IP Library Granted Patent US 12,407,655
Granted Patent B2
US 12,407,655 · App. 18/054,110 · Granted Sep 2, 2025

Unidirectional gateway mediated multiplexing of concurrent data message streams

Inventors: John Curry (New River, AZ); Tzvetan Chaliavski (Arlington, VA); Cosmin Banciu (Raleigh, NC)
Assignee: OPSWAT INC.
H04L63/0281G06F21/53H04L1/1621H04L12/46H04L63/0209H04L63/105G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,655
App. No.
18/054,110
Granted
Sep 2, 2025
Kind
B2
Abstract

A method includes transmitting data by a first interface card in a trusted domain. A second interface card in an untrusted domain receives the data. The second interface card stores the data in a first memory location of a plurality of first memory locations in the untrusted domain and verifies integrity of the data. The second interface card writes a result of the verifying in a second memory location of a plurality of second memory locations in the untrusted domain. The first interface card retrieves the result of the verifying from the second memory location of the plurality of second memory locations in the untrusted domain. The first interface card creates a table configured to identify and track a state of the second memory location of the plurality of second memory locations in the untrusted domain corresponding to the data received from the first interface card in the trusted domain.

Claims (39)

1. A method comprising:

transmitting, by a first interface card in a trusted domain, data;

receiving, by a second interface card in an untrusted domain, the data;

storing, by the second interface card, the data in a first memory location of a plurality of first memory locations in the untrusted domain;

verifying, by the second interface card, integrity of the data;

writing, by the second interface card, a result of the verifying in a second memory location of a plurality of second memory locations in the untrusted domain;

retrieving, by the first interface card in the trusted domain, the result of the verifying from the second memory location of the plurality of second memory locations in the untrusted domain; and

creating, by the first interface card in the trusted domain, a table configured to identify and track a state of the second memory location of the plurality of second memory locations in the untrusted domain corresponding to the data received from the first interface card in the trusted domain.

2. The method of claim 1 , wherein the table identifies and tracks the state of the plurality of second memory locations in the untrusted domain corresponding to the data received from the first interface card in the trusted domain.

3. The method of claim 1 , wherein the table comprises metadata defining the state of the plurality of second memory locations.

4. The method of claim 1 , further comprising:

multiplexing, based on the table, an interleaving of the data across a non-networked connection between the first interface card in the trusted domain and the second interface card in the untrusted domain.

5. The method of claim 1 , further comprising:

interrogating, by the first interface card in the trusted domain, the plurality of second memory locations or a subset of the plurality of second memory locations to obtain the state of the plurality of second memory locations or the subset of the plurality of second memory locations.

6. The method of claim 1 , wherein only the second interface card in the untrusted domain has access to the plurality of first memory locations in the untrusted domain.

7. The method of claim 1 , wherein the first interface card in the trusted domain and the second interface card in the untrusted domain are directly physically connected to one another by a cable.

8. The method of claim 1 , wherein communication between the first interface card and the second interface card is unidirectional with a non-networked connection.

9. The method of claim 1 , wherein:

the first interface card and the second interface card are Peripheral Component Interconnect Express (PCIe) interface cards; and

a communication protocol between the first interface card and the second interface card is a non-routable schema.

10. The method of claim 1 , wherein the result is good, indicating the data was received by the second interface card, or the result is bad, indicating the data was not received by the second interface card.

11. The method of claim 1 , further comprising:

comparing, by the first interface card, the result to a predetermined benchmark value; and

when the result matches the predetermined benchmark value in the comparing, determining the data was received by the second interface card.

12. A method comprising:

transmitting, by a first interface card in a trusted domain, data to a second interface card in an untrusted domain, wherein communication between the first interface card and the second interface card is unidirectional with a non-networked connection;

retrieving, by the first interface card in the trusted domain, a result from a memory location of a plurality of memory locations in the untrusted domain; and

creating, by the first interface card in the trusted domain, a table configured to identify and track a state of the memory location of the plurality of memory locations in the untrusted domain corresponding to the data received from the first interface card in the trusted domain.

13. The method of claim 12 , wherein the table identifies and tracks the state of the plurality of second memory locations in the untrusted domain corresponding to the data received from the first interface card in the trusted domain.

