IP Library › Granted Patent US 12,726,510
Granted Patent B2
US 12,726,510 · App. 18/928,773 · Granted Sep 1, 2026

Network security systems and methods using recurrent device attestation

Inventors: Bela Genge (Tirgu Mures, RO); Balint Szente (Tirgu Mures, RO); George M. Trif (Stefanestii de Jos, RO)
Assignee: Bitdefender IPR Management Ltd.
H04L63/1441H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,510
App. No.
18/928,773
Granted
Sep 1, 2026
Kind
B2
Abstract

Some embodiments improve the security of a network of IoT devices via a recurrent re-attestation of network nodes. The frequency of re-attestation may depend on a network role of the respective device (e.g., router vs. end node) and/or on a measure of connectivity of the respective node (e.g., node degree), with highly connected nodes re-attested more often than end nodes. Some embodiments employ a pebble-ripple attestation procedure wherein an administration device transmits an attestation probe to a device via one-to-one messaging (e.g., unicast), and the respective device replies via one-to-many messaging (e.g., multicast). The administration device then attests the identity and/or functionality of the respective device according to the timing of multiple replies from the attested device, each reply traversing the network via a distinct route.

Claims (77)

1 . A security appliance connected to a computer network interconnecting a plurality of client devices, the security appliance comprising at least one hardware processor configured to:

carry out a recurrent attestation of a selected device of the plurality of client devices wherein:

the recurrent attestation includes a plurality of attestation sessions, each attestation session comprising an exchange of messages between the security appliance and the selected device, and

a length of a time interval between two consecutive sessions of the plurality of attestation sessions is determined according to a measure of connectivity of the selected device within the computer network; and

in response to a failure of the recurrent attestation, determine whether the failure is indicative of a computer security threat.

2 . The security appliance of claim 1 , wherein the computer network comprises a plurality of nodes interconnected by a plurality of edges, and wherein the measure of connectivity of the selected device is determined according to a node degree of a selected node of the plurality of nodes, the selected node comprising the selected device.

3 . The security appliance of claim 2 , wherein the length of the time interval is further constrained between a pre-determined upper bound and a pre-determined lower bound.

4 . The security appliance of claim 2 , wherein the length of the time interval is further determined according to:

T

max

-

T

max

-

T

min

d

max

-

d

min

⁢

(

d

-

d

min

)

,

wherein d denotes the node degree of the selected node, d min and d max are pre-determined lower and upper bounds on the node degree, respectively, and T min and T max are pre-determined lower and upper bounds on the length of the time interval.

5 . The security appliance of claim 1 , wherein the measure of connectivity of the selected device is determined according to a count of devices of the plurality of client devices that the selected device is communicating with over the computer network.

6 . The security appliance of claim 1 , wherein the measure of connectivity of the selected device is determined according to whether the selected device is configured to relay incoming communications to other devices of the plurality of client devices.

7 . The security appliance of claim 1 , wherein the measure of connectivity of the selected device is determined according to whether the selected device is battery-operated.

8 . The security appliance of claim 1 , wherein the measure of connectivity of the selected device is determined according to a type of network protocol used for communicating with the selected device.

9 . The security appliance of claim 1 , wherein the length of the time interval is further determined according to whether the selected device comprises a mobile computing device.

10 . The security appliance of claim 1 , wherein an attestation session of the plurality of attestation sessions comprises the security appliance transmitting an attestation probe to the selected device and determining whether the attestation session is successful according to a timing of a plurality of distinct instances of a reply to the attestation probe, each distinct instance of the reply received from the selected device via a distinct route through the computer network.

11 . A computer-implemented method of protecting a plurality of client devices against computer security threats, the plurality of client devices interconnected by a computer network, the method comprising employing at least one hardware processor of a security appliance connected to the computer network to:

carry out a recurrent attestation of a selected device of the plurality of client devices wherein:

the recurrent attestation includes a plurality of attestation sessions, each attestation session comprising an exchange of messages between the security appliance and the selected device, and

a length of a time interval between two consecutive sessions of the plurality of attestation sessions is determined according to a measure of connectivity of the selected device within the computer network; and

in response to a failure of the recurrent attestation, determine whether the failure is indicative of a computer security threat.

12 . The method of claim 11 , wherein the computer network comprises a plurality of nodes interconnected by a plurality of edges, and wherein the measure of connectivity of the selected device is determined according to a node degree of a selected node of the plurality of nodes, the selected node comprising the selected device.

13 . The method of claim 12 , wherein the length of the time interval is further constrained between a pre-determined upper bound and a pre-determined lower bound.

