Patents by Inventor James Marek

James Marek has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11601277
    Abstract: A first cryptographic communication system is disclosed. The first cryptographic communication system includes a common hardware module configured to receive local cryptographic signals and coalition cryptographic signals that includes a transmitter, a receiver, a common router, a trusted router, and a data loader. The first cryptographic communication system further includes a local cryptographic assembly and a coalition cryptographic assembly each including and end cryptographic unit communicatively coupled to the trusted router, a cross domain guard communicatively coupled to the end cryptographic unit and the trusted router, and a general purpose security module communicatively coupled to the cross domain guard. The first cryptographic communication system further includes a data recoding module communicatively coupled to the data loader that includes local and coalition data recording devices.
    Type: Grant
    Filed: November 20, 2020
    Date of Patent: March 7, 2023
    Assignee: Rockwell Collins, Inc.
    Inventors: Reginald D. Bean, James A. Marek, Edward C. Tubbs
  • Patent number: 11546176
    Abstract: A method of remotely initializing at least one device is disclosed. The method includes initializing at a local host a cryptographic authorization sequence after receiving a secure input value. The method further includes receiving at a local host cryptographic controller a first authorization request from a first remote device. After a challenge-response authentication protocol, the first remote device is authenticated and receives a public key infrastructure certificate. The method includes receiving at a first remote cryptographic controller a second request from a second remote device. After a challenge-response authentication protocol, the first remote device is authenticated, but does not receive a public key infrastructure certificate. A system for remotely initiating at least one device is also disclosed.
    Type: Grant
    Filed: August 26, 2020
    Date of Patent: January 3, 2023
    Assignee: Rockwell Collins, Inc.
    Inventors: Sean Howard, James A. Marek, Jonathon C. Skarphol, Edward C. Tubbs
  • Publication number: 20220382556
    Abstract: A cross-domain guard is disclosed that includes a field programmable gate array (FPGA). The FPGA includes a rule database containing one or more rules, a memory interconnect configured to send control data or rule processing data, media access control logic, and a plurality of filter engines configured to receive an incoming message and generate a processed message. Each of the plurality of filter engines may contain a message processing allocation element configured to receive and distribute the incoming message, and a plurality of rule processor kernels. Each of the plurality of rule processor kernels includes a rule processor kernel control element, a plurality of data operator kernels configured to perform a data comparison operation, a ternary lookup table processor configured to perform a logic operation based upon a result of the data comparison operation, and a processed message arbiter. A method for filtering incoming messages is also disclosed.
    Type: Application
    Filed: May 26, 2021
    Publication date: December 1, 2022
    Inventors: Edward C. Tubbs, Sean Nichols, Jonathon C. Skarphol, Sean Jarrard, Brian R. Roggendorf, Ronald Luse, James A. Marek
  • Patent number: 11373011
    Abstract: A security module is disclosed. In embodiments, the security module includes a common host platform configured to co-host a plurality of certified functions via a plurality of interconnected hardware resources. The common host platform may be configured to host a first certified function independently certified via a first certifying authority, and a second certified function independently certified via a second certifying authority. The first certified function may be hosted on a first sub-set of dedicated hardware resources and a first sub-set of shared hardware resources. The second certified function may hosted on a second sub-set of dedicated hardware resources and the first sub-set of shared hardware resources including one or more hardware resources shared with the first certified function.
    Type: Grant
    Filed: July 1, 2019
    Date of Patent: June 28, 2022
    Assignee: Rockwell Collins, Inc.
    Inventors: James A. Marek, Sarah A. Miller, Adriane R. Van Auken
  • Publication number: 20220070008
    Abstract: A method of remotely initializing at least one device is disclosed. The method includes initializing at a local host a cryptographic authorization sequence after receiving a secure input value. The method further includes receiving at a local host cryptographic controller a first authorization request from a first remote device. After a challenge—response authentication protocol, the first remote device is authenticated and receives a public key infrastructure certificate. The method includes receiving at a first remote cryptographic controller a second request from a second remote device. After a challenge—response authentication protocol, the first remote device is authenticated, but does not receive a public key infrastructure certificate. A system for remotely initiating at least one device is also disclosed.
