Patents by Inventor Kevin M. Tambascio

Kevin M. Tambascio has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10678950
    Abstract: Industrial controller modules are configured with security components that implement backplane-level security protocols, thereby preventing installation of unauthorized modular devices on the backplane of an industrial controller. When a modular device is installed in the controller's chassis and interface with the backplane, security components in the processor module or other supervisory module initiates exchange of authentication data with the modular device via the backplane. The authentication data can comprise one or more security challenges to which the modular device must respond correctly before the modular device is permitted to operate on the backplane. These backplane-level security protocols can prevent installation of rogue modules that may be used to collect proprietary control data or interfere with control processes.
    Type: Grant
    Filed: January 26, 2018
    Date of Patent: June 9, 2020
    Assignee: Rockwell Automation Technologies, Inc.
    Inventors: Michael A. Bush, Taryl J. Jasper, Kevin M. Tambascio
  • Publication number: 20190236313
    Abstract: Industrial controller modules are configured with security components that implement backplane-level security protocols, thereby preventing installation of unauthorized modular devices on the backplane of an industrial controller. When a modular device is installed in the controller's chassis and interface with the backplane, security components in the processor module or other supervisory module initiates exchange of authentication data with the modular device via the backplane. The authentication data can comprise one or more security challenges to which the modular device must respond correctly before the modular device is permitted to operate on the backplane. These backplane-level security protocols can prevent installation of rogue modules that may be used to collect proprietary control data or interfere with control processes.
    Type: Application
    Filed: January 26, 2018
    Publication date: August 1, 2019
    Inventors: Michael A. Bush, Taryl J. Jasper, Kevin M. Tambascio
  • Publication number: 20140337618
    Abstract: A system and method for validating SCEP certificate enrollment that enforces the pairing of a SCEP challenge password and a set of expected certificate request content. A SCEP Validation Service or software residing in another system component whether a certificate request is legitimate by comparing it to registered SCEP challenges and associated expected certificate request content. This system and method addresses a privilege-escalation vulnerability in prior SCEP-based systems that could lead to a practical attack.
    Type: Application
    Filed: July 28, 2014
    Publication date: November 13, 2014
    Applicant: Certified Security Solutions, Inc.
    Inventors: Gary A. Galehouse, Wayne A. Harris, Edward R. Shorter, Kevin M. Tambascio
  • Patent number: 8832432
    Abstract: A system and method for validating SCEP certificate enrollment that enforces the pairing of a SCEP challenge password and a set of expected certificate request content. A SCEP Validation Service or software residing in another system component whether a certificate request is legitimate by comparing it to registered SCEP challenges and associated expected certificate request content. This system and method addresses a privilege-escalation vulnerability in prior SCEP-based systems that could lead to a practical attack.
    Type: Grant
    Filed: August 13, 2013
    Date of Patent: September 9, 2014
    Assignee: Certified Security Solutions, Inc.
    Inventors: Gary A. Galehouse, Wayne A. Harris, Edward R. Shorter, Kevin M. Tambascio
  • Patent number: 8745378
    Abstract: A system and method for validating SCEP certificate enrollment that enforces the pairing of a SCEP challenge password and a set of expected certificate request content. A SCEP Validation Service or software residing in another system component whether a certificate request is legitimate by comparing it to registered SCEP challenges and associated expected certificate request content. This system and method addresses a privilege-escalation vulnerability in prior SCEP-based systems that could lead to a practical attack.
    Type: Grant
    Filed: February 8, 2013
    Date of Patent: June 3, 2014
    Assignee: Certified Security Solutions, Inc.
    Inventors: Gary A. Galehouse, Wayne A. Harris, Edward R. Shorter, Kevin M. Tambascio
  • Publication number: 20130332726
    Abstract: A system and method for validating SCEP certificate enrollment that enforces the pairing of a SCEP challenge password and a set of expected certificate request content. A SCEP Validation Service or software residing in another system component whether a certificate request is legitimate by comparing it to registered SCEP challenges and associated expected certificate request content. This system and method addresses a privilege-escalation vulnerability in prior SCEP-based systems that could lead to a practical attack.
    Type: Application
    Filed: August 13, 2013
    Publication date: December 12, 2013
    Applicant: Certified Security Solutions, Inc.
    Inventors: Gary A. Galehouse, Wayne A. Harris, Edward R. Shorter, Kevin M. Tambascio
  • Patent number: 8015409
    Abstract: An industrial automation system is provided. This includes at least one license component that is granted by a third party to permit access to a portion of an industrial control component. At least one protocol component that is based in part on a private key exchange facilitates authentication and access to the portion of the industrial control component.
    Type: Grant
    Filed: January 26, 2007
    Date of Patent: September 6, 2011
    Assignee: Rockwell Automation Technologies, Inc.
    Inventors: John C. Wilkinson, Jr., Taryl J. Jasper, Michael D. Kalan, Nicholas L. Perrotto, Jr., Glenn B. Schulz, James A. Meeker, Kevin M. Tambascio, Jack M. Visoky
  • Publication number: 20080082449
    Abstract: An industrial automation system is provided. This includes at least one license component that is granted by a third party to permit access to a portion of an industrial control component. At least one protocol component that is based in part on a private key exchange facilitates authentication and access to the portion of the industrial control component.
    Type: Application
    Filed: January 26, 2007
    Publication date: April 3, 2008
    Applicant: ROCKWELL AUTOMATION TECHNOLOGIES, INC.
    Inventors: John C. Wilkinson, Taryl J. Jasper, Michael D. Kalan, Nicholas L. Perrotto, Glenn B. Schulz, James A. Meeker, Kevin M. Tambascio, Jack M. Visoky