IP Library › Granted Patent US 12,619,794
Granted Patent B2
US 12,619,794 · App. 18/421,185 · Granted May 5, 2026

Security method and device

Inventor: Simon Vincent (Bristol, GB)
Assignee: Raytheon Systems Limited
G06F21/85G06F21/44G06F21/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,794
App. No.
18/421,185
Granted
May 5, 2026
Kind
B2
Abstract

A security method for a computer, comprising: providing a security device having a communication connection to the computer and a separate communication connection to an external device; and, at the security device: receiving a message having the computer as the intended destination from the external device; verifying the message; and if the message is verified as legitimate, sending a corresponding message to the computer; or if the message is not verified as legitimate, not sending a corresponding message to the computer

Claims (78)

1 . A security method for a computer, the method comprising:

providing a security device connected to a communication port of the computer and having a separate communication connection to an external device to enable communication over a bidirectional link between the computer and the external device and communication over a unidirectional link from the computer to the external device; and

at the security device:

receiving a first message via the bidirectional link having the computer as a first intended destination from the external device;

verifying the first message; and

one of:

if the first message is verified as legitimate, sending a first corresponding message to the computer; or

if the first message is not verified as legitimate, not sending the first corresponding message to the computer; and

in response to receiving a second message via the unidirectional link from the computer to the external device, forwarding the second message to the external device without analysis;

wherein the first corresponding message is modified when sent over the bidirectional link to cause the external device to appear, to the computer, to be an external device having different apparent parameters corresponding to functionality of the external device than actual parameters corresponding to functionality of the external device in a manner limiting exposure of one or more device drivers among a plurality of device drivers of the computer to the external device.

2 . The method of claim 1 , wherein verifying the first message comprises comparing the first message to possible messages that the external device may send to the computer.

3 . The method of claim 1 , further comprising, at the security device:

receiving a third message having the external device as a second intended destination from the computer; and

sending a second corresponding message to the external device;

wherein verifying the first message comprises confirming that the third message having the external device as the second intended destination was received from the computer so that the first message having the computer as the first intended destination received from the external device may be a response to the third message having the external device as the second intended destination received from the computer.

4 . The method of claim 1 , further comprising, at the security device:

receiving a third message having the external device as a second intended destination from the computer;

verifying the third message; and

one of:

if the third message is verified as legitimate, sending a second corresponding message to the external device; or

if the third message is not verified as legitimate, not sending the second corresponding message to the external device.

5 . The method of claim 4 , wherein verifying the third message comprises comparing the third message to possible messages that the computer may send to the external device.

6 . The method of claim 1 , wherein content for the second message forwarded to the external device is identical to content received for the second message.

7 . The method of claim 1 , wherein the first corresponding message is modified from the first message with respect to one or more display parameters.

8 . A security method for a computer, the method comprising:

providing a security device connected to a communication port of to the computer and having a separate communication connection to an external device to enable communication between the computer and the external device; and

at the security device:

sending one or more request for information messages to the external device regarding operation mode capabilities of the external device;

receiving a first message among one or more response messages from the external device indicating operation modes supported by the external device, the first message having the computer as a first intended destination from the external device;

verifying the first message;

one of:

if the first message is verified as legitimate, sending a first corresponding message to the computer; or

if the first message is not verified as legitimate, not sending the first corresponding message to the computer; and

storing data from the one or more response messages;

wherein the first corresponding message is modified to cause the external device to appear, to the computer, to be an external device having different apparent parameters corresponding to operation modes supported by the external device than actual parameters corresponding to operation modes supported by the external device in a manner limiting exposure of one or more device drivers among a plurality of device drivers of the computer to the external device.

9 . The method of claim 1 , wherein the external device is a monitor.

