ABSTRACT
Abstract
A method for a computer or microchip with one or more inner hardware-based access barriers or firewalls that establish one or more private units disconnected from a public unit or units having connection to the public Internet and one or more of the private units have a connection to one or more non-Internet-connected private networks for private network control of the configuration of the computer or microchip using active hardware configuration, including field programmable gate arrays (FPGA). The hardware-based access barriers include a single out-only bus and/or another in-only bus with a single on/off switch.
Description
This application is a continuation of U.S. patent application Ser. No. 14/174,693, flied Feb. 6, 2014, which is a continuation of U.S. patent application Ser. No. 13/815,814 filed Mar. 15, 2013, now U.S. Pat. No. 8,898,768, which claims priority to U.S. patent application Ser. No. 13/398,403 filed on Feb. 16, 2012 which is a non-provisional of U.S. Provisional Patent Application 61/457,184, filed Feb. 15, 2011; U.S. Provisional Patent Application No. 61/457,297, filed Feb. 18, 2011; U.S. Provisional Patent Application No. 61/457,976, filed Jul. 26, 2011; U.S. Provisional Patent Application No. 61/457,983, filed Jul. 28, 2011; U.S. Provisional Patent Application No. 61/573,006, filed Aug. 2, 2011; and U.S. Provisional Patent Application No. 61/573,007, filed Aug. 3, 2011.
This application is also a continuation-in-part of U.S. application Ser. No. 13/014,201, filed Jan. 26, 2011. U.S. application Ser. No. 13/014,201 is a non-provisional of U.S. Provisional Patent Application No. 61/282,337 filed Jan. 26, 2010; U.S. Provisional Patent Application No. 61/282,378, filed Jan. 29, 2010; U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011.
This application is also a continuation-in-part of U.S. application Ser. No. 13/016,527 filed Jan. 28, 2011. U.S. application Ser. No. 13/016,527 is a non-provisional of U.S. Provisional Patent Application No. 61/282,378, filed Jan. 29, 2010; U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011.
This application is also a continuation-in-part of PCT Application No. PCT/US011/023028, filed Jan. 28, 2011. PCT Application No. PCT/US011/023028 is a non-provisional of U.S. Provisional Patent Application No. 61/282,378, filed Jan. 29, 2010; U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011.
This application is also a continuation-in-part of PCT Application No. PCT/US011/025257, filed Feb. 17, 2011. PCT Application No. PCT/US011/025257 is a non-provisional of U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011. PCT Application No. PCT/US011/025257 also claims the right to priority based on U.S. Nonprovisional patent application Ser. No. 13/014,201, filed Jan. 26, 2011, and U.S. Nonprovisional patent application Ser. No. 13/016,527, filed Jan. 28, 2011.
The contents of all of these provisional and nonprovisional patent applications are hereby incorporated by reference in their entirety.
BACKGROUND
This invention relates to any computer of any form, such as a personal computer and/or microchip, that has an inner hardware-based access barrier or firewall that establishes a private unit that is disconnected from a public unit, the public unit being configured for a connection to a public network of computers including the Internet. In addition, the computer's private unit is configured for a separate connection to at least one non-Internet-connected private network for administration, management, and/or control of the computer and/or microchip, locally or remotely, by either a personal user or a business or corporate entity.
More particularly, this invention relates to a computer and/or microchip with an inner hardware-based access barrier or firewall separating the private unit that is not connected to the Internet from a public unit connected to the Internet, the private and public units being connected only by a hardware-based access barrier or firewall in the form of a secure, out-only bus or equivalent wireless connection. Even more particularly, this invention relates to the private and public units also being connected by an in-only bus (or equivalent wireless connection) that includes a hardware input on/off switch or equivalent signal interruption mechanism, including an equivalent circuit on a microchip or nanochip (or equivalent wireless connection). Still more particularly, this invention relates to the private and public units being connected by an output on/off switch or microcircuit or nanocircuit equivalent on the secure, out-only bus (or equivalent wireless connection).
In addition, this invention relates to a computer and/or microchip that is connected to a another computer and/or microchip, the connection between computers being made with the same hardware-based access barriers or firewalls including potentially any of the buses and on/off switches described in the preceding paragraph.
Finally, this invention relates to a computer and/or microchip with hardware-based access barriers or firewalls used successively between an outer private unit, an intermediate more private unit, an inner most private unit, and the public unit (or units), with each private unit potentially being configured for a connection to a separate private network. Also, Faraday Cage protection from external electromagnetic pulses for part or all of the computer and/or microchip can be provided.
By way of background, connecting computers to the Internet has immense and well known benefits today, but also has created overwhelming security problems that were not imagined when the basic architecture of modern electronic computers was developed in 1945, which was about twenty years before networks came into use. Even then, those first networks involved a very limited number of connected computers, had low transmission speeds between them, and the network users were generally known to each other, since most networks were relatively small and local.
In contrast, the number of computers connected to the Internet today is greater by a factor of many millions, broadband connection speeds are faster by a similar magnitude, the network connections stretch worldwide and connect to hundreds of thousands of bad actors whose identity is not easily or quickly known, if ever. Indeed, the Internet of today allows the most capable criminal hackers direct access to any computer connected to the Internet. This inescapable reality of the Internet has created a huge and growing threat to military and economic security worldwide. At the same time, connection to the Internet has become the communication foundation upon which both the global economy and individual users depend every day.
In summary, then, computer connection to the Internet is mandatory in today's world, so disconnection is not a feasible option, given the existing global dependence on the Internet. But those unavoidable connections have created a seemingly inherent and therefore unsolvable security problem so serious that it literally threatens the world. So Internet connection today is both unavoidable and unavoidably unsafe.
Past efforts to provide Internet security have been based primarily on conventional firewalls that are positioned externally, physically and/or functionally, between the computer and an external network like the Internet. Such conventional firewalls provide a screening or filtering function that attempts to identify and block incoming network malware. But because of their functionally external position, conventional firewalls must allow entry to a significant amount of incoming traffic, so either they perform their screening function perfectly, which is an impossibility, or at least some malware unavoidably gets into the computer and just a single instance of malware can cause a crash or worse. Once the malware is in, the von Neumann architecture of current computers provides only software protection, which is inherently vulnerable to malware attack, so existing computers are essentially indefensible from successful attack from the Internet, which has provided an easy, inexpensive, anonymous, and effective means for the worst of all hackers worldwide to access any computer connected to it.
