Patents Assigned to Secturion Systems, Inc.
-
Patent number: 12634264Abstract: A secure end-to-end communication system is implemented via one or more security processing devices. In one embodiment, a method includes: loading, by a key manager, a first set of keys into a security device; encrypting first data with the first set of keys using the security device; and sending, over a network, the encrypted first data to an external site or a mobile device. The method may further include: requesting the encrypted data from the external site or mobile device; receiving, over the network, the encrypted first data; and decrypting the received encrypted first data with the first set of keys using the security device.Type: GrantFiled: June 7, 2021Date of Patent: May 19, 2026Assignee: SECTURION SYSTEMS, INC.Inventor: Richard J. Takahashi
-
Patent number: 12632395Abstract: A system includes a plurality of data input ports, each port corresponding to one of a plurality of different levels of security classification; a security device, configured for cryptographic processing, coupled to receive incoming data from each of the plurality of input ports, wherein the incoming data includes first data having a first classification level; a key manager configured to select and tag-identified first set of keys from a plurality of key sets, each of the key sets corresponding to one of the different levels of security classification, wherein the first set of keys is used by the security device to encrypt the first data; and a common encrypted data storage, coupled to receive the encrypted first data from the security device for storage.Type: GrantFiled: July 13, 2022Date of Patent: May 19, 2026Assignee: SECTURION SYSTEMS, INC.Inventor: Richard J. Takahashi
-
Patent number: 12596530Abstract: A computing device (e.g., an FPGA or integrated circuit) processes an incoming packet comprising data to compute a Galois hash. The computing device includes a plurality of circuits, each circuit providing a respective result used to determine the Galois hash, and each circuit including: a first multiplier configured to receive a portion of the data; a first exclusive-OR gate configured to receive an output of the first multiplier as a first input, and to provide the respective result; and a second multiplier configured to receive an output of the first exclusive-OR gate, wherein the first exclusive-OR gate is further configured to receive an output of the second multiplier as a second input. In one embodiment, the computing device further comprises a second exclusive-OR gate configured to output the Galois hash, wherein each respective result is provided as an input to the second exclusive-OR gate.Type: GrantFiled: September 7, 2022Date of Patent: April 7, 2026Assignee: SECTURION SYSTEMS, INC.Inventors: Sean Little, Jordan Anderson
-
Patent number: 12513124Abstract: Systems, methods, and apparatus for a MILS HPC, data storage system (DSS) system architecture that incorporates a multi-crypto module (MCM) to provide end-to-end multi-independent level security (MILS) protection. Configuration of each MCM enables a high performance computing (HPC) resource to compute different security domains with the associated security level keys from a key/node manager. The HPC resource can be dynamically re-allocated to different security level domain(s) by the key/node manager. In one embodiment, the DSS stores encrypted data regardless of the domains.Type: GrantFiled: March 21, 2024Date of Patent: December 30, 2025Assignee: SECTURION SYSTEMS, INC.Inventors: Richard J. Takahashi, Timothy Paul Abel, Benjamin Kirk Nielson
-
Publication number: 20250300826Abstract: Systems and methods related to live encryption key rotation. In one approach, an encryption system determines that use of an old key for encrypting data on a storage system is to be replaced with use of a new key. In response to the determination, the encryption system reads a block of data from the storage system that is encrypted with the old key, decrypts the block of data using the old key, encrypts the block of data using the new key, and writes the block of data encrypted with the new key to the storage system. The encryption system also updates a progress indicator that indicates which locations on the storage system store data encrypted with the old key and which locations on the storage system store data encrypted with the new key.Type: ApplicationFiled: November 18, 2024Publication date: September 25, 2025Applicant: Secturion Systems, Inc.Inventor: DEREK OWENS
-
Publication number: 20250158953Abstract: Systems and methods for in-line TCP processing using a systolic array. For example, data received for storage is processed in-line prior to encryption and/or sending to a remote storage device (e.g., cloud storage or server).Type: ApplicationFiled: September 24, 2024Publication date: May 15, 2025Applicant: Secturion Systems, Inc.Inventors: TIMOTHY PAUL ABEL, JACOB FROGGET, DEREK OWENS, JORDAN ANDERSON
-
