US2019068570A1PendingUtilityA1

Multi-party authentication in a zero-trust distributed system

Assignee: ENTEFY INCPriority: Dec 31, 2016Filed: Oct 19, 2018Published: Feb 28, 2019
Est. expiryDec 31, 2036(~10.4 yrs left)· nominal 20-yr term from priority
H04L 65/403H04L 9/32H04L 67/143H04L 63/10H04L 2209/46H04L 63/08
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A zero-trust network and methods of using same are disclosed. The network includes a plurality of nodes, some of which are user devices, such as mobile phones, some of which are computer servers. One or more of the nodes includes a directory system. When a server receives an access request by a user device or other node, the directory system is notified of the request. The directory system will contact a number of randomly selected nodes, and if any one of the nodes does not recognize the requesting device, the requesting device will be denied access. If every queried node is able to authenticate the requesting device, the directory system creates a session for the first device to access the server. The directory system can grant access by providing the server and device reciprocating keys. After the session ends, the accessed node is assigned a new identifier.

Claims

exact text as granted — not AI-modified
1 . A method of managing a network system, comprising:
 receiving, at one or more servers, a request from a first node to access a second node, the second node being from among a plurality of nodes;   selecting, at the one or more servers, one or more third nodes from among the plurality of nodes;   receiving, at the one or more servers, an indication that an event corresponding to the request to access the second node was logged;   sending, from the one or more servers, validation requisitions to the one or more third nodes, responsive to receipt of the request to access the second node and the indication that the event corresponding to the request to access to the second node was logged;   receiving, at the one or more servers, a validation message from each of the one or more third nodes indicating an authenticity of the first node and an authenticity of each of the other third nodes; and   allowing, by the one or more servers, the first node to access the second node for a predetermined amount of time, responsive to receipt of the validation message from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes.   
     
     
         2 . The method of managing a network system of  claim 1 , wherein selecting, at the one or more servers, one or more third nodes from among the plurality of nodes comprises randomly selecting, at the one or more servers, one or more third nodes from among the plurality of nodes. 
     
     
         3 . The method of managing a network system of  claim 1 , wherein selecting, at the one or more servers, one or more third nodes from among the plurality of nodes comprises selecting, at the one or more servers, at least one user device configured to require, responsive to receipt by the user device of a validation requisition, entry of authenticating information via a physical interface. 
     
     
         4 . The method of managing a network system of  claim 1 , wherein allowing, by the one or more servers, the first node to access the second node for the predetermined amount of time, responsive to receipt of the validation message from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes comprises allowing, by the one or more servers, the first node to access the second node for the predetermined amount of time, responsive to receipt of the validation message within a second predetermined amount of time from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes. 
     
     
         5 . The method of managing a network system of  claim 1 , wherein allowing, by the one or more servers, the first node to access the second node for the predetermined amount of time, responsive to receipt of the validation message from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes comprises providing a token to the first node which, upon acceptance of the token by the second node, enables the first node to access the second node during a single session that lasts no longer than the predetermined amount of time, the single session being impossible to recreate. 
     
     
         6 . The method of managing a network system of  claim 5 , further comprising monitoring, by the one or more servers, the single session, wherein monitoring the single session includes ensuring that the single session complies with rules corresponding to the token. 
     
     
         7 . The method of managing a network system of  claim 6 , wherein ensuring that the single session complies with rules corresponding to the token, comprises ensuring that the single session complies with a rule that the single session must end within the predetermined amount of time. 
     
     
         8 . The method of managing a network system of  claim 1 , further comprising disallowing, by the one or more servers, the first node from accessing the second node for a remainder of the predetermined amount of time, responsive to one or more of the third nodes becoming disconnected from the one or more servers, disconnected from one or more of the other third nodes, or both. 
     
     
         9 . The method of managing a network system of  claim 8 , further comprising logging of the disallowing by the one or more servers of the first node from accessing the second node for the remainder of the predetermined amount of time. 
     
     
         10 . The method of managing a network system of  claim 1 , further comprising changing, by the one or more servers, an identifier corresponding to the second node, responsive to elapsing of the predetermined amount of time. 
     
     
         11 . A network system, comprising:
 a plurality of nodes, the plurality of nodes including one or more user devices and one or more servers, wherein the one or more servers are configured to:   receive, at the one or more servers, a request from a first node to access a second node, the second node being from among the plurality of nodes;   select, at the one or more servers, one or more third nodes from among the plurality of nodes;   receive, at the one or more servers, an indication that an event corresponding to the request to access the second node was logged;   send, from the one or more servers, validation requisitions to the one or more third nodes, responsive to receipt of the request to access the second node and the indication that the event corresponding to the request to access to the second node was logged;   receive, at the one or more servers, a validation message from each of the one or more third nodes indicating an authenticity of the first node and an authenticity of each of the other third nodes; and   allow the first node to access the second node for a predetermined amount of time, responsive to receipt of the validation message from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes.   
     
     
         12 . The network system of  claim 11 , wherein the one or more servers are further configured to select the one or more third nodes from among the plurality of nodes by randomly selecting the one or more third nodes from among the plurality of nodes. 
     
     
         13 . The network system of  claim 11 , wherein the one or more servers are further configured to select the one or more third nodes from among the plurality of nodes comprises by randomly selecting, at the one or more servers, the one or more third nodes from among the plurality of nodes. 
     
     
         14 . The network system of  claim 11 , wherein the one or more servers are further configured to select the one or more third nodes from among the plurality of nodes comprises by selecting, at the one or more servers, at least one user device configured to require, responsive to receipt at that user device of a validation requisition, entry of authenticating information via a physical interface. 
     
     
         15 . The network system of  claim 11 , wherein the one or more servers are further configured to allow the first node to access the second node for the predetermined amount of time, responsive to receipt of the validation message from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes by allowing the first node to access the second node for the predetermined amount of time, responsive to receipt of the validation message within a second predetermined amount of time from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes. 
     
     
         16 . The network system of  claim 11 , wherein the one or more servers are further configured to allow the first node to access the second node for the predetermined amount of time, responsive to receipt of the validation message from each of the one or more third nodes indicating the authenticity of the first node and the authenticity of each of the other third nodes by providing a token to the first node which, upon acceptance of that token by the second node, enables the first node to access the second node during a single session that lasts no longer than the predetermined amount of time. 
     
     
         17 . The network system of  claim 16 , wherein the one or more servers are further configured to monitor the single session, wherein monitoring the single session includes ensuring that the single session complies with rules corresponding to the token. 
     
     
         18 . The network system of  claim 17 , wherein ensuring that the single session complies with rules corresponding to the token, comprises ensuring that the single session complies with a rule that the single session must end within the predetermined amount of time. 
     
     
         19 . The network system of  claim 11 , wherein the one or more servers are further configured to revoke the first node's access to the second node for a remainder of the predetermined amount of time, responsive to one or more of the third nodes becoming disconnected from the one or more servers, disconnected from one or more of the other third nodes, or both. 
     
     
         20 . The network system of  claim 19 , wherein the one or more servers are further configured to log the revocation by the one or more servers of the first node's access to the second node for the remainder of the predetermined amount of time.

Join the waitlist — get patent alerts

Track US2019068570A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.