IP Library › Granted Patent US 12,609,914
Granted Patent B2
US 12,609,914 · App. 18/171,945 · Granted Apr 21, 2026

Network access proxy for zero-day attack protection in control and management plane applications

Inventors: Gopi Sirineni (San Jose, CA); Alexander Bachmutsky (Sunnyvale, CA); Raghu Kondapalli (San Jose, CA)
Assignee: Axiado Corporation
H04L63/0281H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,914
App. No.
18/171,945
Granted
Apr 21, 2026
Kind
B2
Abstract

Described herein are systems and methods comprising a trusted control unit (TCU) proxy for security in an environment. The TCU proxy can comprise a classifier, a lookup engine, and an action engine. The TCU proxy can be used to prevent malicious activity on an environment.

Claims (54)

1 . An immutable hardware system comprising: at least one processor, a memory, and instructions executable by the at least one processor, wherein the immutable hardware system performs one or more functions that has been rendered unchangeable to create a trusted control unit (TCU) proxy that is immune to non-physical attacks for security in an environment, the TCU proxy comprising:

(i) a classifier for classifying a type of one or more calls made from a client in the environment or outside the environment;

(ii) a lookup engine for assessing malicious activity based in part on a first output from the classifier; and

(iii) an action engine for determining an action based in part on a second output from the lookup engine,

wherein the TCU proxy consolidates a plurality of operations by the classifier, the lookup engine, the action engine, or any combination thereof into a hardware operation that is anchored into the environment by the immutable hardware system.

2 . The system of claim 1 , wherein the one or more calls comprises all calls made from clients in the environment or outside the environment.

3 . The system of claim 1 , wherein classifying the type of call comprises classifying based in part on a request type, a packet header, or a security protocol.

4 . The system of claim 3 , wherein the security protocol comprises MACsec, IPsec, SSL/TLS, or SSH.

5 . The system of claim 1 , wherein assessing malicious activity comprises applying one or more predetermined rules.

6 . The system of claim 1 , wherein assessing malicious activity comprises applying one or more dynamic rules.

7 . The system of claim 1 , wherein the action comprises authorizing the one or more calls or blocking the one or more calls.

8 . The system of claim 7 , wherein authorizing the one or more calls comprises execution of a program in the computer-implemented system.

9 . The system of claim 7 , wherein blocking the one or more calls further comprises temporarily or permanently blocking the client of the one or more calls.

10 . The system of claim 1 , wherein the one or more calls comprises an application programming interface (API) call.

11 . The system of claim 1 , wherein the one or more calls comprises a network discovery lookup.

12 . The system of claim 1 , wherein the one or more calls comprises a library call.

13 . The system of claim 12 , wherein the action engine authorizes or blocks access of a library of the library call to the network.

14 . The system of claim 1 , wherein the TCU proxy serves as a web-application firewall (WAF).

15 . The system of claim 1 , wherein the lookup engine comprises a machine learning algorithm.

16 . The system of claim 15 , wherein the machine learning algorithm is a self-learning algorithm.

17 . The system of claim 16 , wherein the self-learning algorithm updates one or more dynamic rules for assessing malicious activity based in part on the first output from the classifier.

18 . The system of claim 15 , wherein the lookup engine further analyzes traffic in the environment.

19 . The system of claim 18 , wherein analyzing traffic comprises detecting or preventing a denial-of-service (DoS) attack or a distributed denial-of-service (DDoS) attack.

20 . The system of claim 18 , wherein the traffic is encrypted.

21 . The system of claim 15 , wherein the machine learning algorithm analyzes traffic from one or more tunnels in the environment or application communications in the environment.

22 . The system of claim 1 , wherein the environment comprises a compute, a network, a storage, an artificial intelligence system, or any combination thereof.