SUMMARY
Therefore, computers cannot be successful defended without inner hardware or firmware-based access barriers or firewalls that, because of their internal position, can be designed much more simply to function as a access barrier or blockers rather than as general filters. This is a distinct difference. An Internet filter has to screen any network traffic originating from anywhere in the entire Internet, which is without measure in practical terms and is constantly, rapidly changing, an incredibly difficult if not impossible screening task. In contrast, an access barrier or blocker to an inner protected area of a computer can strictly limit access to only an exception basis. So, in simple terms, a conventional firewall generally grants access to all Internet traffic unless it can be identified as being on the most current huge list of ever changing malware; in contrast, an inner access barrier or blocker can simply deny access to all network traffic, with the only exception being a carefully selected and very short and conditioned list of approved and authenticated sources or types of traffic to which access is not denied.
Such a massively simpler and achievable access blocking function allowing for a much simpler and efficient mechanism for providing reliable security. Whereas a conventional but imperfect firewall requires extremely complicated hardware with millions of switches and/or firmware and/or software with millions of bits of code, the hardware-based access barriers described in this application require as little as a single simple one-way bus and/or another simple one-way bus with just a single switch and/or both simple buses, each with just a single switch. This extraordinarily tiny amount of hardware is at the absolute theoretical limit and cannot be less.
With this new and unique access denial approach, a computer and/or microchip can be simply and effectively defended from Internet malware attack with one or more hardware-based private, protected units (or zones or compartments) inside the computer. Similar to Java Sandboxes in terms of overall function, but far more effective because hardware-based. Any or all of these private units can be administrated, managed, and/or controlled by a personal or corporate computer user through the use of one or more separate and more secure non-Internet private networks. By thus avoiding any connection whatsoever to the generally insecure public Internet, connection of the computer's private unit to the secure private network allows for all the well known speed, efficiency and cost effectiveness of network connection while still completely avoiding the incalculable risk of Internet connection.
Volatile memory like Flash that is read/write can function as inexpensive read-only memory (ROM) when located in the Private Unit(s) because can be protected by an access barrier or firewall against writing. Furthermore, it can even be protected against unauthorized reading, unlike ROM. Finally, it can be written to when authorized by the central controller to update an operating system or download an app, for example, again unlike ROM.
In addition, field programmable gate arrays can be used in the private and public units, as well as in the access barriers or firewalls, and can be securely controlled by the computer or microchip central controller through the secure control bus to actively change security and other configurations, thus providing for the first time a dynamic and proactive hardware defense against Internet malware attacks.
This application hereby expressly incorporates by reference in its entirety U.S. patent application Ser. No. 10/684,657 filed Oct. 15, 2003 and published as Pub. No. US 2005/0180095 A1 on Aug. 18, 2005 and U.S. patent application Ser. No. 12/292,769 filed Nov. 25, 2008 and published as Pub. No. US 2009/0200661 A1 on Aug. 13, 2009.
Also, this application hereby expressly incorporates by reference in its entirety U.S. patent application Ser. No. 10/802,049 filed Mar. 17, 2004 and published as Pub. No. US 2004/0215931 A1 on Oct. 28, 2004; U.S. patent application Ser. No. 12/292,553 filed Nov. 20, 2008 and published as Pub. No. US 2009/0168329 A1 on Jul. 2, 2009; and U.S. patent application Ser. No. 12/292,769 filed Nov. 25, 2008 and published as Pub. No. US 2009/0200661 A1 on Aug. 13, 2009.
Finally, this application hereby expressly incorporates by reference in its entirety U.S. Pat. No. 6,167,428 issued 26 Dec. 2000, U.S. Pat. No. 6,725,250 issued 20 Apr. 2004, U.S. Pat. No. 6,732,141 issued 4 May 2004, U.S. Pat. No. 7,024,449 issued 4 Apr. 2006, U.S. Pat. No. 7,035,906 issued 25 Apr. 2006, U.S. Pat. No. 7,047,275 issued 16 May 2006, U.S. Pat. No. 7,506,020 issued 17 Mar. 2009, U.S. Pat. No. 7,606,854 issued 20 Oct. 2009, U.S. Pat. No. 7,634,529 issued 15 Dec. 2009, U.S. Pat. No. 7,805,756 issued 28 Sep. 2010, and U.S. Pat. No. 7,814,233 issued 12 Oct. 2010.
Definitions and reference numerals are the same in this application as in the above incorporated '657, '769, '049 and '553 U.S. Applications, as well as in the above incorporated '428, '250, '141, '449, '906, '275, '020, '854, '529, '756, and '233 U.S. Patents.
BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1 shows any computer of any type or size or design, such as a personal computer 1 and/or microchip 90 (and/or 501 ) or nanochip with an inner hardware-based access barrier or firewall 50 establishing a Private Unit (or zone or compartment) 53 of the computer or microchip that is disconnected from a Public Unit (or zone or compartment) 54 that is connected to the generally insecure public Internet 3 (and/or another, intermediate network 2 that is connected to the Internet 3 ). FIG. 1 also shows an example embodiment of the Private Unit 53 having at least one separate connection to at least one separate, more secure non-Internet-connected private network 52 for personal or local administration of a computer such as the personal computer 1 and/or microchip 90 (and/or 501 ) and/or silicon wafer 1500 (or portion 1501 , 1502 , and/or 1503 ), or graphene equivalent. The number and placement of the non-Internet-connected networks 52 and the use of active configuration of the connection is optional.
