Patents by Inventor Thomas R. Markham

Thomas R. Markham has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8089340
    Abstract: A vehicle screening system for screening vehicles and occupants for entrance to a secured facility is disclosed. The system can include a processor and an interface that communicates with the processor, wherein the interface displays identification information extracted from a vehicle occupant associated with a vehicle for processing by the processor. Additionally, a plurality of controls are associated with the interface and the processor, wherein the plurality of controls facilitates the handling and management of the information extracted from the vehicle occupant to either permit or deny the vehicle occupant and the vehicle entry to a secured facility through a security gate.
    Type: Grant
    Filed: January 5, 2007
    Date of Patent: January 3, 2012
    Assignee: Honeywell International Inc.
    Inventors: Edward L. Cochran, Jeffrey M. Rye, Bruce W. Anderson, Thomas R. Markham
  • Publication number: 20110202995
    Abstract: A process detects an attack on a software system, eradicates the attack, automatically loads software into the software system in response to the attack, and executes one or more of a reboot of the software system or a boot of the loaded software. The loaded software comprises a substantially similar functionality of at least a portion of the software system and a different implementation of the functionality of the portion of the software system.
    Type: Application
    Filed: February 16, 2010
    Publication date: August 18, 2011
    Applicant: Honeywell International Inc.
    Inventor: Thomas R. Markham
  • Patent number: 7996201
    Abstract: A network security modeling system which simulates a network and analyzes security vulnerabilities of the network. The system includes a simulator which includes a network vulnerabilities database and a network configuration module having network configuration data. The simulator determines vulnerabilities of the simulated network based on the network configuration data and the vulnerabilities database.
    Type: Grant
    Filed: October 23, 2007
    Date of Patent: August 9, 2011
    Assignee: McAfee, Inc.
    Inventors: Alan Dowd, Thomas R. Markham, Tomo Foote-Lennox, David Apostal, Raymond Lu
  • Patent number: 7594262
    Abstract: A system and method for secure group communications is provided. One embodiment provides a method for implementing a virtual private group network. The method includes creating a virtual private group definition on a policy server, establishing a plurality of secure connections between the policy server and a plurality of group nodes, sending a copy of the virtual private group definition from the policy server to the group nodes, sending a shared traffic encryption key from the policy server to each of the group nodes, and sharing secure communication information among the group nodes using the shared traffic encryption key, wherein each group node is included in the virtual private group definition.
    Type: Grant
    Filed: September 4, 2002
    Date of Patent: September 22, 2009
    Assignee: Secure Computing Corporation
    Inventors: Robert Otto Hanzlik, Geoffrey A. Lowe, Thomas R. Markham, Lynn Marquette Meredith
  • Publication number: 20090141993
    Abstract: A system includes a motion detection processor, a motion tracking processor, a people detection processor, a controller, a fusion processor, an appearance model generator processor, a database, a fast search processor, and a matching processor. The motion detection processor, the motion tracking processor, the controller, the people detection processor, the fusion processor, and the appearance model generator processor comprise an analytics pipeline, and the database and the fast search processor comprise a data index pipeline.
    Type: Application
    Filed: December 3, 2007
    Publication date: June 4, 2009
    Inventors: Yunqian Ma, Ben A. Miller, Andrew H. Johnson, Thomas R. Markham
  • Patent number: 7536715
    Abstract: A system and method for restricting packet transfer to a computer across a network, wherein the computer includes a network interface device coupled to the network and wherein the network interface device includes a packet filter. A security server is connected to the network. A packet is received at the network interface device and the network interface device determines if the packet is an authorized transaction. If the packet is not an authorized transaction, the packet is routed to the security server, where the security server determines whether the packet is an authorized transaction. If the security server determines that the packet is an authorized transaction, the network interface device is configured to accept similar transactions.
    Type: Grant
    Filed: November 25, 2002
    Date of Patent: May 19, 2009
    Assignee: Secure Computing Corporation
    Inventor: Thomas R. Markham
  • Publication number: 20080222731
    Abstract: A network security modeling system which simulates a network and analyzes security vulnerabilities of the network. The system includes a simulator which includes a network vulnerabilities database and a network configuration module having network configuration data. The simulator determines vulnerabilities of the simulated network based on the network configuration data and the vulnerabilities database.
