IP Library Granted Patent US 11,539,666
Granted Patent B2
US 11,539,666 · App. 16/910,898 · Granted Dec 27, 2022

Method and apparatus for secure communication and routing

Inventors: Charles C. Hohne (Carmel, IN); Todd A. Swails (Greenwood, IN); Christopher J. Nord (Indianapolis, IN); Christopher J. Pulling (Fishers, IN); Kristi Irgens (Breckenridge, CO); Howard Turner (McCordsville, IN); Ian A. Knopf (Indianapolis, IN); Vincent A. Maglio (Fishers, IN); Kyle A. Brown (Fishers, IN)
Assignee: Vertex Aerospace LLC
H04L63/0272G06F9/45558H04W12/037H04W12/06H04W12/088H04W12/121G06F2009/45583G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,666
App. No.
16/910,898
Granted
Dec 27, 2022
Kind
B2
Abstract

An apparatus is provided, comprising: a volatile memory; a non-volatile memory; a first electronic circuit that is configured to operate as a wireless access point, the first electronic circuit including a wireless controller for accessing a wireless network; and a second electronic circuit that is operatively coupled to the first electronic circuit, the second electronic circuit including at least one processor configured to execute: (i) a first virtual machine that includes a wireless network authentication server, and (ii) a second virtual machine that includes a virtual private network (VPN) server, wherein the wireless network authentication server is configured to authenticate devices that attempt to join the wireless network; wherein the VPN server is arranged to encrypt data that is received at the apparatus to produce encrypted data, and forward the encrypted data to the wireless controller for transmission over the wireless network.

Claims (34)

1. An apparatus, comprising:

a volatile memory;

a non-volatile memory;

a first electronic circuit that is configured to operate as a wireless access point, the first electronic circuit including a wireless controller for accessing a wireless network; and

a second electronic circuit that is operatively coupled via a wired connection to the first electronic circuit, the second electronic circuit including at least one processor configured to execute: (i) a first virtual machine that includes a wireless network authentication server, and (ii) a second virtual machine that includes a virtual private network (VPN) server,

wherein the wireless network authentication server is configured to authenticate devices that attempt to join the wireless network;

wherein the VPN server is arranged to encrypt data that is received at the apparatus to produce encrypted data, and forward the encrypted data to the wireless controller for transmission over the wireless network, and

wherein at least one of the first virtual machine or the second virtual machine is fully contained in the volatile memory.

2. The apparatus of claim 1 , wherein the first electronic circuit and the second electronic circuit are coupled to one another via an Ethernet connection, and the encrypted data is forwarded to the second electronic circuit via the Ethernet connection.

3. The apparatus of claim 1 , wherein the first virtual machine is executed in a first partition that is instantiated in the volatile memory, and the second virtual machine is executed in a second partition that is instantiated in the volatile memory, each of the first partition and the second partition having a separate file system.

4. The apparatus of claim 1 , wherein the processor is further configured to execute a hypervisor, the hypervisor being arranged to perform the operations of:

instantiating a random-access memory (RAM) disk in the volatile memory;

partitioning the RAM disk into a plurality of partitions; and

launching each of the first virtual machine and the second virtual machine on a different one of the plurality of partitions.

5. The apparatus of claim 1 , wherein the first electronic circuit includes a first system-on-a-module (SOM) and the second electronic circuit includes a second SOM.

6. The apparatus of claim 1 , wherein the processor is further configured to execute a third virtual machine, the third virtual machine including a firewall that is interposed between the VPN server and the wireless controller, the firewall being configured to monitor data traffic between the VPN server and the wireless controller.

7. The apparatus of claim 1 , wherein the processor is further configured to execute a third virtual machine, the third virtual machine including a manager application, the manager application being arranged to change a configuration setting of at least one of the VPN server and the wireless network authentication server based on maintenance data that is received at the apparatus.

8. The apparatus of claim 7 , wherein the processor is further configured to execute a fourth virtual machine, the fourth virtual machine including a router, the router being arranged to route data that is received at the apparatus to one of the manager application, external Ethernet ports, and the VPN server.

9. The apparatus of claim 7 , wherein the first electronic circuit includes a first system-on-a-module (SOM) and the second electronic circuit includes a second SOM, the second SOM being configured to implement a first virtual network and a second virtual network, the first virtual network being arranged to forward user data to the first SOM, and the second virtual network being arranged to forward maintenance data to the manager application.