    Type: Application
    Filed: August 26, 2020
    Publication date: March 3, 2022
    Inventors: Sean Howard, James A. Marek, Jonathon C. Skarphol, Edward C. Tubbs
  • Publication number: 20210232715
    Abstract: A security module is disclosed. In embodiments, the security module includes a common host platform configured to co-host a plurality of certified functions via a plurality of interconnected hardware resources. The common host platform may be configured to host a first certified function independently certified via a first certifying authority, and a second certified function independently certified via a second certifying authority. The first certified function may be hosted on a first sub-set of dedicated hardware resources and a first sub-set of shared hardware resources. The second certified function may hosted on a second sub-set of dedicated hardware resources and the first sub-set of shared hardware resources including one or more hardware resources shared with the first certified function.
    Type: Application
    Filed: July 1, 2019
    Publication date: July 29, 2021
    Inventors: James A. Marek, Sarah A. Miller, Adriane R. Van Auken
  • Patent number: 10986076
    Abstract: A multilevel security (MLS) network is disclosed. The MLS network includes untrusted nodes (UTN) capable of receiving messages en route from a source node to a destination node, each message having an unencrypted outer header, an encrypted inner header, and a data payload. UTNs route messages toward their destination as directed by the outer header. Global trusted nodes (GTN) decrypt a portion of the inner header to validate source and destination information before routing the message forward. GTNs further modify the outer header to obfuscate source and destination information from the UTNs. Local trusted nodes (LTN) serve as gateway nodes into a local network. LTNs also validate source and destination information to regulate admission to the local network. LTNs include an address manager which decrypts an additional portion of the inner header to read local address data and generates local messages for routing through the local network.
    Type: Grant
    Filed: June 28, 2019
    Date of Patent: April 20, 2021
    Assignee: Rockwell Collins, Inc.
    Inventors: John G. Bendickson, James A. Marek
  • Patent number: 10877831
    Abstract: A secure onboard maintenance circuit (OMC) includes a primary OMC node with a controller, a secure storage, a trusted CDS interface, and a configurable I/O interface for connecting to at least one system component. The controller is configured to receive maintenance information via the configurable I/O interface and the trusted CDS interface and is further configured to store data associated with the maintenance information in the secure storage. The OMC further includes at least one secondary OMC node with a second controller, a second trusted CDS interface, and a second configurable I/O interface for connecting to at least one other system component. The second controller is configured to receive maintenance information via the second configurable I/O interface and is further configured to transmit the maintenance information to the primary OMC node via the second trusted CDS interface.
    Type: Grant
    Filed: July 30, 2018
    Date of Patent: December 29, 2020
    Assignee: Rockwell Collins, Inc.
    Inventors: Ryan P. Littler, Brian R. Roggendorf, Johnathan C. Lewis, James A. Marek, Edward C. Tubbs, John G. Bendickson
  • Patent number: 10757111
    Abstract: A multilevel security fabric with address management units communicatively coupled to ports of a communication fabric and nodes of a multilevel security system are disclosed. The communication fabric facilitates communication between the nodes. An address management unit associated with a particular node extracts address maps contained in data requests associated with the particular node and regulates communication of that node any other nodes within the system across the communication fabric based on whether the extracted address maps are within an allowable address access range specified for the particular node. In the event that an extracted address map fails to fall within the allowable address access range, the address management unit may block the communication with the particular node. Accordingly, the address management unit may enforce multilevel communication across the communication fabric with high assurance.
    Type: Grant
    Filed: July 12, 2017
    Date of Patent: August 25, 2020
    Assignee: Rockwell Collins, Inc.