FIG. 2 shows an example embodiment similar to that shown in FIG. 1 , including a personal computer 1 and/or microchip 90 (and/or 501 ) with an inner hardware-based access barrier or firewall
This application is a continuation of U.S. patent application Ser. No. 14/174,693, flied Feb. 6, 2014, which is a continuation of U.S. patent application Ser. No. 13/815,814 filed Mar. 15, 2013, now U.S. Pat. No. 8,898,768, which claims priority to U.S. patent application Ser. No. 13/398,403 filed on Feb. 16, 2012 which is a non-provisional of U.S. Provisional Patent Application 61/457,184, filed Feb. 15, 2011; U.S. Provisional Patent Application No. 61/457,297, filed Feb. 18, 2011; U.S. Provisional Patent Application No. 61/457,976, filed Jul. 26, 2011; U.S. Provisional Patent Application No. 61/457,983, filed Jul. 28, 2011; U.S. Provisional Patent Application No. 61/573,006, filed Aug. 2, 2011; and U.S. Provisional Patent Application No. 61/573,007, filed Aug. 3, 2011.
This application is also a continuation-in-part of U.S. application Ser. No. 13/014,201, filed Jan. 26, 2011. U.S. application Ser. No. 13/014,201 is a non-provisional of U.S. Provisional Patent Application No. 61/282,337 filed Jan. 26, 2010; U.S. Provisional Patent Application No. 61/282,378, filed Jan. 29, 2010; U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011.
This application is also a continuation-in-part of U.S. application Ser. No. 13/016,527 filed Jan. 28, 2011. U.S. application Ser. No. 13/016,527 is a non-provisional of U.S. Provisional Patent Application No. 61/282,378, filed Jan. 29, 2010; U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011.
This application is also a continuation-in-part of PCT Application No. PCT/US011/023028, filed Jan. 28, 2011. PCT Application No. PCT/US011/023028 is a non-provisional of U.S. Provisional Patent Application No. 61/282,378, filed Jan. 29, 2010; U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011.
This application is also a continuation-in-part of PCT Application No. PCT/US011/025257, filed Feb. 17, 2011. PCT Application No. PCT/US011/025257 is a non-provisional of U.S. Provisional Patent Application No. 61/282,478, filed Feb. 17, 2010; U.S. Provisional Patent Application No. 61/282,503, filed Feb. 22, 2010; U.S. Provisional Patent Application No. 61/282,861, filed Apr. 12, 2010; U.S. Provisional Patent Application No. 61/344,018, filed May 7, 2010; and U.S. Provisional Patent Application No. 61/457,184, filed Jan. 24, 2011. PCT Application No. PCT/US011/025257 also claims the right to priority based on U.S. Nonprovisional patent application Ser. No. 13/014,201, filed Jan. 26, 2011, and U.S. Nonprovisional patent application Ser. No. 13/016,527, filed Jan. 28, 2011.
The contents of all of these provisional and nonprovisional patent applications are hereby incorporated by reference in their entirety.
BACKGROUND
This invention relates to any computer of any form, such as a personal computer and/or microchip, that has an inner hardware-based access barrier or firewall that establishes a private unit that is disconnected from a public unit, the public unit being configured for a connection to a public network of computers including the Internet. In addition, the computer's private unit is configured for a separate connection to at least one non-Internet-connected private network for administration, management, and/or control of the computer and/or microchip, locally or remotely, by either a personal user or a business or corporate entity.
More particularly, this invention relates to a computer and/or microchip with an inner hardware-based access barrier or firewall separating the private unit that is not connected to the Internet from a public unit connected to the Internet, the private and public units being connected only by a hardware-based access barrier or firewall in the form of a secure, out-only bus or equivalent wireless connection. Even more particularly, this invention relates to the private and public units also being connected by an in-only bus (or equivalent wireless connection) that includes a hardware input on/off switch or equivalent signal interruption mechanism, including an equivalent circuit on a microchip or nanochip (or equivalent wireless connection). Still more particularly, this invention relates to the private and public units being connected by an output on/off switch or microcircuit or nanocircuit equivalent on the secure, out-only bus (or equivalent wireless connection).
In addition, this invention relates to a computer and/or microchip that is connected to a another computer and/or microchip, the connection between computers being made with the same hardware-based access barriers or firewalls including potentially any of the buses and on/off switches described in the preceding paragraph.
Finally, this invention relates to a computer and/or microchip with hardware-based access barriers or firewalls used successively between an outer private unit, an intermediate more private unit, an inner most private unit, and the public unit (or units), with each private unit potentially being configured for a connection to a separate private network. Also, Faraday Cage protection from external electromagnetic pulses for part or all of the computer and/or microchip can be provided.
By way of background, connecting computers to the Internet has immense and well known benefits today, but also has created overwhelming security problems that were not imagined when the basic architecture of modern electronic computers was developed in 1945, which was about twenty years before networks came into use. Even then, those first networks involved a very limited number of connected computers, had low transmission speeds between them, and the network users were generally known to each other, since most networks were relatively small and local.
In contrast, the number of computers connected to the Internet today is greater by a factor of many millions, broadband connection speeds are faster by a similar magnitude, the network connections stretch worldwide and connect to hundreds of thousands of bad actors whose identity is not easily or quickly known, if ever. Indeed, the Internet of today allows the most capable criminal hackers direct access to any computer connected to the Internet. This inescapable reality of the Internet has created a huge and growing threat to military and economic security worldwide. At the same time, connection to the Internet has become the communication foundation upon which both the global economy and individual users depend every day.
In summary, then, computer connection to the Internet is mandatory in today's world, so disconnection is not a feasible option, given the existing global dependence on the Internet. But those unavoidable connections have created a seemingly inherent and therefore unsolvable security problem so serious that it literally threatens the world. So Internet connection today is both unavoidable and unavoidably unsafe.
Past efforts to provide Internet security have been based primarily on conventional firewalls that are positioned externally, physically and/or functionally, between the computer and an external network like the Internet. Such conventional firewalls provide a screening or filtering function that attempts to identify and block incoming network malware. But because of their functionally external position, conventional firewalls must allow entry to a significant amount of incoming traffic, so either they perform their screening function perfectly, which is an impossibility, or at least some malware unavoidably gets into the computer and just a single instance of malware can cause a crash or worse. Once the malware is in, the von Neumann architecture of current computers provides only software protection, which is inherently vulnerable to malware attack, so existing computers are essentially indefensible from successful attack from the Internet, which has provided an easy, inexpensive, anonymous, and effective means for the worst of all hackers worldwide to access any computer connected to it.
