Secured distributed mesh network
Abstract
In accordance with some embodiments, a method of operating a user-equipment (UE) gateway device to establish access for an end-point device coupled to the UE gateway device includes receiving a connection request from the end-point device; creating a registry entry with a digital identity for the end-point device in a security registry of the UE gateway device, transmitting a second registry entry derived from the registry entry to a network device coupled to the UE gateway device, recording activities with devices in communications with the end-point device into the registry entry, and locking the registry entry in the security registry after a set period of time. Security registries are recorded in network devices and communications with then end-point device may be monitored and alerts provided according to the registry entries for the end-point devices in the security registries.
Claims
exact text as granted — not AI-modified1 . A method of operating a user-equipment (UE) gateway device to establish access for an end-point device coupled to the UE gateway device, comprising:
receiving a connection request from the end-point device; creating a registry entry with a digital identity for the end-point device in a security registry of the UE gateway device; transmitting a second registry entry derived from the registry entry to a network device coupled to the UE gateway device; recording activities with devices in communications with the end-point device into the registry entry; and locking the registry entry in the security registry after a set period of time.
2 . The method of claim 1 , wherein the security registry is a Known Communicators Network (KCN) registry.
3 . The method of claim 2 , wherein the KCN registry is a root KCN registry.
4 . The method of claim 3 , wherein the registry entry in the root KCN registry includes the digital identity for the end-point device, a contract ledger for the end-point device, a predictive device profile for the end-point device, and a secure ID management for the end-point device.
5 . The method of claim 4 , wherein the predictive device profile includes access permissions for connections to the end-point device and an activities log for each of the connections to the end-point device.
6 . The method of claim 5 , further including alerting to an attempted connection to the end-point device that is not supported by the predictive device profile.
7 . The method of claim 4 , wherein the secure ID management assigns unique IDs and security levels for the end-point device.
8 . The method of claim 1 , further including allowing communications with the end-point device that is consistent with the security registry.
9 . The method of claim 1 , wherein the second registry entry is an abstracted registry from the registry entry.
10 . The method of claim 1 , wherein the second registry entry is a full registry from the registry entry.
11 . The method of claim 1 , wherein the end-point device is a user equipment device, an internet-of-things device, an energy network device, or a roaming energy network device.
12 . The method of claim 1 , wherein creating a registry entry includes
requesting authorization from an administrative device coupled to the UE gateway; and receiving authorization from the administrative device.
13 . The method of claim 1 , wherein locking the registry entry includes
requesting authorization from an administrative device coupled to the UE gateway; and receiving authorization from the administrative device.
14 . A method of operating a network device coupled to a user equipment (UE) gateway in connection with an end-point device, comprising:
receiving a registry entry for the end-point device from the UE gateway; storing the registry entry into a security registry on the network device; updating the registry entry when communications with the end-point device is received; locking the registry entry in the security registry when requested by the UE gateway; and alerting when communications with the end-point device is inconsistent with the registry entry in the security registry.
15 . The method of claim 14 , wherein the network device is a distributed unit.
16 . The method of claim 14 , wherein the security registry is a full Known Communicators Network (KCN) registry.
17 . The method of claim 16 , wherein the full KCN registry includes a digital identity for the end-point device, a contract ledger for the end-point device, and a predictive device profile for the end-point device.
18 . The method of claim 17 , wherein the predictive device profile includes access permissions for connections to the end-point device and an activities log for each of the connections to the end-point device.
19 . The method of claim 14 , wherein the security registry is an abstracted Known Communication Network (KCN) registry.
20 . The method of claim 19 , wherein the abstracted KCN registry includes a digital identity for the end-point device, an abstracted contract ledger for the end-point device, and an abstracted predictive device profile for the end-point device.
21 . The method of claim 14 , wherein the security registry is a light Known Communication Network (KCN) registry.
22 . The method of claim 21 , wherein the light KCN registry includes an abstracted predictive device profile that includes the end-point device.
23 . The method of claim 14 , further including
creating a second security registry with other network devices that are coupled to the network device.
24 . The method of claim 23 , wherein the network device is a distributed unit and the security registry is a root KCN registry.
25 . The method of claim 23 , wherein creating a security registry includes, for each other network device,
requesting authentication from an authentication device coupled to the network device; and receiving authentication from the authentication device.
26 . A user-equipment (UE) gateway device, comprising:
a radio device that communications with a network; a router coupled to the radio device; and one or more device interfaces coupled to the router, wherein the router executes instructions to
receive a connection request from an end-point device coupled to the one or more device interfaces;
create a registry entry with a digital identity for the end-point device in a security registry of the UE gateway device;
transmit a second registry entry derived from the registry entry to a network device coupled to the UE gateway;
record activities with devices in communications with the end-point device into the registry entry; and
lock the registry entry in the security registry after a set period of time.
