by applicant]
US 10965586B2 · Goel et al. · 2021 [cited by applicant]
US 11153276B1 · Keyerleber · 2021 [cited by applicant]
US 11171934B2 · Fiske · 2021 [cited by applicant]
US 11178262B2 · Goel et al. · 2021 [cited by applicant]
US 11184147B2 · Ghorbani · 2021 [cited by applicant]
US 11381557B2 · Kim et al. · 2022 [cited by applicant]
US 11469922B2 · Goel et al. · 2022 [cited by applicant]
US 11533617B2 · Mihelich et al. · 2022 [cited by applicant]
US 11558422B2 · Twitchell, Jr. et al. · 2023 [cited by applicant]
US 11601359B2 · Goel et al. · 2023 [cited by applicant]
US 11637694B2 · Islamov · 2023 [cited by applicant]
US 11777839B2 · Sindhu et al. · 2023 [cited by applicant]
US 11805127B1 · Sundar et al. · 2023 [cited by applicant]
US 11895015B1 · Budhia et al. · 2024 [cited by applicant]
US 12021972B2 · Wang et al. · 2024 [cited by applicant]
US 12120028B1 · Andrews et al. · 2024 [cited by applicant]
US 12335160B2 · Andrews et al. · 2025 [cited by applicant]
US 20010050914A1 · Akahane et al. · 2001 [cited by applicant]
US 20010054158A1 · Jarosz · 2001 [cited by applicant]
US 20020191797A1 · Perlman · 2002 [cited by applicant]
US 20030112755A1 · McDysan · 2003 [cited by applicant]
US 20040103205A1 · Larson et al. · 2004 [cited by applicant]
US 20060008082A1 · Gluck et al. · 2006 [cited by applicant]
US 20070217424A1 · Kim et al. · 2007 [cited by applicant]
US 20100149988A1 · Matsubara et al. · 2010 [cited by applicant]
US 20110179136A1 · Twitchell, Jr. · 2011 [cited by applicant]
US 20110271096A1 · Bharrat et al. · 2011 [cited by applicant]
US 20120204032A1 · Wilkins · 2012 [cited by examiner]
US 20140115341A1 · Robertson · 2014 [cited by examiner]
US 20150326603A1 · Deisinger et al. · 2015 [cited by applicant]
US 20150350245A1 · Twitchell, Jr. et al. · 2015 [cited by applicant]
US 20150350246A1 · Bergman · 2015 [cited by applicant]
US 20160065370A1 · Le Saint et al. · 2016 [cited by applicant]
US 20160119291A1 · Zollinger · 2016 [cited by examiner]
US 20160255054A1 · Wan et al. · 2016 [cited by applicant]
US 20170019256A1 · Rhelimi · 2017 [cited by applicant]
US 20170033925A1 · DeNeut · 2017 [cited by examiner]
US 20170126626A1 · Datta et al. · 2017 [cited by applicant]
US 20170149740A1 · Mansour · 2017 [cited by examiner]
US 20170331794A1 · Lokman et al. · 2017 [cited by applicant]
US 20170372048A1 · Liu et al. · 2017 [cited by applicant]
US 20180316598A1 · Twitchell, Jr. · 2018 [cited by applicant]
US 20180375663A1 · Le Saint et al. · 2018 [cited by applicant]
US 20190014092A1 · Malek et al. · 2019 [cited by applicant]
US 20190294464A1 · Twitchell, Jr. et al. · 2019 [cited by applicant]
US 20190373458A1 · Dandekar et al. · 2019 [cited by applicant]
US 20200014619A1 · Shelar et al. · 2020 [cited by applicant]
US 20200154272A1 · Uy et al. · 2020 [cited by applicant]
US 20200195439A1 · Suresh · 2020 [cited by examiner]
US 20200211002A1 · Steinberg · 2020 [cited by examiner]
US 20200213111A1 · Leavy et al. · 2020 [cited by applicant]
US 20200213151A1 · Srivatsan et al. · 2020 [cited by applicant]
US 20200226258A1 · Nix · 2020 [cited by examiner]
US 20200259640A1 · Leavy et al. · 2020 [cited by applicant]
US 20210051146A1 · Stolbikov · 2021 [cited by examiner]
US 20210105301A1 · Anderson et al. · 2021 [cited by applicant]
US 20210144004A1 · Gray et al. · 2021 [cited by applicant]
US 20210168138A1 · Paruchuri · 2021 [cited by applicant]
US 20210184854A1 · Pizot · 2021 [cited by examiner]
US 20210297351A1 · Vegesna et al. · 2021 [cited by applicant]
US 20210328779A1 · Ruan · 2021 [cited by applicant]
US 20210328976A1 · Leavy et al. · 2021 [cited by applicant]
US 20210352471A1 · Hallock · 2021 [cited by examiner]
US 20210360026A1 · Anderson et al. · 2021 [cited by applicant]
US 20220247678A1 · Atwal et al. · 2022 [cited by applicant]
US 20220392286A1 · Elrad et al. · 2022 [cited by applicant]
US 20230006993A1 · Bilgin · 2023 [cited by examiner]
US 20230097712A1 · Sullivan et al. · 2023 [cited by applicant]
US 20230164086A1 · York et al. · 2023 [cited by applicant]