Publication number: 20240380738Abstract: Systems, methods, and apparatus for a MILS HPC, data storage system (DSS) system architecture that incorporates a multi-crypto module (MCM) to provide end-to-end multi-independent level security (MILS) protection. Configuration of each MCM enables a high performance computing (HPC) resource to compute different security domains with the associated security level keys from a key/node manager. The HPC resource can be dynamically re-allocated to different security level domain(s) by the key/node manager. In one embodiment, the DSS stores encrypted data regardless of the domains.Type: ApplicationFiled: March 21, 2024Publication date: November 14, 2024Applicant: SECTURION SYSTEMS, INC.Inventors: RICHARD J. TAKAHASHI, TIMOTHY PAUL ABEL, BENJAMIN KIRK NIELSON
-
Patent number: 12132699Abstract: Systems and methods for in-line TCP processing using a systolic array. For example, data received for storage is processed in-line prior to encryption and/or sending to a remote storage device (e.g., cloud storage or server).Type: GrantFiled: July 22, 2019Date of Patent: October 29, 2024Assignee: Secturion Systems, Inc.Inventors: Timothy Paul Abel, Jacob Frogget, Derek Owens, Jordan Anderson
-
Publication number: 20240311516Abstract: A system includes programmable systolic cryptographic modules for security processing of packets from a data source. A first programmable input/output interface routes each incoming packet to one of the systolic cryptographic modules for encryption processing. A second programmable input/output interface routes the encrypted packets from the one systolic cryptographic module to a common data storage. In one embodiment, the first programmable input/output interface is coupled to an interchangeable physical interface that receives the incoming packets from the data source. In another embodiment, each cryptographic module includes a programmable systolic packet input engine, a programmable cryptographic engine, and a programmable systolic packet output engine, each configured as a systolic array (e.g., using FPGAs) for data processing.Type: ApplicationFiled: January 22, 2024Publication date: September 19, 2024Applicant: SECTURION SYSTEMS, INC.Inventor: Richard J. Takahashi
-
Publication number: 20240241955Abstract: Apparatus and methods related to securely transmitting data between a portable storage or other medium and a data storage system. In one approach, a portable storage medium drive reads data from a portable storage medium, and a password key decryption unit automatically decrypts the data using a password key in response to having obtained the password key. A storage key encryption unit automatically encrypts the first password key decrypted data using a storage key in response to an availability of the password key decrypted data. A storage interface automatically transmits the storage key encrypted data to the data storage system in response to an availability of the storage key encrypted data.Type: ApplicationFiled: January 8, 2024Publication date: July 18, 2024Applicant: Secturion Systems, Inc.Inventors: RICHARD J. TAKAHASHI, BENJAMIN KIRK NIELSON
-
Publication number: 20240176760Abstract: Systems and methods for protocol processing using a systolic array (e.g., programmed in an FPGA). For example, protocol processing is performed for incoming data (e.g., received for storage) prior to encryption and/or sending to a remote storage device (e.g., cloud storage or server).Type: ApplicationFiled: September 25, 2023Publication date: May 30, 2024Applicant: Secturion Systems, Inc.Inventors: JORDAN ANDERSON, TIMOTHY PAUL ABEL, DEREK OWENS, SEAN LITTLE
-
Patent number: 11968187Abstract: Systems, methods, and apparatus for a MILS HPC, data storage system (DSS) system architecture that incorporates a multi-crypto module (MCM) to provide end-to-end multi-independent level security (MILS) protection. Configuration of each MCM enables a high performance computing (HPC) resource to compute different security domains with the associated security level keys from a key/node manager. The HPC resource can be dynamically re-allocated to different security level domain(s) by the key/node manager. In one embodiment, the DSS stores encrypted data regardless of the domains.Type: GrantFiled: October 21, 2021Date of Patent: April 23, 2024Assignee: SECTURION SYSTEMS, INC.Inventors: Richard J. Takahashi, Timothy Paul Abel, Benjamin Kirk Nielson
-
Publication number: 20240104250Abstract: A system includes a security device, configured for cryptographic processing, coupled to receive incoming data from a plurality of data sources (e.g., data from different customers), wherein the incoming data includes first data from a first data source; a controller (e.g., an external key manager) configured to select a first set of keys from a plurality of key sets, each of the key sets corresponding to one of the plurality of data sources, wherein the first set of keys is used by the security device to encrypt the first data; and a common encrypted data storage, coupled to receive the encrypted first data from the security device.Type: ApplicationFiled: September 1, 2023Publication date: March 28, 2024Applicant: SECTURION SYSTEMS, INC.Inventor: RICHARD J. TAKAHASHI
-