14. The method of claim 12 , wherein the table comprises metadata defining the state of the plurality of memory locations.

15. The method of claim 12 , further comprising:

multiplexing, based on the table, an interleaving of the data across a non-networked connection between the first interface card in the trusted domain and the second interface card in the untrusted domain.

16. The method of claim 12 , further comprising:

interrogating, by the first interface card in the trusted domain, the plurality of memory locations or a subset of the plurality of memory locations to obtain the state of the plurality of memory locations or the subset of the plurality of memory locations.

17. The method of claim 12 , wherein the first interface card in the trusted domain and the second interface card in the untrusted domain are directly physically connected to one another by a cable.

18. The method of claim 12 , wherein the result is good, indicating the data was received by the second interface card, or the result is bad, indicating the data was not received by the second interface card.

19. The method of claim 12 , further comprising:

comparing, by the first interface card, the result to a predetermined benchmark value; and

when the result matches the predetermined benchmark value in the comparing, determining the data was received by the second interface card.

Assignments (2)
SECURITY INTEREST Recorded Dec 29, 2022
From: OPSWAT INC.
To: CITIBANK, N.A.
Reel/Frame 062236/0124 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2022
From: CURRY, JOHN; CHALIAVSKI, TZVETAN; BANCIU, COSMIN
To: OPSWAT INC.
Reel/Frame 061721/0727 →
Continuity (3)
Continuation PCTUS2021034815 · May 28, 2021
Provisional Application 63032966 · Jun 1, 2020
Related Publication 20230087954A1 · Mar 23, 2023
References Cited (29)
US 7904565B2 · Holden et al. · 2011 [cited by applicant]
US 9819679B1 · Bertz et al. · 2017 [cited by applicant]
US 11960596B2 · Pope · 2024 [cited by examiner]
US 20050033990A1 · Harvey et al. · 2005 [cited by applicant]
US 20080220879A1 · Barrie et al. · 2008 [cited by applicant]
US 20100115027A1 · Ryu et al. · 2010 [cited by applicant]
US 20100169392A1 · Ran et al. · 2010 [cited by applicant]
US 20120017079A1 · Mraz et al. · 2012 [cited by applicant]
US 20130067023A1 · Joy et al. · 2013 [cited by applicant]
US 20130345530A1 · McRoberts et al. · 2013 [cited by applicant]
US 20150039891A1 · Ignatchenko et al. · 2015 [cited by applicant]
US 20150067104A1 · Curry et al. · 2015 [cited by applicant]
US 20150074767A1 · Clark · 2015 [cited by applicant]
US 20150181484A1 · Bruhn et al. · 2015 [cited by applicant]
US 20160034702A1 · Sikka · 2016 [cited by applicant]
US 20160119289A1 · Jain et al. · 2016 [cited by applicant]
US 20160306995A1 · Arasu et al. · 2016 [cited by applicant]
US 20190005254A1 · Arasu et al. · 2019 [cited by applicant]
US 20190095488A1 · Bhattacharjee et al. · 2019 [cited by applicant]
US 20190173919A1 · Irimie et al. · 2019 [cited by applicant]
US 20200259585A1 · Aust et al. · 2020 [cited by applicant]
US 20220174047A1 · Curry · 2022 [cited by examiner]
Office Action dated Dec. 11, 2023 for U.S. Appl. No. 18/054,107. [cited by applicant]
International Search Report and Written Opinion dated Nov. 2, 2021 for PCT Patent Application No. PCT/US2021/034725. [cited by applicant]
International Search Report and Written Opinion dated Oct. 4, 2021 for PCT Patent Application No. PCT/US2021/034815. [cited by applicant]
“User-Level Network Interface Protocols”; Bhoedjang et al.; Computer ( vol. 31, Issue: 11, Nov. 1998) (Year: 1998). [cited by applicant]
Office Action dated Apr. 11, 2023 for U.S. Appl. No. 17/651,387. [cited by applicant]
Notice of Allowance and Fees dated Sep. 12, 2024 for U.S. Appl. No. 18/054,107. [cited by applicant]
Notice of Allowance and Fees dated Aug. 31, 2023 for U.S. Appl. No. 17/651,387. [cited by applicant]