    Inventors: James A. Marek, Jonathon C. Skarphol, Adam W. Pfab, Edward C. Tubbs, John G. Bendickson
  • Patent number: 10558209
    Abstract: A system for controlling the flight of aircraft includes an aircraft operated by a human pilot, one or more optionally piloted aircraft controlled by a processor, and a communication link between the aircraft. The optionally piloted aircraft receives data indicative of the position and flight path of the piloted aircraft, and is automatically controlled to maintain a predetermined range of separation distances from the piloted aircraft. Control of the optionally piloted aircraft may include machine reasoning computing functions based on a classification of data received by the communication link, data indicative of the current positions and three-dimensional flight paths of the aircraft, stored data from previously calculated positions and three-dimensional flight paths of the aircraft, and stored data from previously executed flight plans associated with the optionally piloted aircraft.
    Type: Grant
    Filed: June 13, 2017
    Date of Patent: February 11, 2020
    Assignee: Rockwell Collins, Inc.
    Inventors: David S. Hardin, Jennifer A. Davis, Jing Liu, James A. Marek, Ryan P. Littler
  • Patent number: 10372901
    Abstract: Segregated cores or virtual processors within a processor establish at least two separate encryption paths via software virtualization. Guest operating systems and encryption applications operate on input data with an enforced level of synchronicity. Output is compared to determine if each encryption path arrives at the same encrypted output. If the outputs are identical, the encrypted data is passed on; if not, an error report is generated. No individual vulnerability may produce a single point of failure to produce erroneously encrypted or unencrypted output.
    Type: Grant
    Filed: July 20, 2017
    Date of Patent: August 6, 2019
    Assignee: Rockwell Collins, Inc.
    Inventor: James A. Marek
  • Patent number: 9846784
    Abstract: A data storage system is provided. The system includes an electronic storage architecture configured to be coupled to a computing system and a storage medium. The architecture mediates the storing and accessing of data at the storage medium in response to the commands to write or read data. The architecture includes a file interface configured to process at least one attribute associated with data. The architecture includes a crypto interface configured to encrypt and decrypt the data based on the at least one attribute. The at least one attribute specifies a classification level of the data. The crypto interface includes cryptographic functions. Each cryptographic function is associated with a different classification level. The architecture includes a storage interface configured to provide a mapping between partitions on the storage medium and the cryptographic functions. Each of the partitions is associated with a different classification level.
    Type: Grant
    Filed: February 26, 2013
    Date of Patent: December 19, 2017
    Assignee: ROCKWELL COLLINS, INC.
    Inventors: Daniel S. Murray, James A. Marek
  • Patent number: 9660966
    Abstract: Multilevel secure communication systems and methods for providing multilevel security to such communication systems are disclosed. More specifically, communication systems and methods configured in accordance with the inventive concepts disclosed herein may be utilized to provide support for N levels of secure communications using processors (may also be referred to as nodes) that may only have (N?M) levels of security separation (where N and M are integers and M is strictly less than N). In other words, processors that have less than N levels of security separation may be configured to form a communication system that is capable of supporting N levels of secure communication.
    Type: Grant
    Filed: September 10, 2015
    Date of Patent: May 23, 2017
    Assignee: Rockwell Collins, Inc.
    Inventors: James A. Marek, Greg L. Shelton
  • Patent number: 9465508
    Abstract: A method for indicating the security level of a selected element on a multi-level security display includes determining a security level of a selected element and modifying the visual representation of the selected element to indicate the security level and/or providing an audible tone. Visual distinction may include a security tag, color variation or flashing pattern.
    Type: Grant
    Filed: June 13, 2012
    Date of Patent: October 11, 2016
    Assignee: Rockwell Collins, Inc.
    Inventors: James Marek, David A. Greve
  • Patent number: 9003560
    Abstract: A secured enclosure system and a method for configuring a secured enclosure system are disclosed. The secured enclosure system includes at least one processing module for implementing a processing task, a security module in communication with the processing module for providing a trust anchor functionality to the processing module, a secure backplane in communication with the at processing module for monitoring a connection with the processing module, and a security controller module in communication with the secure backplane for providing a root of trust, for serving as a local system controller, and for serving as a key/certificate manager. An enclosure encloses the components of the system and includes a physical security component for detecting an interference with the enclosure.