    Type: Application
    Filed: October 23, 2007
    Publication date: September 11, 2008
    Inventors: Alan Dowd, Thomas R. Markham, Tomo Foote-Lennox, David Apostal, Raymond Lu
  • Publication number: 20080170758
    Abstract: A method and system for selecting and allocating high confidence biometric data. A combination of presented identification information along with gathered biometric data are associated with an entity separated by a sensor trigger. For example, presenting a driver's license in addition to automated gathering and identification of face, iris, voice, or any other combination of biometrics can be implemented in the context of gathering and selecting biometric data. Such a method and system solves the problem of harvesting sensor data from disparate sources together to form a more strongly identified individual user profile with appropriate related identifying information.
    Type: Application
    Filed: February 7, 2007
    Publication date: July 17, 2008
    Inventors: Andrew H. Johnson, Bruce W. Anderson, Edward L. Cochran, Thomas R. Markham
  • Publication number: 20080164974
    Abstract: A vehicle screening system for screening vehicles and occupants for entrance to a secured facility. The system can include a processor and an interface that communicates with the processor, wherein the interface displays identification information extracted from a vehicle occupant associated with a vehicle for processing by the processor. Additionally, a plurality of controls are associated with the interface and the processor, wherein the plurality of controls permit facilitates the handling and management of the information extracted from the vehicle occupant in order to permit or deny the vehicle occupant and the vehicle entry to a secured facility through a security gate.
    Type: Application
    Filed: January 5, 2007
    Publication date: July 10, 2008
    Inventors: Edward L. Cochran, Jeffrey M. Rye, Bruce W. Anderson, Thomas R. Markham
  • Publication number: 20080147246
    Abstract: A vehicle screening method and system. A vehicle occupant can be identified utilizing one or more biometric identifiers input by or obtained from the vehicle occupant via a biometric input device. A barcode can also be provided by the vehicle occupant from a scanned card or other structure upon which the barcode is maintained. Additionally, a unique identification number can be provided by the user in order to match the unique identification number against a database of identification numbers, thereby permitting the vehicle occupant to be remotely screened and verified for entry into a secure facility based on the biometric identifier(s), the barcode and the unique identification number.
    Type: Application
    Filed: December 15, 2006
    Publication date: June 19, 2008
    Inventors: Edward L. Cochran, Bruce W. Anderson, Thomas R. Markham
  • Patent number: 7315801
    Abstract: A network security modeling system which simulates a network and analyzes security vulnerabilities of the network. The system includes a simulator which includes a network vulnerabilities database and a network configuration module having network configuration data. The simulator determines vulnerabilities of the simulated network based on the network configuration data and the vulnerabilities database.
    Type: Grant
    Filed: January 14, 2000
    Date of Patent: January 1, 2008
    Assignee: Secure Computing Corporation
    Inventors: Alan Dowd, Thomas R. Markham, Tomo Foote-Lennox, David Apostal, Raymond Lu
  • Patent number: 7308706
    Abstract: Systems and methods for an associative policy model are provided. One embodiment of the present invention provides a method for implementing an associative policy. In this embodiment, the method includes providing a policy on a policy server, the policy having a service definition that contains first and second relational components, providing first and second network entities, operatively coupling the first and second network entities to the policy server, dynamically associating the first network entity with the second network entity (wherein such associating includes binding the first relational component of the service definition in the policy to the first network entity, and binding the second relational component of the service definition in the policy to the second network entity), and enforcing the policy on the first and second network entities.
    Type: Grant
    Filed: October 28, 2002
    Date of Patent: December 11, 2007
    Assignee: Secure Computing Corporation
    Inventors: Thomas R. Markham, Jessica J. Bogle, Charles N. Payne, Jr.
  • Patent number: 7231664
    Abstract: A novel system and method for transmitting and receiving secure data in a virtual private group (VPG). In one embodiment, a method for transmitting secure data from a first node to a second node includes accessing a group membership table on the first node, the group membership table having group membership information for each group, including a first group, to which the first node belongs and group security information associated with each group, wherein the first group has two or more members, and checking the group membership table to determine if the second node is a member of the first group. If the second node is a member of the first group, the method further includes encrypting a data packet using the group security information associated with the first group, processing the encrypted data packet, and transmitting the encrypted data packet from the first node to the second node.
    Type: Grant
    Filed: September 4, 2002
    Date of Patent: June 12, 2007
    Assignee: Secure Computing Corporation
    Inventors: Thomas R. Markham, Lynn Marquette Meredith, Robert Otto Hanzlik, Geoffrey A. Lowe
  • Publication number: 20040083382
    Abstract: Systems and methods for an associative policy model are provided. One embodiment of the present invention provides a method for implementing an associative policy. In this embodiment, the method includes providing a policy on a policy server, the policy having a service definition that contains first and second relational components, providing first and second network entities, operatively coupling the first and second network entities to the policy server, dynamically associating the first network entity with the second network entity (wherein such associating includes binding the first relational component of the service definition in the policy to the first network entity, and binding the second relational component of the service definition in the policy to the second network entity), and enforcing the policy on the first and second network entities.
