Patents by Inventor Mohammed I. Alghannam

Mohammed I. Alghannam has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20240187491
    Abstract: A system and method can include receiving a data packet at a low-side network element of a unidirectional, bilateral network system; transmitting the data packet to a primary high-side network element through a primary one-way data diode; and transmitting a duplicate of the data packet to a secondary high-side network element through a unidirectional cross-communications link. The system and method can also involve receiving, at the secondary high-side network element, a health status from the primary high-side network element; determining, by the secondary high-side network element, that the primary high-side network element is experiencing a fault condition based on the health status; and transmitting the data packet towards a data destination based on the determination that the primary high-side network element is experiencing the fault condition.
    Type: Application
    Filed: December 1, 2022
    Publication date: June 6, 2024
    Inventors: Mohammed I. Alghannam, Nasser S. Alharthi
  • Patent number: 11888869
    Abstract: A system, a method, and a computer program are provided for securely isolating access by one or more users in a group of network users to an enterprise network implementing Multi-Protocol Label Switching (MPLS). The security system includes an MPLS Layer-3 VPN (L3VPN) instance created for a group of users to be isolated, and a remote and mobile enterprise access (RMEA) gateway with secure socket layer virtual private network (SSL-VPN) and two-factor user authentication capabilities. A de-militarized zone (DMZ) is positioned in the network to security scan data traffic between the L3VPN and RMEA gateway. The security protocol involves two-factor user authentication and establishing, on top of the L3VPN instance, an SSL-VPN session between the user and the RMEA gateway, which provides the authorized user access to the network. Additionally, data traffic to/from the user is routed through the RMEA and the DMZ.
    Type: Grant
    Filed: September 2, 2021
    Date of Patent: January 30, 2024
    Assignee: SAUDI ARABIAN OIL COMPANY
    Inventors: Mohammed I. Alghannam, Ahmad A. Alharbi
  • Publication number: 20230065575
    Abstract: A system, a method, and a computer program are provided for securely isolating access by one or more users in a group of network users to an enterprise network implementing Multi-Protocol Label Switching (MPLS). The security system includes an MPLS Layer-3 VPN (L3VPN) instance created for a group of users to be isolated, and a remote and mobile enterprise access (RMEA) gateway with secure socket layer virtual private network (SSL-VPN) and two-factor user authentication capabilities. A de-militarized zone (DMZ) is positioned in the network to security scan data traffic between the L3VPN and RMEA gateway. The security protocol involves two-factor user authentication and establishing, on top of the L3VPN instance, an SSL-VPN session between the user and the RMEA gateway, which provides the authorized user access to the network. Additionally, data traffic to/from the user is routed through the RMEA and the DMZ.
    Type: Application
    Filed: September 2, 2021
    Publication date: March 2, 2023
    Inventors: Mohammed I. Alghannam, Ahmad A. Alharbi
  • Patent number: 11582193
    Abstract: A system, a method, and a computer program are provided for securely connecting a main network to one or more subnetworks in an enterprise network through a group of enterprise routers has all data traffic routed between the main network and the subnetwork through an encrypted virtual private network (VPN) tunnel. The data traffic is monitored for a cyberthreat indication in the enterprise network, and any cyberthreat indication is has the cyberthreat remediated by modifying a policy in a firewall or one of the group of enterprise routers to stop routing exchange or cease encryption or transmission of data between the main network and the one or more subnetworks. In part, a key server and each router and the group of enterprise routers is configured with an Internet Protocol address, a group security association value, and a group profile which are employed by the technological solution for secure enterprise connectivity.
    Type: Grant
    Filed: September 16, 2019
    Date of Patent: February 14, 2023
    Assignee: SAUDI ARABIAN OIL COMPANY
    Inventors: Ahmad A. Alharbi, Mohammed I. Alghannam
  • Publication number: 20210084010
    Abstract: A system, a method, and a computer program are provided for securely connecting a main network to one or more subnetworks in an enterprise network through a group of enterprise routers has all data traffic routed between the main network and the subnetwork through an encrypted virtual private network (VPN) tunnel. The data traffic is monitored for a cyberthreat indication in the enterprise network, and any cyberthreat indication is has the cyberthreat remediated by modifying a policy in a firewall or one of the group of enterprise routers to stop routing exchange or cease encryption or transmission of data between the main network and the one or more subnetworks. In part, a key server and each router and the group of enterprise routers is configured with an Internet Protocol address, a group security association value, and a group profile which are employed by the technological solution for secure enterprise connectivity.
    Type: Application
    Filed: September 16, 2019
    Publication date: March 18, 2021
    Inventors: Ahmad A. Alharbi, Mohammed I. Alghannam