US 20230188347A1 · Sarin · 2023 [cited by examiner]
US 20230198914A1 · Ranjan et al. · 2023 [cited by applicant]
US 20230208748A1 · Goel et al. · 2023 [cited by applicant]
US 20240007367A1 · Demchenko · 2024 [cited by applicant]
US 20240028367A1 · Mathew et al. · 2024 [cited by applicant]
US 20240214803A1 · Dandekar et al. · 2024 [cited by applicant]
US 20240275596A1 · Stolbikov · 2024 [cited by examiner]
US 20240380726A1 · Ban et al. · 2024 [cited by applicant]
CN 112333152A · 2021 [cited by applicant]
EP 3651407A1 · 2024 [cited by applicant]
WO 2018160863A1 · 2018 [cited by applicant]
WO 2023134844A1 · 2023 [cited by applicant]
Notice of Allowance dated Jun. 22, 2021, U.S. Appl. No. 16/683,146, filed Nov. 13, 2019. [cited by applicant]
Office Action dated Apr. 12, 2023, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Final Office Action dated Jul. 24, 2023, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Keyerleber, John P., et al., “Secure Data Routing and Randomization,” filed Sep. 22, 2021, U.S. Appl. No. 17/481,914. [cited by applicant]
Andrews, John G., et al., “Secure Data Routing With Channel Resiliency,” filed Mar. 31, 2023, U.S. Appl. No. 18/194,413. [cited by applicant]
Andrews, John G., et al., “Out of Band Key Exchange,” filed Jun. 30, 2023, U.S. Appl. No. 18/345,819. [cited by applicant]
Andrews, John G., et al., “Network Traffic Obfuscation,” filed Jun. 30, 2023, U.S. Appl. No. 18/345,829. [cited by applicant]
Andrews, John G., et al., “Secure Data Routing With Dynamic Packet Spoofing ,” filed Jun. 30, 2023, U.S. Appl. No. 18/345,847. [cited by applicant]
“Andrews, John G., et al., ““Secure Data Routing Andrandomization in Windows,”” filed Jul. 28, 2023, U.S. Appl. No. 18/361,721.” [cited by applicant]
Notice of Allowance dated Jun. 11, 2024, U.S. Appl. No. 18/194,413, filed Mar. 31, 2023. [cited by applicant]
Office Action dated Nov. 27, 2024, U.S. Appl. No. 18/345,829, filed Jun. 30, 2023. [cited by applicant]
Syed, et al., “Zero Trust Architecture (ZTA): A Comprehensive Survey”, IEEE Access—Digital Object Identifier, vol. 10, 37 pages, 2022. [cited by applicant]
Shu, et al., “Secure Data Collection in Wireless Sensor Networks Using Randomized Dispersive Routes”, IEEE Transactions on Mobile Computing, vol. 9, No. 7, Jul. 2010, 14 pages. [cited by applicant]
Andrews, John G., et al., “Secure Data Routing With Channel Resiliency,” filed Sep. 11, 2024, U.S. Appl. No. 11/882,552. [cited by applicant]
Notice of Allowance dated Feb. 21, 2025, U.S. Appl. No. 18/345,847, filed Jun. 30, 2023. [cited by applicant]
Office Action dated Apr. 23, 2025, U.S. Appl. No. 18/361,721, filed Jul. 28, 2023. [cited by applicant]
Office Action dated May 7, 2025, U.S. Appl. No. 18/345,819, filed Jun. 30, 2023. [cited by applicant]
Advisory Action dated Oct. 5, 2023, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Examiner's Answer to Appeal Brief dated Feb. 23, 2024, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]
Office Action dated Feb. 13, 2024, U.S. Appl. No. 18/194,413, filed Mar. 31, 2023. [cited by applicant]
Keyerleber, John P., “Machine Learning Driven Network Traffic Obfuscation,” filed Jan. 24, 2024, U.S. Appl. No. 18/421,960. [cited by applicant]
Keyerleber, et al., “Optimizing Network Traffic Obfuscation Based on Network Performance Using Reinforcement Learning,” filed Jan. 24, 2024, U.S. Appl. No. 18/421,965. [cited by applicant]
Keyerleber, et al., “Optimizing Network Traffic Obfuscation Based on Aggregated Network Performance,” filed Jan. 24, 2024, Application No. Jan. 24, 2024. [cited by applicant]
Notice of Allowance dated May 20, 2025, U.S. Appl. No. 18/345,829, filed Jun. 30, 2023. [cited by applicant]
Notice of Allowance dated Sep. 3, 2025, U.S. Appl. No. 18/345,819, filed Jun. 30, 2023. [cited by applicant]
Notice of Allowance dated Dec. 9, 2025, U.S. Appl. No. 18/361,721, filed Jul. 28, 2023. [cited by applicant]
Decision on Appeal dated Nov. 18, 2025, U.S. Appl. No. 17/481,914, filed Sep. 22, 2022. [cited by applicant]