23 . A computer-implemented method of preventing malicious activity in an environment by an immutable hardware system, wherein the immutable hardware system performs one or more functions that has been rendered unchangeable to create a trusted control unit (TCU) proxy that is immune to non-physical attacks, the method comprising:

(a) feeding one or more calls made from a client in the environment or outside the environment to the TCU proxy operating on immutable hardware, comprising:

(i) classifying a type of the one or more calls using a classifier of the TCU proxy to generate a first output;

(ii) assessing malicious activity using a lookup engine of the TCU proxy based in part on the first output to generate a second output; and

(iii) determining an action using an action engine of the TCU proxy based in part on the second output to generate a third output,

wherein the TCU proxy consolidates a plurality of operations by the classifier, the lookup engine, the action engine, or any combination thereof into a hardware operation that is anchored into the environment by the immutable hardware system; and

(b) performing one or more operations of a system based in part on the third output, wherein the one or more operations comprise authorizing the one or more calls or blocking the one or more calls, thereby preventing malicious activity on the environment.

24 . The method of claim 23 , wherein the one or more calls comprises all calls made from clients in the environment or outside the environment.

25 . The method of claim 23 , wherein classifying the type of call comprises classifying based in part on a request type, a packet header, or a security protocol.

26 . The method of claim 25 , wherein the security protocol comprises MACsec, IPsec, SSL/TLS, or SSH.

27 . The method of claim 23 , wherein assessing malicious activity comprises applying one or more predetermined rules.

28 . The method of claim 23 , wherein assessing malicious activity comprises applying one or more dynamic rules.

29 . The method of claim 23 , wherein the action comprises authorizing the one or more calls or blocking the one or more calls.

30 . The method of claim 29 , wherein authorizing the one or more calls comprises execution of a program in the computer-implemented system.

31 . The method of claim 29 , wherein blocking the one or more calls further comprises temporarily or permanently blocking the client of the one or more calls.

32 . The method of claim 23 , wherein the one or more calls comprises an application programming interface (API) call.

33 . The method of claim 23 , wherein the one or more calls comprises a network discovery lookup.

34 . The method of claim 23 , wherein the one or more calls comprises a library call.

35 . The method of claim 34 , wherein the action engine authorizes or blocks access of a library of the library call to the network.

36 . The method of claim 23 , wherein the TCU proxy serves as a web-application firewall (WAF).

37 . The method of claim 23 , wherein the lookup engine comprises a machine learning algorithm.

38 . The method of claim 37 , wherein the machine learning algorithm is a self-learning algorithm.

39 . The method of claim 38 , wherein the self-learning algorithm updates one or more dynamic rules for assessing malicious activity based in part on the first output from the classifier.

40 . The method of claim 37 , wherein the lookup engine further analyzes traffic in the environment.

41 . The method of claim 40 , wherein analyzing traffic comprises detecting or preventing a denial-of-service (DoS) attack or a distributed denial-of-service (DDoS) attack.

42 . The method of claim 40 , wherein the traffic is encrypted.

43 . The method of claim 37 , wherein the machine learning algorithm analyzes traffic from one or more tunnels in the environment or application communications in the environment.