    Type: Application
    Filed: October 28, 2002
    Publication date: April 29, 2004
    Applicant: Secure Computing Corporation
    Inventors: Thomas R. Markham, Jessica J. Bogle, Charles N. Payne
  • Publication number: 20040044891
    Abstract: A system and method for secure group communications is provided. One embodiment provides a method for implementing a virtual private group network. The method includes creating a virtual private group definition on a policy server, establishing a plurality of secure connections between the policy server and a plurality of group nodes, sending a copy of the virtual private group definition from the policy server to the group nodes, sending a shared traffic encryption key from the policy server to each of the group nodes, and sharing secure communication information among the group nodes using the shared traffic encryption key, wherein each group node is included in the virtual private group definition.
    Type: Application
    Filed: September 4, 2002
    Publication date: March 4, 2004
    Applicant: Secure Computing Corporation
    Inventors: Robert Otto Hanzlik, Geoffrey A. Lowe, Thomas R. Markham, Lynn Marquette Meredith
  • Publication number: 20040044908
    Abstract: A novel system and method for transmitting and receiving secure data in a virtual private group (VPG). In one embodiment, a method for transmitting secure data from a first node to a second node includes accessing a group membership table on the first node, the group membership table having group membership information for each group, including a first group, to which the first node belongs and group security information associated with each group, wherein the first group has two or more members, and checking the group membership table to determine if the second node is a member of the first group. If the second node is a member of the first group, the method further includes encrypting a data packet using the group security information associated with the first group, processing the encrypted data packet, and transmitting the encrypted data packet from the first node to the second node.
    Type: Application
    Filed: September 4, 2002
    Publication date: March 4, 2004
    Applicant: Secure Computing Corporation
    Inventors: Thomas R. Markham, Lynn Marquette Meredith, Robert Otto Hanzlik, Geoffrey A. Lowe
  • Publication number: 20030126468
    Abstract: A system and method for restricting packet transfer to a computer across a network, wherein the computer includes a network interface device coupled to the network and wherein the network interface device includes a packet filter. A security server is connected to the network. A packet is received at the network interface device and the network interface device determines if the packet is an authorized transaction. If the packet is not an authorized transaction, the packet is routed to the security server, where the security server determines whether the packet is an authorized transaction. If the security server determines that the packet is an authorized transaction, the network interface device is configured to accept similar transactions.
    Type: Application
    Filed: November 25, 2002
    Publication date: July 3, 2003
    Inventor: Thomas R. Markham
  • Patent number: 5822435
    Abstract: A method and apparatus for ensuring secure communication over an unsecured communications medium between a user working on an unsecured workstation or computer and a host computer. A secure user interface is created by inserting a trusted path subsystem between input/output devices to the workstation and the workstation itself. Data transferred from the input/output devices is intercepted, encrypted and transmitted in packets to the host computer. Packets of screen display data from the host computer are decrypted and presented within a user-defined screen overlay.
    Type: Grant
    Filed: September 18, 1996
    Date of Patent: October 13, 1998
    Assignee: Secure Computing Corporation
    Inventors: William E. Boebert, Mark H. Hanson, Thomas R. Markham
  • Patent number: 5796836
    Abstract: A system and method for encrypting blocks of plain text. Output FIFO memories are provided for decoupling pseudorandom vector generation from plain text encryption. The output FIFOs produce the effect of multiplexing several cryptographic devices together and can be combined with feedback FIFO memories in order to provide key agility and parallel secret key encryption. Throughput is also enhanced by constructing wide codebooks so that a block of data can be enciphered as a whole.
    Type: Grant
    Filed: August 29, 1995
    Date of Patent: August 18, 1998
    Assignee: Secure Computing Corporation
    Inventor: Thomas R. Markham
  • Patent number: 5596718
    Abstract: A method and apparatus for ensuring secure communication over an unsecured communications medium between a user working on an unsecured workstation or computer and a host computer. A secure user interface is created by inserting a trusted path subsystem between input/output devices to the workstation and the workstation itself. Data transferred from the input/output devices is intercepted, encrypted and transmitted in packets to the host computer. Packets of screen display data from the host computer are decrypted and presented within a user-defined screen overlay.
    Type: Grant
    Filed: July 10, 1992
    Date of Patent: January 21, 1997
    Assignee: Secure Computing Corporation
    Inventors: William E. Boebert, Mark H. Hanson, Thomas R. Markham