US2016294808A1PendingUtilityA1

Authentication of remote host via closed ports

Assignee: LENOVO ENTPR SOLUTIONS SINGAPORE PTE LTDPriority: Jan 21, 2005Filed: Jun 19, 2016Published: Oct 6, 2016
Est. expiryJan 21, 2025(expired)· nominal 20-yr term from priority
H04L 63/083H04L 63/029H04L 67/42H04L 63/06H04L 63/02H04L 67/02H04L 67/01H04L 63/0428H04L 9/3271H04L 9/32H04L 63/08H04L 63/126H04L 9/08
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, system and apparatus for authenticating a communication request sent from a client computing device. The communication request is initially blocked by a firewall preventing delivery to a server. A first logging event corresponding to the communication request is created. The communication request and the logging event are stored in a firewall. The server is notified of the first logging event. The communication request corresponding to the first logging event is authenticated. A port in the firewall is enabled if the communication request is authenticated.

Claims

exact text as granted — not AI-modified
1 . A system for authenticating a communication request sent from a client computing device, the system comprising:
 a firewall, the firewall comprising:
 a processing unit operating to perform functions including:
 initially block the communication request; and, 
 create a first logging event corresponding to the communication request; and 
 
 a storage unit, the storage unit storing the communication request and the logging event; and 
   a server in data communication with the firewall, the server having a processing unit, the processing unit operating to perform functions including:
 receiving notification of the first logging event created by the firewall; 
 authenticating the communication request corresponding to the first logging event; and 
 enabling a port in the firewall if the communication request is authenticated. 
   
     
     
         2 . The system according to  claim 1 , wherein the communication request is comprised of a plurality of addresses corresponding to the client and a hash of the plurality of addresses corresponding to the client. 
     
     
         3 . The system according to  claim 2 , wherein the server central processing unit authenticates the communication request by performing functions including:
 hashing the plurality of addresses corresponding to the client; and,   matching the plurality of addresses hashed by the server with the hashed plurality of addresses in the communication request.   
     
     
         4 . The system according to  claim 3 , wherein the server central processing unit further authenticates the communication request by transmitting a request to the client for a public key corresponding to the server if the plurality of addresses hashed by the server match with the hashed plurality of addresses in the communication request. 
     
     
         5 . (canceled) 
     
     
         6 . The system according to  claim 5 , wherein the plurality of addresses corresponding to the client include an Internet Protocol Address and a Media Access Control layer address. 
     
     
         7 . A method for authenticating a communication request sent from a client computing device, the method comprising:
 initially blocking the communication request from delivery to a server;   creating a first logging event corresponding to the communication request;   storing the communication request and the logging event in a firewall;   notifying the server of the first logging event;   authenticating the communication request corresponding to the first logging event; and   enabling a port in the firewall if the communication request is authenticated.   
     
     
         8 . The method according to  claim 7 , wherein the communication request is comprised of a plurality of addresses corresponding to the client and a first hashing of the plurality of addresses corresponding to the client. 
     
     
         9 . The method according to  claim 8 , wherein authenticating the communication request includes:
 performing a second hashing of the plurality of address corresponding to the client; and,   matching the second hashing of plurality of addresses with the hashed plurality of addresses in the communication request.   
     
     
         10 . The method according to  claim 9 , wherein authenticating the communication request further includes transmitting a request to the client for a public key corresponding to the server if the second hashed plurality of addresses match with the hashed plurality of addresses in the communication request. 
     
     
         11 . (canceled) 
     
     
         12 . The method according to  claim 11 , wherein the plurality of addresses corresponding to the client include an Internet Protocol Address and a Media Access Control layer address. 
     
     
         13 . The method according to  claim 10 , wherein the first hashing and the second hashing further include positional coordinates corresponding to the client. 
     
     
         14 . A machine readable storage device having stored thereon a computer program for authenticating a communication request sent from a client computing device, the computer program comprising a set of instructions which when executed by a machine causes the machine to perform a method including:
 initially blocking the communication request from delivery to a server;   creating a first logging event corresponding to the communication request;   storing the communication request and the logging event;   notifying the server of the first logging event;   authenticating the communication request corresponding to the first logging event; and   enabling a port in a firewall if the communication request is authenticated.   
     
     
         15 . The machine readable storage device according to  claim 14 , wherein the communication request is comprised of a plurality of addresses corresponding to the client and a first hash of the plurality of addresses corresponding to the client. 
     
     
         16 . The method according to  claim 15 , wherein authenticating the communication request includes:
 performing a second hashing of the plurality of address corresponding to the client; and,   matching the second hashing of plurality of addresses with the hashed plurality of addresses in the communication request.   
     
     
         17 . The method according to  claim 16 , wherein authenticating the communication request further includes transmitting a request to the client for a public key corresponding to the server if the second hashed plurality of addresses match with the first hashed plurality of addresses in the communication request. 
     
     
         18 . (canceled) 
     
     
         19 . The method according to  claim 18 , wherein the plurality of addresses corresponding to the client include an Internet Protocol Address and a Media Access Control layer address. 
     
     
         20 . The method according to  claim 17 , wherein the first hashing and the second hashing further include positional coordinates corresponding to the client.

Join the waitlist — get patent alerts

Track US2016294808A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.