Publication number: 20240098071Abstract: Systems and methods to securely send or write data to a cloud storage or server. In one embodiment, a method includes: establishing a connection to a client using a client-side transport protocol; receiving, over the connection, data from the first client; decrypting, using a client session key, the received data to provide first decrypted data; encrypting the first decrypted data using a stored payload key (that is associated with the client) to provide first encrypted data; encrypting, using a cloud session key, the first encrypted data using a remote-side transport protocol to provide second encrypted data; and sending the second encrypted data to the cloud storage or server.Type: ApplicationFiled: September 7, 2023Publication date: March 21, 2024Applicant: SECTURION SYSTEMS, INC.Inventors: JORDAN ANDERSON, RICHARD J. TAKAHASHI, SEAN LITTLE, LEE NOEHRING
-
Patent number: 11921906Abstract: A system includes programmable systolic cryptographic modules for security processing of packets from a data source. A first programmable input/output interface routes each incoming packet to one of the systolic cryptographic modules for encryption processing. A second programmable input/output interface routes the encrypted packets from the one systolic cryptographic module to a common data storage. In one embodiment, the first programmable input/output interface is coupled to an interchangeable physical interface that receives the incoming packets from the data source. In another embodiment, each cryptographic module includes a programmable systolic packet input engine, a programmable cryptographic engine, and a programmable systolic packet output engine, each configured as a systolic array (e.g., using FPGAs) for data processing.Type: GrantFiled: March 10, 2022Date of Patent: March 5, 2024Assignee: SECTURION SYSTEMS, INC.Inventor: Richard J. Takahashi
-
Publication number: 20240061790Abstract: Systems and methods to securely store data in a remote storage (e.g., cloud storage or server). In one approach, a method includes: receiving, from a local device, data blocks to be stored; generating a hash from a hash of each data block; storing each respective hash (e.g., in a local or remote memory for later use); and writing the data blocks to remote storage. Data integrity is verified when each data block is read from the remote storage by generating a hash of the respective read data block, and comparing the generated hash to the respective stored hash.Type: ApplicationFiled: July 24, 2023Publication date: February 22, 2024Applicant: SECTURION SYSTEMS, INC.Inventor: JORDAN ANDERSON
-
Publication number: 20240064128Abstract: In one embodiment, a method includes: receiving, by a first computing device on a first port of a plurality of ports, a data packet, wherein each of the ports corresponds to one of a plurality of security classes, and the first computing device comprises a plurality of cryptographic modules, each module configured to encrypt data for a respective one of the security classes; tagging the data packet, wherein tagging data identifies one of the security classes and the first port; routing, based on at least one header, the data packet to a first cryptographic module of the plurality of cryptographic modules; encrypting the data packet using the first cryptographic module; and storing the encrypted data packet in a first data storage device.Type: ApplicationFiled: July 25, 2023Publication date: February 22, 2024Applicant: SECTURION SYSTEMS, INC.Inventor: RICHARD J. TAKAHASHI
-
Patent number: 11803507Abstract: Systems and methods for protocol processing using a systolic array (e.g., programmed in an FPGA). For example, protocol processing is performed for incoming data (e.g., received for storage) prior to encryption and/or sending to a remote storage device (e.g., cloud storage or server).Type: GrantFiled: October 16, 2019Date of Patent: October 31, 2023Assignee: SECTURION SYSTEMS, INC.Inventors: Jordan Anderson, Timothy Paul Abel, Derek Owens, Sean Little
-
Patent number: 11792169Abstract: Systems and methods to securely send or write data to a cloud storage or server. In one embodiment, a method includes: establishing a connection to a client using a client-side transport protocol; receiving, over the connection, data from the first client; decrypting, using a client session key, the received data to provide first decrypted data; encrypting the first decrypted data using a stored payload key (that is associated with the client) to provide first encrypted data; encrypting, using a cloud session key, the first encrypted data using a remote-side transport protocol to provide second encrypted data; and sending the second encrypted data to the cloud storage or server.Type: GrantFiled: February 15, 2022Date of Patent: October 17, 2023Assignee: SECTURION SYSTEMS, INC.Inventors: Jordan Anderson, Richard J. Takahashi, Sean Little, Lee Noehring
-
Patent number: 11783089Abstract: A system includes a security device, configured for cryptographic processing, coupled to receive incoming data from a plurality of data sources (e.g., data from different customers), wherein the incoming data includes first data from a first data source; a controller (e.g., an external key manager) configured to select a first set of keys from a plurality of key sets, each of the key sets corresponding to one of the plurality of data sources, wherein the first set of keys is used by the security device to encrypt the first data; and a common encrypted data storage, coupled to receive the encrypted first data from the security device.Type: GrantFiled: December 16, 2020Date of Patent: October 10, 2023Assignee: SECTURION SYSTEMS, INC.Inventor: Richard J. Takahashi