44 . The method of claim 23 , wherein the environment comprises a compute, a network, a storage, an artificial intelligence system, or any combination thereof.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2024
From: SIRINENI, GOPI; KONDAPALLI, RAGHU; BACHMUTSKY, ALEXANDER
To: AXIADO CORPORATION
Reel/Frame 066461/0288 →
Continuity (2)
Provisional Application 63312656 · Feb 22, 2022
Related Publication 20230269237A1 · Aug 24, 2023
References Cited (109)
US 5937036A · Dean et al. · 1999 [cited by applicant]
US 6868492B1 · McCarty et al. · 2005 [cited by applicant]
US 7437568B2 · Das-Purkayastha et al. · 2008 [cited by applicant]
US 7831839B2 · Hatakeyama · 2010 [cited by applicant]
US 7945792B2 · Cherpantier · 2011 [cited by applicant]
US 8060732B2 · Jones et al. · 2011 [cited by applicant]
US 8533444B2 · Jun · 2013 [cited by applicant]
US 8938792B2 · Koeberl et al. · 2015 [cited by applicant]
US 8990548B2 · Varnum et al. · 2015 [cited by applicant]
US 9177122B1 · Trier · 2015 [cited by applicant]
US 9230112B1 · Peterson et al. · 2016 [cited by applicant]
US 9602282B2 · Hussain · 2017 [cited by applicant]
US 9614669B1 · Cox, Jr. et al. · 2017 [cited by applicant]
US 9710651B2 · Stewart et al. · 2017 [cited by applicant]
US 9755831B2 · Laver et al. · 2017 [cited by applicant]
US 9930051B1 · Potlapally et al. · 2018 [cited by applicant]
US 10284368B2 · Li et al. · 2019 [cited by applicant]
US 10331593B2 · Lambert et al. · 2019 [cited by applicant]
US 10474596B2 · Jayakumar et al. · 2019 [cited by applicant]
US 10592671B2 · Chen et al. · 2020 [cited by applicant]
US 10742421B1 · Wentz et al. · 2020 [cited by applicant]
US 10936299B2 · Butcher et al. · 2021 [cited by applicant]
US 11144652B1 · Cochell et al. · 2021 [cited by applicant]
US 11227047B1 · Vashisht · 2022 [cited by examiner]
US 11392301B2 · Kloth · 2022 [cited by applicant]
US 11416150B2 · Kloth · 2022 [cited by applicant]
US 11520494B2 · Kloth · 2022 [cited by applicant]
US 12008246B2 · Kloth · 2024 [cited by applicant]
US 12278830B2 · Sirineni et al. · 2025 [cited by applicant]
US 20020099950A1 · Smith · 2002 [cited by applicant]
US 20030097558A1 · England et al. · 2003 [cited by applicant]
US 20050022010A1 · Swander · 2005 [cited by examiner]
US 20050262571A1 · Zimmer et al. · 2005 [cited by applicant]
US 20070076853A1 · Kurapati · 2007 [cited by examiner]
US 20070177627A1 · Raju et al. · 2007 [cited by applicant]
US 20070260869A1 · Dade et al. · 2007 [cited by applicant]
US 20070283140A1 · Jones et al. · 2007 [cited by applicant]
US 20090089572A1 · Jun · 2009 [cited by applicant]
US 20090222653A1 · Findeisen et al. · 2009 [cited by applicant]
US 20090235355A1 · Chen · 2009 [cited by examiner]
US 20090241190A1 · Todd · 2009 [cited by examiner]
US 20100001786A1 · Ramachandran et al. · 2010 [cited by applicant]
US 20110173457A1 · Reh · 2011 [cited by applicant]
US 20110314547A1 · Yoo · 2011 [cited by examiner]
US 20120036572A1 · Yoo · 2012 [cited by examiner]
US 20120137117A1 · Bosch et al. · 2012 [cited by applicant]
US 20120198224A1 · Leclercq · 2012 [cited by applicant]
US 20140189340A1 · Hadley · 2014 [cited by applicant]
US 20140223564A1 · Joo · 2014 [cited by examiner]
US 20150006914A1 · Oshida · 2015 [cited by applicant]
US 20150012737A1 · Newell · 2015 [cited by applicant]
US 20150199520A1 · Woolley et al. · 2015 [cited by applicant]
US 20160013110A1 · Brokish et al. · 2016 [cited by applicant]
US 20160147996A1 · Martinez · 2016 [cited by applicant]
