Protocol isolation for security

US11178113B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11178113-B2
Application numberUS-201916526571-A
CountryUS
Kind codeB2
Filing dateJul 30, 2019
Priority dateJul 30, 2019
Publication dateNov 16, 2021
Grant dateNov 16, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In accordance with some embodiments, a first apparatus that provides protocol isolation includes a controller, one or more re-configurable data communication devices operable to provide alternative transport of data for a native data communication device on a second apparatus to an external device, and one or more data converters coupled to the one or more re-configurable data communication devices. The protocol isolation method performed by the first apparatus includes establishing a local communication channel with the second apparatus. The method further includes exchanging the data via the local communication channel with the second apparatus according to a first protocol. The method also includes converting the data to a second protocol different from the first protocol. The method additionally includes exchanging, via a first re-configurable data communication device of the one or more re-configurable data communication devices, the converted data with the external device according to the second protocol.

First claim

Opening claim text (preview).

What is claimed is: 1. An apparatus comprising: a first re-configurable data communication device operable to provide alternative transport of data for a native data communication device on a second device; a first data converter, coupled to the first re-configurable data communication device, operable to convert between a first protocol and a second protocol different from the first protocol; a controller, connected to the first re-configurable data communication device, operable to manage alternative transport of the data between the second device and an external device through the first re-configurable data communication device and the first data converter; and a housing arranged to at least partially support the first re-configurable data communication device, the first data converter, and the controller. 2. The apparatus of claim 1 , wherein the data includes malicious control messages according to the second protocol for controlling the first re-configurable data communication device. 3. The apparatus of claim 1 , further comprising a second re-configurable data communication device connectable to the second device, and coupled to the first data converter, operable to provide alternative transport of the data for the native data communication device on the second device. 4. The apparatus of claim 1 , wherein the native data communication device or the first re-configurable data communication device includes at least one of a Wi-Fi device, a cellular device, or a Bluetooth device. 5. The apparatus of claim 1 , wherein the controller is connected to the first re-configurable data communication device via a non-Direct Memory Access (DMA) channel. 6. The apparatus of claim 1 , wherein the controller is connected to the first re-configurable data communication device via a second data converter. 7. The apparatus of claim 1 , wherein the first re-configurable data communication device includes a second data converter, the second data converter is operable to convert between the second protocol and a third protocol. 8. The apparatus of claim 1 , further comprising a first communication device, at least partially supported by the housing, connectable to a second communication device on the second device in order to establish a local communication channel. 9. The apparatus of claim 8 , wherein the local communication channel is through a wired connection or a wireless connection. 10. The apparatus of claim 8 , wherein the controller is further operable to, via the local communication channel, disable the native data communication device on the second device. 11. A method comprising: at a first apparatus including a controller, one or more re-configurable data communication devices operable to provide alternative transport of data for a native data communication device on a second apparatus to an external device, and one or more data converters coupled to the one or more re-configurable data communication devices: establishing a local communication channel with the second apparatus; exchanging the data via the local communication channel with the second apparatus according to a first protocol; converting the data to a second protocol different from the first protocol; and exchanging, via a first re-configurable data communication device of the one or more re-configurable data communication devices, the converted data with the external device according to the second protocol. 12. The method of claim 11 , wherein the native data communication device or the first re-configurable data communication device includes at least one of a USB device, a Wi-Fi device, a cellular device, or a Bluetooth device. 13. The method of claim 11 , wherein the local communication channel is through a wired connection or a wireless connection. 14. The method of claim 11 , further comprising: directing by the controller, via the local communication channel, the second apparatus to disable the native data communication device. 15. The method of claim 11 , wherein converting the data to the second protocol different from the first protocol includes: converting the data according to a third protocol to generate a first set of data; and converting the first set of data according to the second protocol to generate the converted data. 16. The method of claim 15 , wherein converting the data according to the third protocol is performed by a first data converter of the one or more data converters and converting the first set of data according to the second protocol is performed by a second data converter of the one or more data converters, different from the first data converter. 17. The method of claim 15 , wherein: at least one of converting the data according to the third protocol or converting the first set of data according to the second protocol is performed by a second re-configurable data communication device of the one or more re-configurable data communication devices, the second re-configurable data communication device including a data converter of the one or more data converters. 18. The method of claim 11 , wherein exchanging the converted data with the external device according to the second protocol includes: establishing, via the first re-configurable data communication device of the one or more re-configurable data communication devices, a remote communication channel with the external device according to the second protocol; and exchanging the converted data with the external device through the remote communication channel. 19. The method of claim 11 , further comprising: exchanging messages between the controller and the first re-configurable data communication device via a non-DMA channel. 20. The method of claim 11 , wherein the data includes malicious control messages according to the second protocol for controlling the first re-configurable data communication device.

Assignees

Inventors

Classifications

  • H04L69/08Primary

    Protocols for interworking; Protocol conversion · CPC title

  • H04L63/029Primary

    Firewall traversal, e.g. tunnelling or, creating pinholes · CPC title

  • Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication · CPC title

  • Multiprotocol handlers, e.g. single devices capable of handling multiple protocols · CPC title

  • using different networks or channels, e.g. using out of band channels (cryptographic mechanisms or cryptographic arrangements for key distribution involving distinctive intermediate devices or communication paths H04L9/0827; cryptographic mechanisms or cryptographic arrangements for authentication using a plurality of channels H04L9/3215) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11178113B2 cover?
In accordance with some embodiments, a first apparatus that provides protocol isolation includes a controller, one or more re-configurable data communication devices operable to provide alternative transport of data for a native data communication device on a second apparatus to an external device, and one or more data converters coupled to the one or more re-configurable data communication dev…
Who is the assignee on this patent?
Ppip Llc
What technology area does this patent fall under?
Primary CPC classification H04L69/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 16 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).