IP Library Granted Patent US 12,598,078
Granted Patent B2
US 12,598,078 · App. 18/110,051 · Granted Apr 7, 2026

Network access using hardware-based security

Inventors: Dipak Kr. Das (Bangalore, IN); Avni Bhupendrakumar Wala (Bangalore, IN); John Frederick Dawson (Pittsburgh, PA); Hariprasad Nekkare Gururaj (Bangalore, IN); Anirban Debnath (Bengaluru, IN)
Assignee: Sophos Limited
H04L9/3247H04L9/3213H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,078
App. No.
18/110,051
Filed
Feb 15, 2023
Granted
Apr 7, 2026
Kind
B2
Art Unit
2439
USPC
713/168
Abstract

An endpoint device uses hardware-based security to authenticate to an enterprise network. For example, an endpoint device such as network hardware or an end user device can request authentication in order to join an enterprise network that is managed by a computing platform such as a threat management facility. In one aspect, an authenticator at the computing platform sends a challenge payload in response to the request from the endpoint device. The endpoint device may then sign the challenge payload with a hardware-based security system that was bound to the endpoint device at manufacture, and return a response to the authenticator that includes the signed challenge payload. The authenticator can cryptographically validate the response and generate an authentication token for use by the endpoint device when joining the enterprise network.

Claims (50)

1 . A method for operating a computing platform to authenticate an endpoint device at the computing platform, the method comprising:

receiving a request from the endpoint device for authentication at the computing platform, wherein the endpoint device is a network device for an enterprise network managed by the computing platform and the computing platform is a threat management facility;

generating a data packet;

signing the data packet with a key, thereby providing a first digital signature;

sending a challenge payload to a hardware-based security system on the endpoint device, the challenge payload including the data packet and the first digital signature;

receiving a response to the challenge payload from the endpoint device, the response including an endpoint device certificate, the challenge payload, and a second digital signature for the challenge payload from the endpoint device;

validating the response to the challenge payload by:

validating a certificate chain for the endpoint device certificate,

validating the second digital signature for the challenge payload, and

validating an expiry of the data packet in the challenge payload;

in response to validating the challenge payload, sending an authentication token to the endpoint device for access to security services of the computing platform for the enterprise network;

in response to an unsuccessful validation of the response to the challenge payload, generating a security alert to address a failed authentication; and

in response to an expiration of the authentication token, reauthenticating the endpoint device without a refresh token by transmitting a second challenge payload to the hardware-based security system on the endpoint device.

2 . The method of claim 1 wherein validating the second digital signature for the challenge payload includes validating the second digital signature with a public key associated with the endpoint device certificate.

3 . The method of claim 1 , further comprising sending an alert to the endpoint device in response to a first failure to validate the certificate chain or a second failure to validate the second digital signature.

4 . The method of claim 1 , wherein the method further includes receiving a reauthentication request at the computing platform when the authentication token has expired.

5 . The method of claim 1 , wherein the computing platform includes a cloud computing platform.

6 . The method of claim 1 wherein validating the response to the challenge payload includes validating a second expiry of one or more digital signatures in the certificate chain for the endpoint device certificate.

7 . The method of claim 1 , wherein the authentication token allows access to a partial list of at least one of services, network locations, and resources.

8 . A method for operating an endpoint device to authenticate the endpoint device at a computing platform, the method comprising:

sending a request for authentication to the computing platform, wherein the computing platform is a threat management facility;

receiving a challenge payload from the computing platform;

fetching an endpoint device certificate from a hardware-based security system on the endpoint device, wherein the endpoint device is a network device for an enterprise network managed by the computing platform;

signing the challenge payload with a digital signature from the hardware-based security system;

sending a challenge response to the computing platform based on the challenge payload, the challenge response including the endpoint device certificate, the challenge payload, and the digital signature;

receiving an authentication token for access to security services of the computing platform for the enterprise network from the computing platform in response to the challenge response;

authenticating the endpoint device at the computing platform with the authentication token;

in response to an expiration of the authentication token, reauthenticating the endpoint device without a refresh token by transmitting a second challenge payload to the hardware-based security system on the endpoint device; and

accessing services of the computing platform from the endpoint device with the authentication token.

9 . The method of claim 8 , wherein the challenge payload includes a random data segment and an expiration date.

10 . The method of claim 9 , wherein the challenge payload includes a second digital signature for the random data segment from the computing platform.

11 . The method of claim 10 , further comprising validating the computing platform at the endpoint device with the second digital signature and the random data segment.

12 . The method of claim 8 , wherein sending the request for authentication includes sending a reauthentication request in response to an expiration of a prior authentication token.

13 . The method of claim 8 , wherein sending the request for authentication includes sending the request for authentication in response to a boot up of the endpoint device.

14 . The method of claim 8 , wherein the authentication token has a valid time of an hour or less.

15 . The method of claim 8 , further comprising sending a second request to the computing platform in response to an expiration of the authentication token.