US 20160300064A1 · Stewart et al. · 2016 [cited by applicant]
US 20170099310A1 · Di Pietro · 2017 [cited by examiner]
US 20170126405A1 · Li et al. · 2017 [cited by applicant]
US 20170312530A1 · Schilling et al. · 2017 [cited by applicant]
US 20170366186A1 · Reese · 2017 [cited by applicant]
US 20180096151A1 · Ghetie et al. · 2018 [cited by applicant]
US 20180144131A1 · Wojnowicz · 2018 [cited by examiner]
US 20180145991A1 · McCauley et al. · 2018 [cited by applicant]
US 20180165455A1 · Liguori et al. · 2018 [cited by applicant]
US 20180181752A1 · Guri · 2018 [cited by examiner]
US 20180198809A1 · Kushwaha · 2018 [cited by examiner]
US 20180203998A1 · Maisel · 2018 [cited by examiner]
US 20190007433A1 · McLane · 2019 [cited by examiner]
US 20190007434A1 · McLane · 2019 [cited by examiner]
US 20190081983A1 · Teal · 2019 [cited by applicant]
US 20190132344A1 · Lem et al. · 2019 [cited by applicant]
US 20190311126A1 · Areno et al. · 2019 [cited by applicant]
US 20200014722A1 · Walters et al. · 2020 [cited by applicant]
US 20200099815A1 · Ono · 2020 [cited by applicant]
US 20200110880A1 · Ghetie et al. · 2020 [cited by applicant]
US 20200117804A1 · Laffey et al. · 2020 [cited by applicant]
US 20200272480A1 · Admon et al. · 2020 [cited by applicant]
US 20200320209A1 · Cohen et al. · 2020 [cited by applicant]
US 20200356701A1 · Pruss et al. · 2020 [cited by applicant]
US 20210192050A1 · Hird et al. · 2021 [cited by applicant]
US 20210312051A1 · Kloth · 2021 [cited by applicant]
US 20210312053A1 · Kloth · 2021 [cited by applicant]
US 20210312054A1 · Kloth · 2021 [cited by applicant]
US 20210312056A1 · Kloth · 2021 [cited by applicant]
US 20210312057A1 · Kloth · 2021 [cited by applicant]
US 20210377303A1 · Bui et al. · 2021 [cited by applicant]
US 20210377304A1 · Ma et al. · 2021 [cited by applicant]
US 20220067146A1 · Cai · 2022 [cited by examiner]
US 20220255897A1 · Miele et al. · 2022 [cited by applicant]
US 20230060207A1 · Sirineni et al. · 2023 [cited by applicant]
CN 109995507A · 2019 [cited by applicant]
DE 102010045580A1 · 2012 [cited by applicant]
EP 3214567A1 · 2017 [cited by applicant]
EP 3214797A1 · 2017 [cited by applicant]
WO WO2014088172A1 · 2014 [cited by applicant]
WO WO2014088239A1 · 2014 [cited by applicant]
U.S. Appl. No. 17/006,717 Final Office Action dated Mar. 23, 2023. [cited by applicant]
U.S. Appl. No. 17/023,308 Non-Final Office Action dated Aug. 5, 2022. [cited by applicant]
U.S. Appl. No. 17/023,308 Non-Final Office Action dated Feb. 13, 2023. [cited by applicant]
U.S. Appl. No. 17/025,083 Non-Final Office Action dated Mar. 30, 2022. [cited by applicant]
U.S. Appl. No. 17/025,731 Non-Final Office Action dated Nov. 10, 2022. [cited by applicant]
U.S. Appl. No. 17/023,308 Final Office Action dated Sep. 21, 2023. [cited by applicant]
U.S. Appl. No. 17/006,717 Notice of Allowance dated Jul. 24, 2023. [cited by applicant]
U.S. Appl. No. 17/016,334 Office Action dated Sep. 14, 2021. [cited by applicant]
U.S. Appl. No. 17/023,308 Corrected Notice of Allowability dated Mar. 7, 2024. [cited by applicant]
U.S. Appl. No. 17/023,308 Notice of Allowance dated Feb. 28, 2024. [cited by applicant]
U.S. Appl. No. 17/023,341 Office Action dated Dec. 9, 2021. [cited by applicant]
U.S. Appl. No. 17/897,676 Corrected Notice of Allowability dated Mar. 10, 2025. [cited by applicant]
U.S. Appl. No. 17/897,676 Notice of Allowance dated Jan. 7, 2025. [cited by applicant]
U.S. Appl. No. 17/897,676 Office Action dated Jun. 21, 2024. [cited by applicant]