10 . A security device comprising:

a first communications module configured to be connected to a communication port of a computer;

a second communications module configured to be connected to an external device to enable communication over a bidirectional link between the computer and the external device and communication over a unidirectional link from the computer to the external device; and

a processor configured to:

when the second communications module receives a first message via the bidirectional link having the computer as a first intended destination from the external device, verify the first message; and

one of:

if the first message is verified as legitimate, send a first corresponding message from the first communications module to the computer; or

if the first message is not verified as legitimate, not send the first corresponding message to the computer; and

when the first communications module receives a second message via the unidirectional link from the computer to the external device, forward the second message to the external device without analysis;

wherein the first corresponding message is modified when sent over the bidirectional link to cause the external device to appear, to the computer, to be an external device having different apparent parameters corresponding to functionality of the external device than actual parameters corresponding to functionality of the external device in a manner limiting exposure of one or more device drivers among a plurality of device drivers of the computer to the external device.

11 . The security device of claim 10 , wherein, to verify the first message, the processor is configured to compare the first message to possible messages that the external device may send to the computer.

12 . The security device of claim 10 , wherein the processor is further configured to:

receive a third message having the external device as a second intended destination from the computer; and

send a second corresponding message to the external device;

wherein, to verify the first message, the processor is configured to confirm that the third message having the external device as the second intended destination was received from the computer so that the first message having the computer as the first intended destination received from the external device may be a response to the third message having the external device as the second intended destination received from the computer.

13 . The security device of claim 10 , wherein the processor is further configured to:

when the first communications module receives a third message having the external device as a second intended destination from the computer, verify the third message; and

one of:

if the third message is verified as legitimate, send a second corresponding message from the second communications module to the external device; or

if the third message is not verified as legitimate, not send the second corresponding message to the external device.

14 . The security device of claim 13 , wherein, to verify the third message, the processor is configured to compare the third message to possible messages that the computer may send to the external device.

15 . The security device of claim 10 , wherein content for the second message forwarded to the external device is identical to content received for the second message.

16 . The security device of claim 10 , wherein the first corresponding message is modified from the first message with respect to one or more display parameters.

17 . A security device comprising:

a first communications module configured to be connected to a communication port of a computer;

a second communications module configured to be connected to an external device to enable communication over a bidirectional link between the computer and the external device and communication over a unidirectional link from the computer to the external device; and

a processor configured to:

send one or more request for information messages via the second communications module to the external device regarding operation mode capabilities of the external device;

when the second communications module receives a first message among one or more response messages from the external device indicating operation modes supported by the external device, the first message having the computer as a first intended destination from the external device, verify the first message;

one of:

if the first message is verified as legitimate, send a first corresponding message from the first communications module to the computer; or

if the first message is not verified as legitimate, not send the first corresponding message to the computer; and

when the second communications module receives the one or more response messages from the external device, store data from the one or more response messages;

wherein the first corresponding message is modified to cause the external device to appear, to the computer, to be an external device having different apparent parameters corresponding to operation modes supported by the external device than actual parameters corresponding to operation modes supported by the external device in a manner limiting exposure of one or more device drivers among a plurality of device drivers of the computer to the external device.

18 . A non-transitory computer-readable medium comprising instructions that, when executed by a processor of a security device, cause the processor to:

receive a message having a computer as an intended destination from an external device via a bidirectional link at a security device connected to a communication port of the computer and having a separate communication connection to the external device to enable communication over the bidirectional link between the computer and the external device and communication over a unidirectional link from the computer to the external device;

verify the message; and

one of:

if the message is verified as legitimate, send a corresponding message to the computer; or

if the message is not verified as legitimate, not send the corresponding message to the computer; and

in response to receiving a second message via the unidirectional link from the computer to the external device, forward the second message to the external device without analysis;

