IP Library › Granted Patent US 9,391,962
Granted Patent B2
US 9,391,962 · App. 14/499,943 · Granted Jul 12, 2016

Multi-node encryption

Inventors: Robert F. Houghton (Pocatello, ID); Jeffrey J. Johnson (Smithfield, UT)
Assignee: Utah State University
H04L63/0428H04L63/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,391,962
App. No.
14/499,943
Granted
Jul 12, 2016
Kind
B2
Abstract

For multi-node encryption, a method generates an upstream node nonce from communication data exchanged with an upstream node. In addition, the method generates a first upstream message transformation as a function of the upstream node nonce. The method further generates a tunnel transformation as a function of previous upstream message transformations and the first upstream message transformation.

Claims (34)

1. A method comprising:

communicating an Internet control message protocol (ICMP) message from a first upstream node to a first downstream node in response to the first upstream node initiating a secure communication with the first downstream node;

generating, by use of a processor, a downstream node nonce from the ICMP message exchanged with the first downstream node;

generating a first downstream message transformation as a function of the downstream node nonce, wherein the downstream node nonce is an input to a message transformation generator;

receiving a request encrypted with the first downstream message transformation through the first downstream node from a destination node that is downstream of the first downstream node, wherein the request is for an upstream message transformation that is shared between the first upstream node and a second upstream node that is upstream of the first upstream node;

communicating the upstream message transformation encrypted with the first downstream message transformation through the first downstream node to the destination node in response to the request; and

generating a tunnel transformation at the destination node as a function of one or more upstream message transformations and the first downstream message transformation.

2. The method of claim 1 , wherein the downstream node nonce further identifies the first downstream message transformation from a message transformation table.

3. The method of claim 1 , wherein the first upstream node initiates secure communication by communicating a token.

4. The method of claim 1 , wherein the first upstream node initiates secure communication through port knocking.

5. The method of claim 1 , wherein the first downstream message transformation and the tunnel transformation are generated on an open system interconnection (OSI) layer.

6. The method of claim 1 , wherein a source node communicates with the destination node through a plurality of paths, each of the plurality of paths has a unique tunnel transformation, and the method further comprises generating a tunnel transformation index that determines when to apply each tunnel transformation to a received secure message.

7. A program product comprising a non-transitory computer readable storage medium that stores code executable by a processor, the executable code comprising code to perform:

communicating an Internet control message protocol (ICMP) message from a first upstream node to a first downstream node in response to the first upstream node initiating a secure communication with the first downstream node;

generating a downstream node nonce from the ICMP message exchanged with the first downstream node;

generating a first downstream message transformation as a function of the downstream node nonce, wherein the downstream nonce node is an input to a message transformation generator;

receiving a request encrypted with the first downstream message transformation through the first downstream node from a destination node that is downstream of the first downstream node, wherein the request is for an upstream message transformation that is shared between the first upstream node and a second upstream node that is upstream of the first upstream node;

communicating the upstream message transformation encrypted with the first downstream message transformation through the first downstream node to the destination node in response to the request; and

generating a tunnel transformation at the destination node as a function of one or more upstream message transformations and the first downstream message transformation.

8. The program product of claim 7 , wherein the downstream node nonce further identifies the first downstream message transformation from a message transformation table.

9. The program product of claim 7 , wherein the first upstream node initiates secure communication by one or more of communicating a token and port knocking.

10. The program product of claim 7 , wherein a source node communicates with the destination node through a plurality of paths, each of the plurality of paths has a unique tunnel transformation, and the executable code further generates a tunnel transformation index that determines when to apply each tunnel transformation to a received secure message.

11. An apparatus comprising:

a processor;

a memory that stores code executable by the processor to:

communicate an Internet control message protocol (ICMP) message from a first upstream node to a first downstream node in response to the first upstream node initiating a secure communication with the first downstream node;

generate a downstream node nonce from the ICMP message exchanged with the first downstream node;

generate a first downstream message transformation as a function of the downstream node nonce, wherein the downstream nonce node is an input to a message transformation generator;

receiving a request encrypted with the first downstream message transformation through the first downstream node from a destination node that is downstream of the first downstream node, wherein the request is for an upstream message transformation that is shared between the first upstream node and a second upstream node that is upstream of the first upstream node;

communicate the upstream message transformation encrypted with the first downstream message transformation through the first downstream node to the destination node in response to the request; and

generate a tunnel transformation at the destination node as a function of one or more upstream message transformations and the first downstream message transformation.

12. The apparatus of claim 11 , wherein the downstream node nonce further identifies the first downstream message transformation from a message transformation table.

13. The apparatus of claim 11 , wherein the first upstream node initiates secure communication by one or more of communicating a token and port knocking.

14. The apparatus of claim 11 , wherein a source node communicates with the destination node through a plurality of paths, each of the plurality of paths has a unique tunnel transformation, and the processor further generates a tunnel transformation index that determines when to apply each tunnel transformation to a received secure message.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2020
From: UTAH STATE UNIVERSITY
To: CYBERLINGUAL, LLC
Reel/Frame 052780/0304 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2014
From: HOUGHTON, ROBERT F.; JOHNSON, JEFFREY J.
To: UTAH STATE UNIVERSITY
Reel/Frame 034130/0071 →
Continuity (1)
Related Publication 20160094523A1 · Mar 31, 2016