SUMMARY
Therefore, computers cannot be successful defended without inner hardware or firmware-based access barriers or firewalls that, because of their internal position, can be designed much more simply to function as a access barrier or blockers rather than as general filters. This is a distinct difference. An Internet filter has to screen any network traffic originating from anywhere in the entire Internet, which is without measure in practical terms and is constantly, rapidly changing, an incredibly difficult if not impossible screening task. In contrast, an access barrier or blocker to an inner protected area of a computer can strictly limit access to only an exception basis. So, in simple terms, a conventional firewall generally grants access to all Internet traffic unless it can be identified as being on the most current huge list of ever changing malware; in contrast, an inner access barrier or blocker can simply deny access to all network traffic, with the only exception being a carefully selected and very short and conditioned list of approved and authenticated sources or types of traffic to which access is not denied.
Such a massively simpler and achievable access blocking function allowing for a much simpler and efficient mechanism for providing reliable security. Whereas a conventional but imperfect firewall requires extremely complicated hardware with millions of switches and/or firmware and/or software with millions of bits of code, the hardware-based access barriers described in this application require as little as a single simple one-way bus and/or another simple one-way bus with just a single switch and/or both simple buses, each with just a single switch. This extraordinarily tiny amount of hardware is at the absolute theoretical limit and cannot be less.
With this new and unique access denial approach, a computer and/or microchip can be simply and effectively defended from Internet malware attack with one or more hardware-based private, protected units (or zones or compartments) inside the computer. Similar to Java Sandboxes in terms of overall function, but far more effective because hardware-based. Any or all of these private units can be administrated, managed, and/or controlled by a personal or corporate computer user through the use of one or more separate and more secure non-Internet private networks. By thus avoiding any connection whatsoever to the generally insecure public Internet, connection of the computer's private unit to the secure private network allows for all the well known speed, efficiency and cost effectiveness of network connection while still completely avoiding the incalculable risk of Internet connection.
Volatile memory like Flash that is read/write can function as inexpensive read-only memory (ROM) when located in the Private Unit(s) because can be protected by an access barrier or firewall against writing. Furthermore, it can even be protected against unauthorized reading, unlike ROM. Finally, it can be written to when authorized by the central controller to update an operating system or download an app, for example, again unlike ROM.
In addition, field programmable gate arrays can be used in the private and public units, as well as in the access barriers or firewalls, and can be securely controlled by the computer or microchip central controller through the secure control bus to actively change security and other configurations, thus providing for the first time a dynamic and proactive hardware defense against Internet malware attacks.
This application hereby expressly incorporates by reference in its entirety U.S. patent application Ser. No. 10/684,657 filed Oct. 15, 2003 and published as Pub. No. US 2005/0180095 A1 on Aug. 18, 2005 and U.S. patent application Ser. No. 12/292,769 filed Nov. 25, 2008 and published as Pub. No. US 2009/0200661 A1 on Aug. 13, 2009.
Also, this application hereby expressly incorporates by reference in its entirety U.S. patent application Ser. No. 10/802,049 filed Mar. 17, 2004 and published as Pub. No. US 2004/0215931 A1 on Oct. 28, 2004; U.S. patent application Ser. No. 12/292,553 filed Nov. 20, 2008 and published as Pub. No. US 2009/0168329 A1 on Jul. 2, 2009; and U.S. patent application Ser. No. 12/292,769 filed Nov. 25, 2008 and published as Pub. No. US 2009/0200661 A1 on Aug. 13, 2009.
Finally, this application hereby expressly incorporates by reference in its entirety U.S. Pat. No. 6,167,428 issued 26 Dec. 2000, U.S. Pat. No. 6,725,250 issued 20 Apr. 2004, U.S. Pat. No. 6,732,141 issued 4 May 2004, U.S. Pat. No. 7,024,449 issued 4 Apr. 2006, U.S. Pat. No. 7,035,906 issued 25 Apr. 2006, U.S. Pat. No. 7,047,275 issued 16 May 2006, U.S. Pat. No. 7,506,020 issued 17 Mar. 2009, U.S. Pat. No. 7,606,854 issued 20 Oct. 2009, U.S. Pat. No. 7,634,529 issued 15 Dec. 2009, U.S. Pat. No. 7,805,756 issued 28 Sep. 2010, and U.S. Pat. No. 7,814,233 issued 12 Oct. 2010.
Definitions and reference numerals are the same in this application as in the above incorporated '657, '769, '049 and '553 U.S. Applications, as well as in the above incorporated '428, '250, '141, '449, '906, '275, '020, '854, '529, '756, and '233 U.S. Patents.
BRIEF DESCRIPTION OF THE DRAWINGS
FIG. 1 shows any computer of any type or size or design, such as a personal computer 1 and/or microchip 90 (and/or 501 ) or nanochip with an inner hardware-based access barrier or firewall 50 establishing a Private Unit (or zone or compartment) 53 of the computer or microchip that is disconnected from a Public Unit (or zone or compartment) 54 that is connected to the generally insecure public Internet 3 (and/or another, intermediate network 2 that is connected to the Internet 3 ). FIG. 1 also shows an example embodiment of the Private Unit 53 having at least one separate connection to at least one separate, more secure non-Internet-connected private network 52 for personal or local administration of a computer such as the personal computer 1 and/or microchip 90 (and/or 501 ) and/or silicon wafer 1500 (or portion 1501 , 1502 , and/or 1503 ), or graphene equivalent. The number and placement of the non-Internet-connected networks 52 and the use of active configuration of the connection is optional.
FIG. 2 shows an example embodiment similar to that shown in FIG. 1 , including a personal computer 1 and/or microchip 90 (and/or 501 ) with an inner hardware-based access barrier or firewall 50 separating a Private Unit 53 disconnected from the Internet 3 and a Public Unit 54 connected to the Internet 3 , but with the Private Unit 53 and Public Unit 54 connected only by a hardware-based access barrier or firewall 50 a , for example in the form of a secure, out-only bus (or wire) or channel 55 (or in an alternate embodiment, a wireless connection, including radio or optical).