    Type: Grant
    Filed: June 5, 2012
    Date of Patent: April 7, 2015
    Assignee: Rockwell Collins, Inc.
    Inventors: Reginald D. Bean, James A. Marek, Glenn D. Schillinger, Robert B. Ray
  • Patent number: 8904556
    Abstract: A method and system for securely distributing human-machine input/output to multi-level displays in a multi-level security environment is disclosed. The method and system in accordance with the present disclosure provides the ability to take input from common input devices and manages the input to ensure that the input is delivered only to the intended security domain/level and that the input is delivered only to the intended display element within the intended security domain/level. Furthermore, architectures configured for supporting the multi-level security display with secure input/output are also disclosed.
    Type: Grant
    Filed: August 29, 2012
    Date of Patent: December 2, 2014
    Assignee: Rockwell Collins, Inc.
    Inventors: Joshua R. Bertram, James A. Marek, Andre F. Mitchell, Curtis M. Topf, Reginald D. Bean
  • Patent number: 8880868
    Abstract: A secure deterministic fabric includes switches that segregate data traffic requiring disparate levels of authentication or having different safety levels. Data may be segregated physically, utilizing different hardware; or virtually, by allocating certain assets such as memory blocks exclusively for certain levels of authentication. The secure deterministic fabric may include elements for safety monitoring and multi-level security monitoring.
    Type: Grant
    Filed: June 15, 2012
    Date of Patent: November 4, 2014
    Assignee: Rockwell Collins, Inc.
    Inventors: Roger K. Shultz, Joshua Bertram, Raymond Knoff, James Marek, Max G. Taylor
  • Patent number: 8875226
    Abstract: A method for disambiguating entities on a multi-level security display includes receiving a selection of a particular security level and rendering entities having a different security level in a visually distinct way. Visual distinction may include not drawing the entities on the multi-level security display.
    Type: Grant
    Filed: June 14, 2012
    Date of Patent: October 28, 2014
    Assignee: Rockwell Collins, Inc.
    Inventor: James A. Marek
  • Publication number: 20140298934
    Abstract: An anti-rotation device for use in a linear actuator comprises a hollow body permitting passage of a screw therein. At least one pair of legs extends longitudinally away from the hollow body and each leg of the at least one pair includes a first key feature configured for mating or complementary engagement with a second key feature of an housing used to enclose the screw, nut and anti-rotation device. In one embodiment, each leg is configured to extend or flex radially outward relative to an outer diameter of the hollow body. In another embodiment, the second key features of the housing are substantially longitudinally uniform, whereas the first key feature of at least one of the legs includes a longitudinally non-uniform feature. These pre-loading features induce self-centering of the anti-rotation device that reduces or eliminates play between the components and noise while also improving performance of the linear actuator.
    Type: Application
    Filed: April 1, 2014
    Publication date: October 9, 2014
    Applicant: Thomson Industries Inc.
    Inventors: James MAREK, Rikard HENRYSSON
  • Patent number: 8161529
    Abstract: The present invention is directed to routing information between networks of differing security level. Communication to/from each network is handled by a dedicated Offload Engine (OE). Each OE interfaces to a Guard Engine through a Guard Data Mover (GDM) and includes an interface for connecting to an external network. A first OE receives a data packet from a first network intended to be transmitted to a second network. The Guard Engine analyzes the data packet. The Guard Engine includes an ACL (Access Control List) which are rules data packets must meet before being passed onto a destination network. If allowed, the Guard Engine delivers the data packet to the second network via a second OE utilizing a GDM associated with the first OE and a GDM associated with the second OE. The architecture of the present invention reduces the time and effort needed to attain high-assurance certification.
    Type: Grant
    Filed: June 19, 2007
    Date of Patent: April 17, 2012
    Assignee: Rockwell Collins, Inc.
    Inventors: Mark A. Bortz, Matthew M. Wilding, James A. Marek, David S. Hardin, T. Douglas Hiratzka, Philippe M. T. Limondin