IP Library Granted Patent US 12,199,889
Granted Patent B2
US 12,199,889 · App. 18/054,107 · Granted Jan 14, 2025

Unidirectional gateway mediated delivery of data messages

Inventors: John Curry (New River, AZ); Tzvetan Chaliavski (Arlington, VA); Cosmin Banciu (Raleigh, NC)
Assignee: OPSWAT Inc.
H04L49/9068H04L12/46
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,889
App. No.
18/054,107
Granted
Jan 14, 2025
Kind
B2
Abstract

A method includes transmitting, by a first interface card in a trusted domain, data. A second interface card in an untrusted domain receives the data. The second interface card stores the data to a first memory location in the untrusted domain, and verifies integrity of the data. The second interface card writes a result of the verifying in a second memory location in the untrusted domain. The first interface card in the trusted domain retrieves the result of the verifying from the second memory location in the untrusted domain. The first interface card in the trusted domain determines if the data in the transmitting was received by the second interface card based on the result.

Claims (45)

1. A method comprising:

transmitting, by a first interface card in a trusted domain, data;

receiving, by a second interface card in an untrusted domain, the data;

storing, by the second interface card, the data to a first memory location in the untrusted domain;

verifying, by the second interface card, integrity of the data;

writing, by the second interface card, a result of the verifying in a second memory location in the untrusted domain;

retrieving, by the first interface card in the trusted domain, the result of the verifying from the second memory location in the untrusted domain; and

determining, by the first interface card in the trusted domain, if the data in the transmitting was received by the second interface card based on the result;

wherein communication between the first interface card and the second interface card is unidirectional from the first interface card to the second interface card and does not involve another interface card, and the data and content cannot be received in the trusted domain from the untrusted domain.

2. The method of claim 1 , wherein the result is good, indicating the data was received by the second interface card, or the result is bad, indicating the data was not received by the second interface card.

3. The method of claim 1 , further comprising:

comparing, by the first interface card, the result to a predetermined benchmark value; and

when the result matches the predetermined benchmark value in the comparing, determining the data was received by the second interface card.

4. The method of claim 1 , wherein only the second interface card in the untrusted domain has access to the first memory location in the untrusted domain.

5. The method of claim 1 , wherein the verifying performs a series of validity checks in a proprietary communications protocol.

6. The method of claim 1 , wherein the first interface card in the trusted domain and the second interface card in the untrusted domain are directly physically connected to one another by a cable.

7. The method of claim 1 , wherein communication between the first interface card and the second interface card is with a non-networked connection.

8. The method of claim 1 , wherein:

the first interface card and the second interface card are Peripheral Component Interconnect Express (PCIe) interface cards; and

a communication protocol between the first interface card and the second interface card is a non-routable schema.

9. A method comprising:

transmitting, by a first interface card in a trusted domain, data to a second interface card in an untrusted domain, wherein communication between the first interface card and the second interface card is unidirectional from the first interface card to the second interface card and does not involve another interface card, and the data and content cannot be received in the trusted domain from the untrusted domain;

retrieving, by the first interface card in the trusted domain, a result from a memory location in the untrusted domain; and

determining, by the first interface card in the trusted domain, if the data in the transmitting was received by the second interface card based on the result.

10. The method of claim 9 , wherein the result is good, indicating the data was received by the second interface card, or the result is bad, indicating the data was not received by the second interface card.

11. The method of claim 9 , further comprising:

comparing, by the first interface card, the result to a predetermined benchmark value; and

when the result matches the predetermined benchmark value in the comparing, determining the data was received by the second interface card.

12. The method of claim 9 , wherein the first interface card in the trusted domain and the second interface card in the untrusted domain are directly physically connected to one another by a cable.

13. The method of claim 9 , wherein:

the first interface card and the second interface card are Peripheral Component Interconnect Express (PCIe) interface cards; and

a communication protocol between the first interface card and the second interface card is a non-routable schema.