14 . The method of claim 12 , wherein the length of the time interval is further determined according to:

T

max

-

T

max

-

T

min

d

max

-

d

min

⁢

(

d

-

d

min

)

,

wherein d denotes the node degree of the selected node, d min and d max are pre-determined lower and upper bounds on the node degree, respectively, and T min and T max are pre-determined lower and upper bounds on the length of the time interval.

15 . The method of claim 11 , wherein the measure of connectivity of the selected device is determined according to a count of devices of the plurality of client devices that the selected device is communicating with over the computer network.

16 . The method of claim 11 , wherein the measure of connectivity of the selected device is determined according to whether the selected device is configured to relay incoming communications to other devices of the plurality of client devices.

17 . The method of claim 11 , wherein the measure of connectivity of the selected device is determined according to whether the selected device is battery-operated.

18 . The method of claim 11 , wherein the measure of connectivity of the selected device is determined according to a type of network protocol used for communicating with the selected device.

19 . The method of claim 11 , wherein the length of the time interval is further determined according to whether the selected device comprises a mobile computing device.

20 . The method of claim 11 , wherein an attestation session of the plurality of attestation sessions comprises the security appliance transmitting an attestation probe to the selected device and determining whether the attestation session is successful according to a timing of a plurality of distinct instances of a reply to the attestation probe, each distinct instance of the reply received from the selected device via a distinct route through the computer network.

21 . A non-transitory computer-readable medium storing instructions which, when executed by at least one hardware processor of a security appliance connected to a computer network interconnecting a plurality of client devices, causes the security appliance to:

carry out a recurrent attestation of a selected device of the plurality of client devices wherein:

the recurrent attestation includes a plurality of attestation sessions, each attestation session comprising an exchange of messages between the security appliance and the selected device, and

a length of a time interval between two consecutive sessions of the plurality of attestation sessions is determined according to a measure of connectivity of the selected device within the computer network; and

in response to a failure of the recurrent attestation, determine whether the failure is indicative of a computer security threat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2024
From: GENGE, BELA; SZENTE, BALINT; TRIF, GEORGE M
To: BITDEFENDER IPR MANAGEMENT LTD.
Reel/Frame 069043/0830 →
Continuity (2)
Provisional Application 63624895 · Jan 25, 2024
Related Publication 20250247418A1 · Jul 31, 2025
References Cited (24)
US 10177915B2 · Ignatchenko · 2019 [cited by applicant]
US 10181987B2 · Gandham · 2019 [cited by applicant]
US 20050132202A1 · Dillaway · 2005 [cited by applicant]
US 20190138716A1 · Huang · 2019 [cited by applicant]
US 20190363843A1 · Gordaychik · 2019 [cited by applicant]
US 20200296128A1 · Wentz · 2020 [cited by applicant]
US 20200322348A1 · Kathail · 2020 [cited by examiner]
US 20200322356A1 · Sheth · 2020 [cited by applicant]
US 20200322386A1 · Mani · 2020 [cited by applicant]
US 20210328794A1 · Mishra · 2021 [cited by examiner]
US 20210377737A1 · Zaffino · 2021 [cited by examiner]
US 20220070178A1 · Lee · 2022 [cited by examiner]
US 20220078015A1 · Nainar · 2022 [cited by examiner]
US 20220116224A1 · Guim · 2022 [cited by applicant]
US 20220255916A1 · Smith · 2022 [cited by applicant]
US 20230013347A1 · Moyer · 2023 [cited by examiner]
US 20240380617A1 · Oliver · 2024 [cited by examiner]
US 20250112948A1 · Lee · 2025 [cited by applicant]
US 20250158916A1 · Sharma · 2025 [cited by examiner]
European Patent Office (EPO), International Search Report and Written Opinion mailed Mar. 3, 2025 for PCT International Patent Application No. PCT/EP2025/050537, international filing date Jan. 10, 2025, priority date Ja… [cited by applicant]
European Patent Office (EPO), International Search Report and Written Opinion mailed Mar. 3, 2025 for PCT International Patent Application No. PCT/EP2025/050543, international filing date Jan. 10, 2025, priority date Ja… [cited by applicant]
Moreau et al., “CRAFT: A Continuous Remote Attestation Framework for IoT,” IEEE Access, vol. 9, pp. 46430-46447, Mar. 22, 2021. [cited by applicant]
Wedaj, “DADS: Decentralized Attestation for Device Swarms,” ACM Transactions on Privacy and Security, 22 (3):1-29, Jul. 16, 2019. [cited by applicant]
USPTO, Office Action mailed May 11, 2026 for U.S. Appl. No. 18/928,937, filed Oct. 28, 2024. [cited by applicant]