16 . The method of claim 8 , wherein the hardware-based security system includes a trusted platform module, the method further comprising installing the trusted platform module and the endpoint device certificate in a trusted platform module chip during manufacturing of the endpoint device.

17 . The method of claim 8 , wherein the endpoint device includes security hardware for the enterprise network.

18 . The method of claim 8 , wherein the endpoint device includes at least one of a gateway, a firewall, a wireless access point, and a switch.

19 . A system comprising:

an endpoint device connected to an enterprise network, wherein the endpoint device is a network device for the enterprise network; and

a computing platform including an authenticator embodied in computer executable code stored in a non-transitory computer readable medium for managing access by the endpoint device to the computing platform, wherein the computing platform is a threat management facility, and wherein the authenticator is configured:

to receive a request from the endpoint device for authentication at the computing platform,

to generate a random data segment,

to send the random data segment to the endpoint device,

to receive a response data packet from the endpoint device,

to determine a validity of the response data packet with one or more cryptographic validation tests of the response data packet,

to send an authentication token to the endpoint device for access to security services of the computing platform for the enterprise network if the response data packet passes the one or more cryptographic validation tests, and

in response to an expiration of the authentication token, to reauthenticate the endpoint device without a refresh token by transmitting a second challenge payload to a hardware-based security system on the endpoint device.

20 . The system of claim 19 , wherein the authenticator is configured to allow access to a partial list of at least one of services, network locations, and resources based on the authentication token.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: NEKKARE GURURAJ, HARIPRASAD; DEBNATH, ANIRBAN
To: SOPHOS LIMITED
Reel/Frame 065147/0250 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2023
From: DAS, DIPAK KR.; WALA, AVNI BHUPENDRAKUMAR; DAWSON, JOHN FREDERICK
To: SOPHOS LIMITED
Reel/Frame 062889/0845 →
Priority Claims (2)
IN 202211062663 · Nov 2, 2022 · national
IN 202211062663 · Nov 15, 2022 · national
Continuity (1)
Related Publication 20240146536A1 · May 2, 2024
References Cited (25)
US 9853977B1 · Laucius · 2017 [cited by examiner]
US 9979550B1 · Fiedler · 2018 [cited by examiner]
US 10154023B1 · Nossik · 2018 [cited by examiner]
US 11836254B2 · Lewis · 2023 [cited by examiner]
US 20090113533A1 · Genty · 2009 [cited by examiner]
US 20140123124A1 · Gray · 2014 [cited by examiner]
US 20200320199A1 · Sheth · 2020 [cited by examiner]
US 20210036867A1 · Attard · 2021 [cited by examiner]
US 20210103439A1 · Mellqvist · 2021 [cited by examiner]
US 20210288954A1 · Saravanan · 2021 [cited by examiner]
US 20220045848A1 · Hulshof · 2022 [cited by examiner]
US 20220141019A1 · Thomas · 2022 [cited by examiner]
US 20220365788A1 · Koo · 2022 [cited by examiner]
US 20230009739A1 · Ponnuswamy · 2023 [cited by examiner]
US 20230216693A1 · Singh · 2023 [cited by examiner]
Juhyeng Han et al., Toward Scaling Hardware Security Module for Emerging Cloud Services, Oct. 27, 2019, ACM, pp. 1-6. (Year: 2019). [cited by examiner]
Nico Mexis et al., A Lightweight Architecture for Hardware-Based Security in the Emerging Era of Systems of Systems, Jun. 30, 2021, ACM, pp. 1-25. (Year: 2021). [cited by examiner]
Michael Roland et al., Digital Signature Records for the NFC Data Exchange Format, Jun. 3, 2010, IEEE, pp. 71-76. (Year: 2010). [cited by examiner]
Mehdi Akbari Gurabi et al., Hardware based Two-Factor User Authentication for the Internet of Things, Aug. 30, 2018, IEEE, pp. 1081-1086. (Year: 2018). [cited by examiner]
UKIPO, “UK Application No. 2316761.2 Search and Examination Report mailed Apr. 26, 2024”, 8 pages. [cited by applicant]
Das, D. , “Zero Touch Provisioning IOT or Other Devices on cloud”, https://medium.com/@dd.identity/zero-touch-provisioning-iot-or-other-devices-on-cloud-79a77af9304e Jun. 6, 2022 , 5 Pages. [cited by applicant]
Das, Dipak Kr , “Authorisation Between your IOT Devices and Cloud”, https://medium.com/@dd.identity/authorisation-between-your-iot-devices-and-cloud-dd9fde2c1e0f Jun. 27, 2022 , 5 Pages. [cited by applicant]
UKIPO, , “UK Application No. 2316761.2 Examination Report mailed May 2, 2025”, , 5 pages. [cited by applicant]
A Menezes, et al., “Handbook of Applied Cryptography”, CRC Press, See protocol 12.40, p. 511, Oct. 16, 1996 , p. 511. [cited by applicant]
UKIPO, , “UK Application No. 2316761.2 Examination Report mailed Feb. 23, 2026”, 6 pages. [cited by applicant]