FIG. 3 is an example embodiment similar to that shown in FIG. 2 , but with the Private Unit 53 and Public Unit 54 connected by a hardware-based access barrier or firewall 50 b example that also includes an in-only bus or channel 56 that includes a hardware input on/off switch 57 or equivalent function signal interruption mechanism, including an equivalent functioning circuit on a microchip or nanochip.
FIG. 4 is a similar example embodiment to that shown in FIGS. 2 and 3 , but with Private Unit 53 and Public Unit 54 connected by a hardware-based access barrier or firewall 50 c example that also includes an output on/off switch 58 or microcircuit equivalent on the secure, out-only bus or channel 55 .
FIG. 5 shows an example embodiment of any computer such as a first personal computer 1 and/or microchip 90 (and/or 501 ) that is connected to a second computer such as a personal computer 1 and/or microchip 90 (and/or 501 ), the connection between computers made with the same hardware-based access barrier or firewall 50 c example that includes the same buses or channels with on/off switches or equivalents as FIG. 4 .
FIG. 6 shows an example embodiment of a personal computer 1 and/or microchip 90 (and/or 501 ) similar to FIGS. 23A and 23B of the '657 Application, which showed multiple access barriers or firewalls 50 with progressively greater protection, but with hardware-based access barriers or
firewalls
50 c , 50 b , and 50 a used successively from a inner private unit 53 , to an intermediate more private unit 53 1 , and to an inner most private unit 53 2 , respectively; each
Private Unit
53 , 53 1 , and 53 2 has at least one separate connection to at least one separate private or limited-access network.
FIG. 7 shows a schematic illustration of a classic Von Neumann computer hardware architecture.
FIGS. 8 - 14 are additional architectural schematic embodiment examples of 48 the use of hardware-based access barriers or firewalls 50 a , 50 b , and 50 c to create multiple compartments, as well as secure control buses and Faraday Cages.
FIGS. 15 and 16 show a lock mechanism 51 in access barrier/ firewall 50 that enables a highly controlled method of transferring data or code between computer or microchip units separated by 50 , such as between a Private Unit 53 and a Public Unit 54 .
FIG. 17 A shows a buffer zone 350 without circuitry in any process layer in the zone, which functions to prevent hidden backdoor connections between microchip (or computer) units separated by an access barrier/ firewall 50 , such as between a Private Unit 53 and a Public Unit 54 ; FIG. 17 B shows a cross section of the FIG. 17 A embodiment.
FIG. 18 is like FIG. 6 , but shows an embodiment with the central controller (C) positioned in Private Unit 53 1 and a secondary controller (S) 32 in Private Unit 53 2 .
FIGS. 19 and 20 illustrate methods in accordance with the present disclosure.
FIGS. 21 A- 21 E show multiple firewalls 50 within a personal computer 1 or PC microchip 90 .
DETAILED DESCRIPTION OF EXAMPLE EMBODIMENTS
FIGS. 1 - 4 , 6 , 8 - 14 all show useful architectural example embodiments of any computer or microchip, including a personal computer 1 and/or microchip 90 (and/or 501 ) or silicon wafer (or graphene equivalent) 1500 (wafer or wafer portion 1501 , 1502 , and/or 1503 , as described in FIGS. 19-26 and associated text of the '553 Application, which are incorporated by reference herein); tablets, smartphones, servers (including blades) and cloud or supercomputer arrays are other well known examples of computers. The computer shown has an inner hardware-based access barrier or firewall 50 establishing a secure Private Unit (or zone or compartment) 53 that is directly controlled by a user 49 (local in this example) and disconnected by hardware-based access barrier or firewall 50 from a Public Unit (or zone or compartment) 54 that is connected to the open, public and generally insecure Internet 3 and/or another, intermediate network 2 ; the connection of the computer 1 (and/or 90 and/or 501 and/or 1500 or 1501 , 1502 , or 1503 ) to the network 2 and/or Internet 3 can be wired 99 or wireless 100 .
Hardware-based access barrier or firewall 50 (or 50 a , 50 b , or 50 c ) as used in this application refers to an access barrier that includes one or more access barrier or firewall-specific hardware and/or firmware components. This hardware and/or firmware configuration is in contrast to, for example, a computer firewall common in the art that includes only software and general purpose hardware, such as an example limited to firewall-specific software running on the single general purpose microprocessor or CPU of a computer.
The Internet-disconnected Private Unit 53 includes a master controlling device (M or CC) 30 for the computer PC 1 (and/or a master controller unit 93 for the microchip 90 and/or 501 ) that can include a microprocessor or processing unit and thereby take the form of a general purpose microprocessor or CPU, for one useful example, or alternatively only control the computer as a master controller 31 or master controller unit 93 â² (with relatively little or no general purpose processing power compared to the processing units or cores of the computer or microchip being controlled). The user 49 controls the master controlling device 30 (or 31 or 93 or 93 â²) located in the Private Unit 53 and controls both the Private Unit 53 at all times and any part or all of the Public Unit 54 selectively, but can peremptorily control any and all parts of the Public Unit 54 at the discretion of the user 49 through active intervention or selection from a range of settings, or based on standard control settings by default, using for example a secure control bus 48 (to be discussed later). The Public Unit 54 typically can include one or more cores or general purpose microprocessors
40 or 94 and/or graphics-based microprocessors
68 or 82 that are designed for more general operations and not limited to graphics-related operations, including very large numbers of either or both types of microprocessors, and potentially including one or more secondary controllers 32 , as well as any number of specialized or single-function microprocessors.
The inner hardware-based access barrier or firewall has the capability of denying access to said protected portion of the computer 1 or microchip 90 by a generally insecure public network including the Internet, while permitting access by any other computer in the public network including the Internet to said one or more of the processing units included in the unprotected portion of the computer 1 or microchip 90 for an operation with said any other computer in the public network including the Internet when the computer is connected to the public network including the Internet. The operation can be any computer operation whatsoever involving some interaction between two computers including simply sending and/or receiving data and also including, but not limited to, specific examples such as searching, browsing, downloading, streaming, parallel processing, emailing, messaging, file transferring or sharing, telephoning or conferencing.