wherein the corresponding message is modified when sent over the bidirectional link to cause the external device to appear, to the computer, to be an external device having different apparent parameters corresponding to functionality of the external device than actual parameters corresponding to functionality of the external device in a manner limiting exposure of one or more device drivers among a plurality of device drivers of the computer to the external device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2024
From: VINCENT, SIMON
To: RAYTHEON SYSTEMS LIMITED
Reel/Frame 066229/0358 →
Priority Claims (1)
GB 2301092 · Jan 25, 2023 · national
Continuity (1)
Related Publication 20240249034A1 · Jul 25, 2024
References Cited (40)
US 8390842B2 · Shouno · 2013 [cited by examiner]
US 8869308B2 · Soffer · 2014 [cited by applicant]
US 10958983B1 · Soffer · 2021 [cited by examiner]
US 12277086B2 · Robustelli · 2025 [cited by examiner]
US 20040198430A1 · Moriyama · 2004 [cited by examiner]
US 20070079252A1 · Ramnani · 2007 [cited by examiner]
US 20070203682A1 · Gummalla · 2007 [cited by examiner]
US 20070222779A1 · Fastert · 2007 [cited by examiner]
US 20110246756A1 · Smith · 2011 [cited by examiner]
US 20120311207A1 · Powers et al. · 2012 [cited by applicant]
US 20130021351A1 · Chen · 2013 [cited by examiner]
US 20130080662A1 · Bourque · 2013 [cited by examiner]
US 20150365237A1 · Soffer · 2015 [cited by examiner]
US 20160373408A1 · Wentworth · 2016 [cited by examiner]
US 20170229093A1 · Sivertsen · 2017 [cited by examiner]
US 20180137310A1 · Schenk · 2018 [cited by examiner]
US 20180225230A1 · Litichever · 2018 [cited by examiner]
US 20200226087A1 · Sun · 2020 [cited by examiner]
US 20200226298A1 · Appleboum et al. · 2020 [cited by applicant]
US 20200389469A1 · Litichever et al. · 2020 [cited by applicant]
US 20210149441A1 · Bartscherer · 2021 [cited by examiner]
US 20220101814A1 · Patel · 2022 [cited by examiner]
US 20220109680A1 · Plaquin · 2022 [cited by examiner]
US 20230351028A1 · Ponsini · 2023 [cited by examiner]
CN 113553202A · 2021 [cited by examiner]
EP 3651437A1 · 2020 [cited by applicant]
EP 3742324A1 · 2020 [cited by applicant]
WO 2013144962A1 · 2013 [cited by applicant]
Search Report dated Jul. 28, 2023 in connection with United Kingdom Patent Application No. GB2301092.9, 1 page. [cited by applicant]
Examination Report dated Jul. 31, 2023 in connection with United Kingdom Patent Application No. GB2301092.9, 3 pages. [cited by applicant]
Combined Search and Examination Report dated Jul. 31, 2023 in connection with United Kingdom Patent Application No. GB2301092.9, 3 pages. [cited by applicant]
Vincent et al., “DPFuzzer: A platform independent DisplayPort fuzzer,” Raytheon UK presentation, Sep. 2022, 39 pages. [cited by applicant]
Vincent et al., “DPFuzzer: A platform independent DisplayPort fuzzer,” Raytheon UK YouTube presentation with transcript, https://youtu.be/JjaYNTljqjs, Sep. 2022, 14 pages. [cited by applicant]
European Search Report dated Jun. 3, 2024 in connection with European Patent Application No. 24153137.5, 8 pages. [cited by applicant]
Examination Report No. 1 dated Nov. 18, 2024 in connection with Australian Patent Application No. 2024200384, 4 pages. [cited by applicant]
Office Action dated Feb. 14, 2025 in connection with Canadian Patent Application No. 3,227,053, 9 pages. [cited by applicant]
Examination Report dated Nov. 26, 2025 in connection with United Kingdom Patent Application No. GB2301092.9, 4 pages. [cited by applicant]
Examiner requisition dated Feb. 18, 2026 in connection with Canadian Patent Application No. 3,227,053, 5 pages. [cited by applicant]
Microsoft, “Using an INF File to Override EDIDs,” Microsoft Learn, Sep. 2022, 5 pages. [cited by applicant]
Whittaker, “This USB firewall protects against malicious device attacks,” ZDNet, Mar. 2017, 7 pages. [cited by applicant]