Patents Assigned to Red Balloon Security, Inc.
  • Patent number: 11657169
    Abstract: A system and method of providing pin-level encryption to low-information signals is provided. The system comprises a first system and a second system communicatively coupled together. The second system comprises a signal generator and a one-time pad (OTP) key mixer. An emanator is communicatively coupled to the first system and the second system and is configured to emanate an OTP key to both the first system and the second system. The OTP key mixer is configured to apply the OTP key to a low-information signal from the signal generator prior to transmitting the low-information signal to the first system.
    Type: Grant
    Filed: August 6, 2019
    Date of Patent: May 23, 2023
    Assignee: RED BALLOON SECURITY, INC.
    Inventor: Ang Cui
  • Patent number: 11481519
    Abstract: Methods of sensory input integrity attestation are provided. Artifacts included within devices under test inject a known noise signal into the output signal of one or more output devices that are detectable by one or more input devices (i.e., sensors) of an embedded device, and monitor the received input data. By comparing the received signal against the expected noise signal, attestation of the validity of sensory input data is possible. Such sensory input data attestation is capable either locally or using a remote attestation device with knowledge of the expected data stream.
    Type: Grant
    Filed: November 20, 2020
    Date of Patent: October 25, 2022
    Assignee: RED BALLOON SECURITY, INC.
    Inventors: Ang Cui, Joseph Dean Pantoga
  • Patent number: 11361083
    Abstract: Systems and methods for securing embedded devices via both online and offline defensive strategies. One or more security software components may be injected into firmware binary to create a modified firmware binary, which is functionally- and size-equivalent to the original firmware binary. The security software components may retrieve live forensic information related to embedded devices for use in live hardening of the modified firmware binary while the embedded device is online, dynamically patching the firmware. In addition, the live forensic information may be aggregated with other analytical data identifying firmware vulnerabilities. A vulnerability identification and mitigation system can then identify and inject modifications to the original firmware binary to develop secure firmware binary, which may be imaged and loaded onto one or more embedded devices within a network.
    Type: Grant
    Filed: April 13, 2020
    Date of Patent: June 14, 2022
    Assignee: RED BALLOON SECURITY, INC.
    Inventors: Ang Cui, Salvatore J. Stolfo
  • Patent number: 10872169
    Abstract: Methods of sensory input integrity attestation are provided. Artifacts included within devices under test inject a known noise signal into the output signal of one or more output devices that are detectable by one or more input devices (i.e., sensors) of an embedded device, and monitor the received input data. By comparing the received signal against the expected noise signal, attestation of the validity of sensory input data is possible. Such sensory input data attestation is capable either locally or using a remote attestation device with knowledge of the expected data stream.
    Type: Grant
    Filed: September 28, 2016
    Date of Patent: December 22, 2020
    Assignee: RED BALLOON SECURITY, INC.
    Inventors: Ang Cui, Joseph Dean Pantoga
  • Patent number: 10657262
    Abstract: Systems and methods for securing embedded devices via both online and offline defensive strategies. One or more security software components may be injected into firmware binary to create a modified firmware binary, which is functionally- and size-equivalent to the original firmware binary. The security software components may retrieve live forensic information related to embedded devices for use in live hardening of the modified firmware binary while the embedded device is online, dynamically patching the firmware. In addition, the live forensic information may be aggregated with other analytical data identifying firmware vulnerabilities. A vulnerability identification and mitigation system can then identify and inject modifications to the original firmware binary to develop secure firmware binary, which may be imaged and loaded onto one or more embedded devices within a network.
    Type: Grant
    Filed: September 28, 2015
    Date of Patent: May 19, 2020
    Assignee: RED BALLOON SECURITY, INC.
    Inventors: Ang Cui, Salvatore J. Stolfo
  • Patent number: 10311232
    Abstract: Methods and systems for detection and prevention of exploitation of embedded devices. A sensing component is configured to detect a plurality of emanated analog signals and generate one or more synchronization events. The synchronization events are used to perform one or more attestation analyzes, including execution attestation, integrity attestation, and control-flow reconstruction, the results of which may be used to generate security events.
    Type: Grant
    Filed: November 17, 2016
    Date of Patent: June 4, 2019
    Assignee: RED BALLOON SECURITY, INC.
    Inventor: Ang Cui
  • Publication number: 20170147814
    Abstract: Methods and systems for detection and prevention of exploitation of embedded devices. A sensing component is configured to detect a plurality of emanated analog signals and generate one or more synchronization events. The synchronization events are used to perform one or more attestation analyses, including execution attestation, integrity attestation, and control-flow reconstruction, the results of which may be used to generate security events.
    Type: Application
    Filed: November 17, 2016
    Publication date: May 25, 2017
    Applicant: Red Balloon Security, Inc.
    Inventor: ANG CUI
  • Publication number: 20170094538
    Abstract: Methods of sensory input integrity attestation are provided. Artifacts included within devices under test inject a known noise signal into the output signal of one or more output devices that are detectable by one or more input devices (i.e., sensors) of an embedded device, and monitor the received input data. By comparing the received signal against the expected noise signal, attestation of the validity of sensory input data is possible. Such sensory input data attestation is capable either locally or using a remote attestation device with knowledge of the expected data stream.
    Type: Application
    Filed: September 28, 2016
    Publication date: March 30, 2017
    Applicant: Red Balloon Security, Inc.
    Inventors: Ang CUI, Joseph Dean PANTOGA