More particularly, FIG. 1 shows a useful example of an optional (one or more) private network 52 , which is more secure by being, for example, closed and disconnected from the Internet 3 (permanently or temporarily) and/or by having controlled access, to be used for administration and/or management and/or control of the Private Unit 53 , including for example by a business enterprise. Wired 99 connection directly to the Private Unit 53 offers superior security generally for the closed and secure private network 52 , but wireless 100 connection is a option, especially if used with a sufficiently high level of encryption and/or other security measures, including low power radio signals of high frequency and short range and/or directional, as well as frequency shifting and other known wireless security measures. Access from the private non-Internet-connected network 52 can be limited to only a part of the Private Unit 53 or to multiple parts or to all of the Private Unit 53 .
FIG. 1 shows a computer 1 and/or microchip 90 (and/or 501 and/or 1500 , 1501 , 1502 , or 1503 ) with the at least one Public Unit 54 and the at least one Private Unit 53 . The at least one Public Unit 54 is configured for connection to the Internet 3 , either directly or through at least one intermediate network 2 . The at least one Private Unit 53 is disconnected from the networks
2 and 3 by the access barrier/ firewall 50 and is connected to only a private network 52 from a network connection location in the Private Unit 53 . The Public Unit 54 is connected to network 2 and/or 3 from a separate network connection location in the Public Unit 54 . Separate and distinct network connection components 98 for separate wired 99 and/or wireless 100 network connections are shown at the at least two separate and distinct network connection locations, one location in the Private Unit (or units) 53 and the other location in Public Unit 54 indicated in FIG. 1 and FIGS. 2 - 11 , 12 - 14 and 18 .
Such a one or more private non-Internet-connected network 52 (not connected to the open and insecure public Internet 3 either directly or indirectly, such as through another, intermediate network like an Intranet 2 ) can allow specifically for use as a highly secure and closed private network for providing administrative or management or control functions like testing, maintenance, trouble-shooting, synchronizing files, modifying security, or operating or application system updates to the Private Units 53 of any computers (PC 1 or microchip 90 or 501 ) with one or more Public Units 54 that are connected to a less secure local network 2 , such as a business or home network, that is connected to the public Internet 3 .
A particularly useful business example would be administering large numbers of local employee personal computers or network servers, and also including large arrays (especially blades) for cloud applications or supercomputer arrays with a vast multitude of microprocessors or local clusters; in the latter examples, it is possible for a centralized operator to use the private network 52 to control, securely and directly, the master controlling devices
30 or 31 or master controller unit
93 or 93 â² and associated memory or other devices in the Private Units 53 of a multitude of servers, blades, or large arrays or clusters of computers that are connected to the Internet 3 . A personal use example would be to use a private network 52 to connect the private unit 53 of a personal user's smartphone to the private unit 53 of the user's computer laptop in order to update and/or synchronize data or code between the two private units 53 . To maximize security, some or all network 52 traffic can be encrypted and/or authenticated, especially if wireless 100 , including with a very high level of encryption.
In addition, in another useful example, a computer (PC 1 and/or 90 and/or 501 ) can be configured so that the private non-Internet-connected network 52 can have the capability to allow for direct operational control of the Private Unit 53 , and thus the entire computer, from any location (including a remote one), which can be useful for example for businesses operating an array of servers like blades to host cloud operations or supercomputers with large numbers of microprocessors or cores.
One or more access barriers or firewalls 50 a , 50 b , or 50 c can be located between the secure private non-Internet-connected network 52 and the Private Unit 53 , providing a useful example of increased security that can be controlled using the private network 52 .
In yet another useful example, a personal user 49 can dock his smartphone (PC 1 and/or 90 and/or 501 and/or 1500 , 1501 , 1502 , or 1503 ) linking through wire or wirelessly to his laptop or desktop computer (PC 1 and/or 90 and/or 501 and/or 1500 , 1501 , 1502 , or 1503 ) in a network 52 connection to synchronize the Private Units 53 of those two (or more) personal computers or perform other shared operations between the Private Units 53 . In addition, the Public Units 54 of the user's multiple personal computers can be synchronized simultaneously during the same tethering process, or perform other shared operations between the Public Units 54 . Other shared operations can be performed by the two or more linked computers of the user 49 utilizing, for example, two or three or more Private Units 53 , each unit with one or more private non-Internet connected networks 52 , while two or more Public Units 54 can perform shared operations using one or more other networks 2 , including the open and insecure Internet 3 , as shown later in FIG. 6 .
Also shown in FIG. 1 for personal computer PC 1 embodiments is an optional removable memory 47 located in the Private Unit 53 ; the removable memory 47 can be of any form or type or number using any form of one or more direct connections to the Private Unit 53 ; a thumbdrive or SD card are typical examples, connected to USB, Firewire, SD, or other ports located in the Private Unit 53 (or other ports or card slots of any form), which can also be used for the physical connection to the private network 52 . FIG. 1 shows as well an optional one or more removable keys 46 , of which an access key, an ID authentication key, or an encryption and/or decryption key are examples, also connected to the Private Unit 53 using any form of connection, including the above examples; both 46 and 47 can potentially be isolated from other parts of the Private Unit 53 by access barrier(s) or firewall(s) 50 , 50 a , 50 b , and/or 50 c , which can use active configuration such as field programmable gate array(s) 59 .