10. A method for use in an electronic device that includes a first electronic circuit configured to operate as an access point for accessing a wireless network and a second electronic circuit coupled via wired connection to the first electronic circuit and having a volatile memory and at least one processor, the method comprising:

instantiating a random-access memory (RAM) disk in the volatile memory of the second electronic circuit;

partitioning the RAM disk into a plurality of partitions;

launching a first virtual machine on the second electronic circuit, the first virtual machine being launched in a first partition of the RAM disk, the first virtual machine including a wireless network authentication server that is configured to authenticate devices that attempt to join the wireless network via the first electronic circuit; and

launching a second virtual machine on the second electronic circuit, the second virtual machine being launched in a second partition of the RAM disk, the second virtual machine including a virtual private network (VPN) server that is configured to encrypt data that is received at the apparatus to produce encrypted data, and forward the encrypted data to the first electronic circuit for transmission over the wireless network,

wherein the first virtual machine and the second virtual machine are fully contained in the volatile memory of the second electronic circuit.

11. The method of claim 10 , further comprising:

detecting that a purge switch of the electronic device is activated; and

executing one or more overwrite sequences on the volatile memory of the second electronic circuit to render data of the authentication server and the VPN server unrecoverable.

12. The method of claim 10 , further comprising:

launching a hypervisor on the second electronic circuit when the electronic device is booted,

wherein the RAM disk is instantiated and partitioned by the hypervisor, and

wherein the first virtual machine and the second virtual machine are launched by the hypervisor.

13. The method of claim 10 , further comprising launching a third virtual machine on the second electronic circuit, the third virtual machine being launched in a third partition of the RAM disk, the third virtual machine including a manager application, the manager application being arranged to change a configuration setting of at least one of the VPN server and the wireless network authentication server based on maintenance data that is received at the electronic device.

14. The method of claim 13 , further comprising launching a fourth virtual machine on the second electronic circuit, the fourth virtual machine being launched in a fourth partition of the RAM disk, the fourth virtual machine including a router configured to route data that is received at the apparatus to one of the manager application, external Ethernet ports, and the VPN server.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Mar 2, 2023
From: ALLY BANK, AS COLLATERAL AGENT
To: VERTEX AEROSPACE LLC; VECTRUS SYSTEMS CORPORATION; ADVANTOR SYSTEMS, LLC
Reel/Frame 062927/0061 →
RELEASE OF SECURITY INTEREST Recorded Mar 2, 2023
From: ROYAL BANK OF CANADA
To: VERTEX AEROSPACE LLC; VECTRUS SYSTEMS CORPORATION; ADVANTOR SYSTEMS, LLC
Reel/Frame 062927/0079 →
RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Mar 1, 2023
From: ROYAL BANK OF CANADA
To: VERTEX AEROSPACE LLC; VECTRUS SYSTEMS CORPORATION; ADVANTOR SYSTEMS, LLC
Reel/Frame 062903/0736 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 28, 2023
From: VERTEX AEROSPACE LLC; VECTRUS SYSTEMS CORPORATION; ADVANTOR SYSTEMS, LLC; DELEX SYSTEMS, INCORPORATED; HIGGINS, HERMANSEN, BANIKAS, LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062886/0877 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2022
From: RAYTHEON COMPANY
To: VERTEX AEROSPACE LLC
Reel/Frame 059436/0396 →
SECURITY AGREEMENT Recorded Dec 10, 2021
From: VERTEX AEROSPACE, LLC
To: ALLY BANK, AS COLLATERAL AGENT
Reel/Frame 058957/0428 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 7, 2021
From: VERTEX AEROSPACE LLC
To: ROYAL BANK OF CANADA
Reel/Frame 058342/0027 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 7, 2021
From: VERTEX AEROSPACE LLC
To: ROYAL BANK OF CANADA
Reel/Frame 058342/0046 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2020
From: HOHNE, CHARLES C.; SWAILS, TODD A.; NORD, CHRISTOPHER J.; PULLING, CHRISTOPHER J.; IRGENS, KRISTI; TURNER, HOWARD; KNOPF, IAN A.; MAGLIO, VINCENT A.; BROWN, KYLE A.
To: RAYTHEON COMPANY
Reel/Frame 053164/0064 →
Cited By (1)
US 12,294,567