27 . The UE gateway device of claim 26 , wherein the security registry is a Known Communicators Network (KCN) registry.
28 . The UE gateway device of claim 27 , wherein the KCN registry is a root KCN registry.
29 . The UE gateway device of claim 28 , wherein the registry entry in the root KCN registry includes the digital identity for the end-point device, a contract ledger for the end-point device, a predictive device profile for the end-point device, and a secure ID management for the end-point device.
30 . The UE gateway device of claim 29 , wherein the predictive device profile includes access permissions for connections to the end-point device and an activities log for each of the connections to the end-point device.
31 . The UE gateway device of claim 30 , wherein the router further includes instructions to alert to an attempted connection to the end-point device that is not supported by the predictive device profile.
32 . The UE gateway device of claim 29 , wherein the secure ID management assigns unique IDs and security levels for the end-point device.
33 . The UE gateway device of claim 26 , wherein the router further includes instructions to allow communications with the end-point device that is consistent with the security registry.
34 . The UE gateway device of claim 26 , wherein the second registry entry is an abstracted registry from the registry entry.
35 . The UE gateway device of claim 26 , wherein the second registry entry is a full registry from the registry entry.
36 . The UE gateway device of claim 26 , wherein the end-point device is a user equipment device, an internet-of-things device, an energy network device, or a roaming energy network device.
37 . The UE gateway device of claim 26 , wherein the instructions to create a registry entry includes instructions to
request authorization from an administrative device coupled to the UE gateway; and receive authorization from the administrative device.
38 . The UE gateway device of claim 26 , wherein instructions to lock the registry entry includes instructions to
request authorization from an administrative device coupled to the UE gateway; and receive authorization from the administrative device.
39 . A network device, comprising:
a processing platform coupled through a radio unit to user equipment (UE) gateway, the UE gateway being coupled with an end-point device, the processing platform executing instructions to
receive a registry entry for the end-point device from the UE gateway;
store the registry entry into a security registry on the network device;
update the registry entry when communications with the end-point device is received;
lock the registry entry in the security registry when requested by the UE gateway; and
alert when communications with the end-point device is inconsistent with the registry entry in the security registry.
40 . The network device of claim 39 , wherein the network device is a distributed unit.
41 . The network device of claim 39 , wherein the security registry is a full Known Communicators Network (KCN) registry.
42 . The network device of claim 41 , wherein the full KCN registry includes a digital identity for the end-point device, a contract ledger for the end-point device, and a predictive device profile for the end-point device.
43 . The network device of claim 41 , wherein the predictive device profile includes access permissions for connections to the end-point device and an activities log for each of the connections to the end-point device.
44 . The network device of claim 39 , wherein the security registry is an abstracted Known Communication Network (KCN) registry.
45 . The network device of claim 44 , wherein the abstracted KCN registry includes a digital identity for the end-point device, an abstracted contract ledger for the end-point device, and an abstracted predictive device profile for the end-point device.
46 . The network device of claim 39 , wherein the security registry is a light Known Communication Network (KCN) registry.
47 . The network device of claim 46 , wherein the light KCN registry includes an abstracted predictive device profile that includes the end-point device.
48 . The network device of claim 39 , wherein the instructions further include instructions to
create a second security registry with other network devices that are coupled to the network device.
49 . The network device of claim 48 , wherein the network device is a distributed unit and the second security registry is a root KCN registry.
50 . The network device of claim 48 , wherein the instructions to create the second security registry includes, for each other network device, instructions to
request authentication from an authentication device coupled to the network device; and receive authentication from the authentication device.
51 . A network, comprising:
a user equipment (UE) gateway coupled to an end-point device, the UE gateway including a UE security registry that includes the end-point device; a distributed unit (DU) coupled to the UE gateway, the DU including a DU security registry that includes the end-point device; and a central unit (CU) coupled to the DU, the CU including a CU security registry, wherein a communication device attempting to connect with the end-point device is allowed if the communication device has permission as recorded in the UE security registry or the DU security registry and alerts are generated if the communication device does not have permission.
52 . The network of claim 51 , wherein the UE security registry is a root known communicator network (KCN) registry.
53 . The network of claim 52 , wherein the DU security registry is a full KCN registry or a light KCN registry.
54 . The network of claim 53 , wherein the CU security registry is a light KCN registry.
55 . A method of communicating with an end-point device through a user equipment (UE) gateway, comprising:
receiving a communication from a communicating device; determining whether the communicating device has permissions in a UE registry that includes the end-point device; allowing communication if the permissions are in the UE registry; and alerting if the permissions are not in the UE registry.Join the waitlist — get patent alerts
Track US2021105617A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.