For microchip 90 (and/or 501 ) embodiments, wireless connection is a feasible option to enable one or more removable memories 47 or one or more r
CLAIMS
Claims ( 26 )
The invention claimed is:
1. A computer or microchip comprising:
at least one network connection for connection to at least a public network of computers, said at least one network connection being located in at least one public unit of said computer or microchip;
at least one additional and separate network connection for connection to at least a separate, private network of computers, said at least one additional and separate network connection being located in at least one protected private unit of said computer or microchip;
at least one inner primary hardware-based access barrier or inner primary hardware-based firewall that is located between and communicatively connects said at least one protected private unit of said computer or microchip and said at least one public unit of said computer; or microchip; and
at least one second hardware-based firewall that is located inside said at least one protected private unit of said computer or microchip;
wherein said private and public units and said two separate network connections are separated by said at least one inner primary hardware-based access barrier or inner primary hardware-based firewall; and
said at least one protected private unit of the computer or microchip includes at least a first microprocessor and a system BIOS of the computer or microchip located in flash or other non-volatile memory;
said at least one public unit of the computer or microchip includes at least a second microprocessor, and
said second microprocessor is separate from said at least one inner hardware-based access barrier or inner hardware-based firewall.
2. The computer or microchip of claim 1 , further comprising at least one third hardware-based firewall that is located inside said at least one second hardware-based firewall.
3. The computer or microchip of claim 1 , wherein the at least one inner primary hardware-based access barrier or inner primary hardware-based firewall comprises at least one bus with an on/off switch controlling communication input and output.
4. The computer or microchip of claim 1 , wherein said at least one protected private unit of the computer or microchip is not configured to connect to the Internet.
5. The computer or microchip of claim 1 , wherein the computer or microchip is included in one of a personal computer, a smartphone, a tablet computer, a server, a cloud server array, a blade, a cluster, a supercomputer, a supercomputer array, and a game machine.
6. The computer or microchip of claim 1 , wherein the at least one public unit of the computer or microchip includes at least 2 or 4 or 8 or 16 or 32 or 64 or 128 or 256 or 512 or 1024 microprocessors or processing units or cores.
7. The computer or microchip of claim 1 , wherein said at least one additional and separate network connection is at least one wired connection to said at least one separate, private network of computers.
8. The computer or microchip of claim 1 , wherein the computer or microchip is surrounded by a Faraday Cage.
9. The computer or microchip of claim 1 , wherein the at least one public unit of the computer or microchip includes at least a second microprocessor configured to operate as a general purpose microprocessor.
10. The computer or microchip of claim 1 , wherein the computer or microchip is configured to operate as a general purpose computer or microchip.
11. The computer or microchip of claim 1 , further comprising a master controlling device that controls the at least one inner primary hardware-based firewall, said master controlling device comprising a microprocessor, core or processing unit configured for general purposes.
12. A computer or microchip comprising:
at least one network connection for connection to at least a public network of computers, said at least one network connection being located in at least one public unit of said computer or microchip;
at least one additional and separate network connection for connection to at least a separate, private network of computers, said at least one additional and separate network connection being located in at least one protected private unit of said computer or microchip;
at least one inner primary hardware-based access barrier or inner primary hardware-based firewall that is located between and communicatively connects said at least one protected private unit of said computer or microchip and said at least one public unit of said computer or microchip; and
at least one second hardware-based firewall that is connected to said at least one network connection and located outside said at least one inner primary hardware-based access barrier or inner primary hardware-based firewall;
wherein said private and public units and said two separate network connections are separated by said at least one inner primary hardware-based access barrier or inner primary hardware-based firewall; and
said at least one protected private unit of the computer or microchip includes at least a first microprocessor and a system BIOS of the computer or microchip located in flash or other non-volatile memory;
said at least one public unit of the computer or microchip includes at least a second microprocessor, and
said second microprocessor is separate from said at least one inner primary hardware-based access barrier or primary inner hardware-based firewall.
13. The computer or microchip of claim 12 , wherein the inner primary hardware-based access barrier or inner primary hardware-based firewall comprises at least one bus with an on/off switch controlling communication input and output.
14. The computer or microchip of claim 12 , further comprising a master controlling device that controls the at least one inner primary hardware-based firewall, said master controlling device comprising a microprocessor, core or processing unit configured for general purposes.
15. The computer or microchip of claim 14 , wherein said master controlling device further comprises a non-volatile memory.
16. The computer or microchip of claim 12 , wherein said secure control bus is configured such that it cannot be affected, interfered with, altered, read from or written to, or superseded by any part of said unprotected public unit or by input from said network.
17. The computer or microchip of claim 14 , wherein said secure control bus provides and ensures direct preemptive control by said master controlling device over said unprotected public unit.
18. The computer or microchip of claim 13 , wherein said secure control bus is configured such that it can be used by said master controlling device to control one or more secondary controllers located on said secure control bus.
19. A computer or microchip configured to be securely controlled, said computer or microchip comprising:
at least one microprocessor, core or processing unit being configured for general purposes and having a connection for a network of computers, said microprocessor, core or processing unit and said network connection being located in an unprotected public unit of the computer or microchip;
at least a master controlling device for the computer or microchip; and
a system BIOS of the computer or microchip located in flash or other non-volatile memory which is located in a portion of the computer or microchip protected by an inner hardware-based access barrier or firewall; and
a secure control bus configured to connect at least said master controlling device with at least said at least one microprocessor, core or processing unit, said secure control bus being isolated from input from said network and input from components of said computer or microchip other than said master controlling device, and said secure control bus is configured such that it cannot be affected, interfered with, altered, read from or written to, or superseded by any part of the unprotected public unit or by input from said network; and
said master controlling device comprising a microprocessor, core or processing unit configured for general purposes and being configured for securely controlling at least one operation executed by at least one said microprocessor, core or processing unit, said secure control being provided by said master controlling device via said secure control bus.
20. The computer or microchip of claim 19 , wherein the inner hardware-based access barrier or firewall comprises a bus with an on/off switch controlling communication input and output.
21. The computer or microchip of claim 19 , wherein said master controlling device is also located in the portion of the computer or microchip protected by an inner hardware-based access barrier or firewall.
22. The computer or microchip of claim 19 , wherein said master controlling device comprises a non-volatile memory.
23. The computer or microchip of claim 19 , wherein said secure control bus provides and ensures direct preemptive control by said master controlling device over said at least one microprocessor, core or processing unit.
24. The computer or microchip of claim 19 , wherein said secure control bus is configured such that it can be used by said master controlling device to control one or more secondary controllers located on said secure control bus.
