US2016294808A1PendingUtilityA1
Authentication of remote host via closed ports
Assignee: LENOVO ENTPR SOLUTIONS SINGAPORE PTE LTDPriority: Jan 21, 2005Filed: Jun 19, 2016Published: Oct 6, 2016
Est. expiryJan 21, 2025(expired)· nominal 20-yr term from priority
H04L 63/083H04L 63/029H04L 67/42H04L 63/06H04L 63/02H04L 67/02H04L 67/01H04L 63/0428H04L 9/3271H04L 9/32H04L 63/08H04L 63/126H04L 9/08
45
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method, system and apparatus for authenticating a communication request sent from a client computing device. The communication request is initially blocked by a firewall preventing delivery to a server. A first logging event corresponding to the communication request is created. The communication request and the logging event are stored in a firewall. The server is notified of the first logging event. The communication request corresponding to the first logging event is authenticated. A port in the firewall is enabled if the communication request is authenticated.
Claims
exact text as granted — not AI-modified1 . A system for authenticating a communication request sent from a client computing device, the system comprising:
a firewall, the firewall comprising:
a processing unit operating to perform functions including:
initially block the communication request; and,
create a first logging event corresponding to the communication request; and
a storage unit, the storage unit storing the communication request and the logging event; and
a server in data communication with the firewall, the server having a processing unit, the processing unit operating to perform functions including:
receiving notification of the first logging event created by the firewall;
authenticating the communication request corresponding to the first logging event; and
enabling a port in the firewall if the communication request is authenticated.
2 . The system according to claim 1 , wherein the communication request is comprised of a plurality of addresses corresponding to the client and a hash of the plurality of addresses corresponding to the client.
3 . The system according to claim 2 , wherein the server central processing unit authenticates the communication request by performing functions including:
hashing the plurality of addresses corresponding to the client; and, matching the plurality of addresses hashed by the server with the hashed plurality of addresses in the communication request.
4 . The system according to claim 3 , wherein the server central processing unit further authenticates the communication request by transmitting a request to the client for a public key corresponding to the server if the plurality of addresses hashed by the server match with the hashed plurality of addresses in the communication request.
5 . (canceled)
6 . The system according to claim 5 , wherein the plurality of addresses corresponding to the client include an Internet Protocol Address and a Media Access Control layer address.
7 . A method for authenticating a communication request sent from a client computing device, the method comprising:
initially blocking the communication request from delivery to a server; creating a first logging event corresponding to the communication request; storing the communication request and the logging event in a firewall; notifying the server of the first logging event; authenticating the communication request corresponding to the first logging event; and enabling a port in the firewall if the communication request is authenticated.
8 . The method according to claim 7 , wherein the communication request is comprised of a plurality of addresses corresponding to the client and a first hashing of the plurality of addresses corresponding to the client.
9 . The method according to claim 8 , wherein authenticating the communication request includes:
performing a second hashing of the plurality of address corresponding to the client; and, matching the second hashing of plurality of addresses with the hashed plurality of addresses in the communication request.
10 . The method according to claim 9 , wherein authenticating the communication request further includes transmitting a request to the client for a public key corresponding to the server if the second hashed plurality of addresses match with the hashed plurality of addresses in the communication request.
11 . (canceled)
12 . The method according to claim 11 , wherein the plurality of addresses corresponding to the client include an Internet Protocol Address and a Media Access Control layer address.
13 . The method according to claim 10 , wherein the first hashing and the second hashing further include positional coordinates corresponding to the client.
14 . A machine readable storage device having stored thereon a computer program for authenticating a communication request sent from a client computing device, the computer program comprising a set of instructions which when executed by a machine causes the machine to perform a method including:
initially blocking the communication request from delivery to a server; creating a first logging event corresponding to the communication request; storing the communication request and the logging event; notifying the server of the first logging event; authenticating the communication request corresponding to the first logging event; and enabling a port in a firewall if the communication request is authenticated.
15 . The machine readable storage device according to claim 14 , wherein the communication request is comprised of a plurality of addresses corresponding to the client and a first hash of the plurality of addresses corresponding to the client.
16 . The method according to claim 15 , wherein authenticating the communication request includes:
performing a second hashing of the plurality of address corresponding to the client; and, matching the second hashing of plurality of addresses with the hashed plurality of addresses in the communication request.
17 . The method according to claim 16 , wherein authenticating the communication request further includes transmitting a request to the client for a public key corresponding to the server if the second hashed plurality of addresses match with the first hashed plurality of addresses in the communication request.
18 . (canceled)
19 . The method according to claim 18 , wherein the plurality of addresses corresponding to the client include an Internet Protocol Address and a Media Access Control layer address.
20 . The method according to claim 17 , wherein the first hashing and the second hashing further include positional coordinates corresponding to the client.Join the waitlist — get patent alerts
Track US2016294808A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.