US2023043229A1PendingUtilityA1

Enhanced monitoring and protection of enterprise data

Assignee: SMART SECURITY SYSTEMS LLCPriority: Apr 15, 2019Filed: Oct 14, 2022Published: Feb 9, 2023
Est. expiryApr 15, 2039(~12.7 yrs left)· nominal 20-yr term from priority
H04L 9/3271H04L 9/50G06F 21/604G06F 21/575H04L 9/3239H04L 9/3066H04L 9/3297G06F 21/6218H04L 9/0841
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure relates to systems and methods for communicating over a network, including encrypting and decrypting communications of data over the network for providing enhanced security utilizing a blockchain-encryption process and a global device ledger. The following also discloses systems for device and session initialization, automation, data capture, security, providing alerts, personalization of settings, and other objectives described in the disclosure. Methods of establishing and monitoring network communications are also disclosed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A blockchain-enabled system for enhanced, secure communications among a plurality of devices in communication over a local system, comprising:
 a plurality of devices in communication over a network associated with the local system;   at least one Known Authority associated with at least one local domain controller (LDC);   at least one encryption module comprising at least one device agent, the at least one encryption module configured to implement one or more encryption policies for communication threads between the at least one LDC and the plurality of devices;   a blockchain-enabled device ledger maintained by the at least one LDC;   wherein each device of the plurality of devices requires registration and validation from the at least one Known Authority;   wherein the at least one Known Authority operates through the at least one local domain controller (LDC) to control and command devices on the local system;   wherein the at least one encryption module is further configured to operate on the at least one Known Authority and the at least one LDC;   wherein the at least one device agent generates a challenge in response to a request to the at least one Known Authority for registration and validation from each device, wherein the at least one device agent communicates a message with the challenge to each device from the at least one Known Authority, wherein the at least one device agent compares the challenge received from the at least one Known Authority to the challenge generated for each device, wherein each device is registered and validated only when the challenges match; and   wherein the at least one LDC adds each device receiving a challenge match to the blockchain-enabled device ledger.   
     
     
         2 . The system of  claim 1 , wherein the at least one encryption module is in communication with a datastore local to the local system, and wherein the datastore only contains information at a specific level of the at least one LDC and below. 
     
     
         3 . The system of  claim 1 , wherein each device of the plurality of devices in the local system operates at least one device agent, and wherein each device agent establishes a secure communication channel with the at least one LDC. 
     
     
         4 . The system of  claim 3 , wherein each of the at least one device agents are not visible to other systems and applications in the local system. 
     
     
         5 . The system of  claim 1 , wherein the at least one encryption module records the transmission of messages and errors received during communications between or among the plurality of devices. 
     
     
         6 . The system of  claim 5 , wherein the messages comprise a 32-bit Universally Unique Identifier (UUID) key for encryption by the at least one encryption module. 
     
     
         7 . The system of  claim 5 , wherein the messages are encrypted by Supersingular Isogeny Diffie-Hellman (SIDH) key exchange and key encapsulation. 
     
     
         8 . The system of  claim 1 , wherein the Known Authority initiated at least one decryption routine to decrypt the encryption policies implemented by the at least one encryption module. 
     
     
         9 . The system of  claim 5 , wherein the 32-bit Universally Unique Identifier (UUID) key further comprises at least one Device Install Key (DIK). 
     
     
         10 . The system of  claim 1 , wherein the at least one device agent is configured to generate an alert if unknown data is received by the plurality of devices, and wherein the alert is sent to the at least one LDC. 
     
     
         11 . A method of adding a device to a local system comprising:
 installing a Thin Agent Verifier program on the device;   executing the Thin Agent Verifier program;   generating a 32-bit Unique Identifier and Device Install Keys (DIK) from an endpoint IP address and a first timestamp;   encrypting and transmitting the endpoint IP address, the 32-bit Identifier and the DIK Public Key with a public key by the Thin Agent Verifier to a known authority of the local system;   locating a private key corresponding to the DIK public key;   performing a decryption routine by the known authority;   determining if the private key and public key values match;   encrypting an Unlock Key with the DIK public key by the known authority;   communicating the encrypted Unlock Key to the new device;   wherein the device performs a decryption routine, uninstalls the Thin Agent Verifier, wherein the device establishes Secure SIDH Communications using the DIK Keys; and   wherein the device validates itself with the known authority.   
     
     
         12 . The method of  claim 11  further comprising the step of performing BIOS fingerprinting before validating the device with the known authority. 
     
     
         13 . The method of  claim 11  further comprising the step of executing a full installation of a device agent on the device and uninstalling the Thin Agent Verifier. 
     
     
         14 . The method of  claim 11  further comprising generating a challenge, based at least in part on the 32-Bit Identifier and the first timestamp, and communicating a message with the challenge to the device from the known authority. 
     
     
         15 . The method of  claim 14 , wherein the device generates a challenge and compares the challenge received from the known authority to the challenge generated at the device, and wherein device communications are initiated only if the challenges match. 
     
     
         16 . The method of  claim 15  further comprising at least one local domain controller, wherein the local domain controller adds the device to a global device ledger. 
     
     
         17 . The method of  claim 16  further comprising the step of generating alerts if unknown data or other anomalies are received by the device, wherein the alerts generated are sent to the at least one local domain controller and at least one administrator.

Join the waitlist — get patent alerts

Track US2023043229A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.