14. A method comprising:

receiving, by a second interface card in an untrusted domain, data from a first interface card in a trusted domain, wherein communication between the first interface card and the second interface card is unidirectional from the first interface card to the second interface card and does not involve another interface card, and the data and content cannot be received in the trusted domain from the untrusted domain;

storing, by the second interface card, the data to a first memory location in the untrusted domain;

verifying, by the second interface card, integrity of the data; and

writing, by the second interface card, a result of the verifying in a second memory location in the untrusted domain;

wherein the result of the verifying can be read by the first interface card.

15. The method of claim 14 , wherein the result is good, indicating the data was received by the second interface card, or the result is bad, indicating the data was not received by the second interface card.

16. The method of claim 14 , wherein only the second interface card in the untrusted domain has access to the first memory location in the untrusted domain.

17. The method of claim 14 , wherein the verifying performs a series of validity checks in a proprietary communications protocol.

18. The method of claim 14 , wherein the first interface card in the trusted domain and the second interface card in the untrusted domain are directly physically connected to one another by a cable.

19. The method of claim 14 , wherein:

the first interface card and the second interface card are Peripheral Component Interconnect Express (PCIe) interface cards; and

a communication protocol between the first interface card and the second interface card is a non-routable schema.

Assignments (3)
SECURITY INTEREST Recorded Dec 29, 2022
From: OPSWAT INC.
To: CITIBANK, N.A.
Reel/Frame 062236/0124 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2022
From: CURRY, JOHN; CHALIAVSKI, TZVETAN; BANCIU, COSMIN
To: OPSWAT, INC.
Reel/Frame 061718/0757 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2022
From: CURRY, JOHN; CHALIAVSKI, TZVETAN; BANCIU, COSMIN
To: OPSWAT INC.
Reel/Frame 061721/0680 →
Continuity (3)
Continuation PCTUS2021034725 · May 28, 2021
Provisional Application 63032962 · Jun 1, 2020
Related Publication 20230085632A1 · Mar 23, 2023
References Cited (26)
US 7904565B2 · Holden · 2011 [cited by examiner]
US 9819679B1 · Bertz · 2017 [cited by examiner]
US 20050033990A1 · Harvey · 2005 [cited by examiner]
US 20080220879A1 · Barrie · 2008 [cited by examiner]
US 20100115027A1 · Ryu et al. · 2010 [cited by applicant]
US 20100169392A1 · Ran et al. · 2010 [cited by applicant]
US 20120017079A1 · Mraz · 2012 [cited by examiner]
US 20130067023A1 · Joy et al. · 2013 [cited by applicant]
US 20130345530A1 · McRoberts · 2013 [cited by examiner]
US 20150039891A1 · Ignatchenko · 2015 [cited by examiner]
US 20150067104A1 · Curry · 2015 [cited by examiner]
US 20150074767A1 · Clark · 2015 [cited by applicant]
US 20150181484A1 · Bruhn · 2015 [cited by examiner]
US 20160034702A1 · Sikka · 2016 [cited by applicant]
US 20160119289A1 · Jain · 2016 [cited by examiner]
US 20160306995A1 · Arasu et al. · 2016 [cited by applicant]
US 20190005254A1 · Arasu et al. · 2019 [cited by applicant]
US 20190095488A1 · Bhattacharjee et al. · 2019 [cited by applicant]
US 20190173919A1 · Irimie et al. · 2019 [cited by applicant]
US 20200259585A1 · Aust · 2020 [cited by examiner]
US 20220174047A1 · Curry et al. · 2022 [cited by applicant]
International Search Report and Written Opinion dated Nov. 2, 2021 for PCT Patent Application No. PCT/US2021/034725. [cited by applicant]
International Search Report and Written Opinion dated Oct. 4, 2021 for PCT Patent Application No. PCT/US2021/034815. [cited by applicant]
“User-Level Network Interface Protocols”; Bhoedjang et al.; Computer ( vol. 31, Issue: 11, Nov. 1998) (Year: 1998). [cited by applicant]
Office Action dated Apr. 11, 2023 for U.S. Appl. No. 17/651,387. [cited by applicant]
Notice of Allowance and Fees dated Aug. 31, 2023 for U.S. Appl. No. 17/651,387. [cited by applicant]