Tracking Tainted Connection Agents
Abstract
Methods and systems for tracking tainted connection agents, such as without a trusted central authority, are described herein. During a server outage, a client device may verify that a connection agent is untainted based on a public-key encryption or certificate-based system. If the connection agent is untainted, a server may sign a public key or certificate associated with the connection agent. The server may provide, to the client device, a lease, a public key associated with the server. The connection agent may sign data generated by the client device. The client device may verify a signature of the signed public key, such as based on the public key associated with the server. The client device may verify a signature of the signed data, such as based on the verified public key associated with the connection agent.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving, by a client device and from one or more servers, a public key of the one or more servers; receiving, by the client device and from a computing device, information comprising:
a public key, of the computing device, signed by a private key of the one or more servers; and
data generated by the client device and signed by a private key of the computing device; and
determining, by the client device, whether a signature of the signed public key of the computing device corresponds to the public key of the one or more servers.
2 . The method of claim 1 , wherein the receiving the public key of the one or more servers comprises issuing, by the one or more servers to the client device, a connection lease.
3 . The method of claim 2 , further comprising:
based on a determination that the signature of the signed public key of the computing device does not correspond with the public key of the one or more servers, connecting, by the client device, to a second computing device identified in the connection lease.
4 . The method of claim 2 , further comprising:
based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determining, by the client device, whether a signature of the signed data corresponds to the signed public key of the computing device.
5 . The method of claim 4 , further comprising:
based on a determination that the signature of the signed data does not correspond to the signed public key of the computing device, connecting, by the client device, to a second computing device identified in the connection lease.
6 . The method of claim 4 , further comprising:
based on a determination that the signature of the signed data corresponds to the signed public key of the computing device, connecting, by the client device, to the computing device.
7 . The method of claim 1 , further comprising:
receiving, by the client device and from the one or more servers, a second public key of the one or more servers; and verifying, by the client device and based on the second public key of the one or more servers, the signed public key of the computing device.
8 . The method of claim 1 , wherein the signed public key of the computing device comprises one or more of a machine ID or an expiration date.
9 . One or more non-transitory computer readable media storing computer readable instructions that, when executed, cause a client device to:
receive, from one or more servers, a public key of the one or more servers; receive, from a computing device, information comprising:
a public key, of the computing device, signed by a private key of the one or more servers; and
data generated by the client device and signed by a private key of the computing device; and
determine whether a signature of the signed public key of the computing device corresponds to the public key of the one or more servers.
10 . The one or more non-transitory computer-readable media of claim 9 , wherein the public key associated with the one or more servers is associated with a connection lease issued by the one or more servers to the client device.
11 . The one or more non-transitory computer-readable media of claim 10 , wherein the computer readable instructions, when executed, further cause the client device to:
based on a determination that the signature of the signed public key of the computing device does not correspond with the public key of the one or more servers, connect to a second computing device identified in the connection lease.
12 . The one or more non-transitory computer-readable media of claim 10 , wherein the computer readable instructions, when executed, further cause the client device to:
based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and based on a determination that the signature of the signed data does not correspond to the signed public key of the computing device, connect to a second computing device identified in the connection lease.
13 . The one or more non-transitory computer-readable media of claim 10 , wherein the computer readable instructions, when executed, further cause the client device to:
based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and based on a determination that the signature of the signed data corresponds to the signed public key of the computing device, connect to the computing device.
14 . The one or more non-transitory computer-readable media of claim 9 , wherein the computer readable instructions, when executed, further cause the client device to:
receive, from the one or more servers, a second public key associated with the one or more servers; and verify, based on the second public key associated with the one or more servers, the signed public key of the computing device.
15 . An apparatus comprising:
one or more processors; and memory storing executable instructions that, when executed by the one or more processors, cause the apparatus to: receive, from one or more servers, a public key of the one or more servers; receive, from a computing device, information comprising:
a public key, of the computing device, signed by a private key of the one or more servers; and
data generated by the apparatus and signed by a private key of the computing device; and
determine whether a signature of the signed public key of the computing device corresponds to the public key of the one or more servers.
16 . The apparatus of claim 15 , wherein the public key associated with the one or more servers is associated with a connection lease issued by the one or more servers to the apparatus.
17 . The apparatus of claim 16 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
based on a determination that the signature of the signed public key of the computing device does not correspond with the public key of the one or more servers, connect to a second computing device identified in the connection lease.
18 . The apparatus of claim 16 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and based on a determination that the signature of the signed data does not correspond to the signed public key of the computing device, connect to a second computing device identified in the connection lease.
19 . The apparatus of claim 16 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
based on a determination that the signature of the signed public key of the computing device corresponds to the public key of the one or more servers, determine whether a signature of the signed data corresponds to the signed public key of the computing device; and based on a determination that the signature of the signed data corresponds to the signed public key of the computing device, connect to the computing device.
20 . The apparatus of claim 15 , wherein the executable instructions, when executed by the one or more processors, further cause the apparatus to:
receive, from the one or more servers, a second public key associated with the one or more servers; and verify, based on the second public key associated with the one or more servers, the signed public key of the computing device.Join the waitlist — get patent alerts
Track US2022021532A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.