25. The computer or microchip of claim 19 , wherein said secure control bus is wired, wireless or a channel.
26. The computer or microchip of claim 19 , wherein said secure control bus provides a connection to control a firewall located on the periphery of said computer or microchip.
US17/187,279
2010-01-26
2021-02-26
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Active
2031-03-07
US11683288B2
( en )
Priority Applications (3)
Application Number
Priority Date
Filing Date
Title
US17/187,279
US11683288B2
( en )
2010-01-26
2021-02-26
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
US18/320,577
US12401619B2
( en )
2010-01-26
2023-05-19
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
US19/015,520
US20250150435A1
( en )
2010-01-26
2025-01-09
Method of using a secure private network to actively configure the hardware of a computer microchip
Applications Claiming Priority (22)
Application Number
Priority Date
Filing Date
Title
US28233710P
2010-01-26
2010-01-26
US28237810P
2010-01-29
2010-01-29
US28247810P
2010-02-17
2010-02-17
US28250310P
2010-02-22
2010-02-22
US28286110P
2010-04-12
2010-04-12
US34401810P
2010-05-07
2010-05-07
US201161457184P
2011-01-24
2011-01-24
US13/014,201
US20110225645A1
( en )
2010-01-26
2011-01-26
Basic architecture for secure internet computers
US13/016,527
US8171537B2
( en )
2010-01-29
2011-01-28
Method of securely controlling through one or more separate private networks an internet-connected computer having one or more hardware-based inner firewalls or access barriers
PCT/US2011/023028
WO2011094616A1
( en )
2010-01-29
2011-01-28
The basic architecture for secure internet computers
PCT/US2011/025257
WO2011103299A1
( en )
2010-02-17
2011-02-17
The basic architecture for secure internet computers
US201161457297P
2011-02-18
2011-02-18
US201161457976P
2011-07-26
2011-07-26
US201161457983P
2011-07-28
2011-07-28
US201161573006P
2011-08-02
2011-08-02
US201161573007P
2011-08-03
2011-08-03
US13/398,403
US8429735B2
( en )
2010-01-26
2012-02-16
Method of using one or more secure private networks to actively configure the hardware of a computer or microchip
US13/815,814
US8898768B2
( en )
2010-01-26
2013-03-15
Computer or microchip with a secure control bus connecting a central controller to volatile RAM and the volatile RAM to a network-connected microprocessor
US14/174,693
US10057212B2
( en )
2010-01-26
2014-02-06
Personal computer, smartphone, tablet, or server with a buffer zone without circuitry forming a boundary separating zones with circuitry
US16/051,054
US10375018B2
( en )
2010-01-26
2018-07-31
Method of using a secure private network to actively configure the hardware of a computer or microchip
US16/456,897
US10965645B2
( en )
2010-01-26
2019-06-28
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
US17/187,279
US11683288B2
( en )
2010-01-26
2021-02-26
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Related Parent Applications (1)
Application Number
Title
Priority Date
Filing Date
US16/456,897
Continuation
US10965645B2
( en )
2010-01-26
2019-06-28
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Related Child Applications (1)
Application Number
Title
Priority Date
Filing Date
US18/320,577
Continuation
US12401619B2
( en )
2010-01-26
2023-05-19
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Publications (2)
Publication Number
Publication Date
US20210185005A1
US20210185005A1 ( en )
2021-06-17
US11683288B2
true
US11683288B2 ( en )
2023-06-20
Family
ID=47262783
Family Applications (8)
Application Number
Title
Priority Date
Filing Date
US13/398,403
Active
US8429735B2
( en )
2010-01-26
2012-02-16
Method of using one or more secure private networks to actively configure the hardware of a computer or microchip
US13/815,814
Active
2031-03-08
US8898768B2
( en )
2010-01-26
2013-03-15
Computer or microchip with a secure control bus connecting a central controller to volatile RAM and the volatile RAM to a network-connected microprocessor
US14/174,693
Active
US10057212B2
( en )
2010-01-26
2014-02-06
Personal computer, smartphone, tablet, or server with a buffer zone without circuitry forming a boundary separating zones with circuitry
US14/333,759
Active
US9009809B2
( en )
2010-01-26
2014-07-17
Computer or microchip with a secure system BIOS and a secure control bus connecting a central controller to many network-connected microprocessors and volatile RAM
US14/334,283
Active
US9003510B2
( en )
2010-01-26
2014-07-17
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
US16/051,054
Active
US10375018B2
( en )
2010-01-26
2018-07-31
Method of using a secure private network to actively configure the hardware of a computer or microchip
US16/456,897
Active
2031-04-27
US10965645B2
( en )
2010-01-26
2019-06-28
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
US17/187,279
Active
2031-03-07
US11683288B2
( en )
2010-01-26
2021-02-26
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Family Applications Before (7)
Application Number
Title
Priority Date
Filing Date
US13/398,403
Active
US8429735B2
( en )
2010-01-26
2012-02-16
Method of using one or more secure private networks to actively configure the hardware of a computer or microchip
US13/815,814
Active
2031-03-08
US8898768B2
( en )
2010-01-26
2013-03-15
Computer or microchip with a secure control bus connecting a central controller to volatile RAM and the volatile RAM to a network-connected microprocessor
US14/174,693
Active
US10057212B2
( en )
2010-01-26
2014-02-06
Personal computer, smartphone, tablet, or server with a buffer zone without circuitry forming a boundary separating zones with circuitry
US14/333,759
Active
US9009809B2
( en )
2010-01-26
2014-07-17
Computer or microchip with a secure system BIOS and a secure control bus connecting a central controller to many network-connected microprocessors and volatile RAM
US14/334,283
Active
US9003510B2
( en )
2010-01-26
2014-07-17
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
US16/051,054
Active
US10375018B2
( en )
2010-01-26
2018-07-31
Method of using a secure private network to actively configure the hardware of a computer or microchip
US16/456,897
Active
2031-04-27
US10965645B2
( en )
2010-01-26
2019-06-28
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Country Status (1)
Country
Link
US
( 8 )
US8429735B2
( en )
Families Citing this family (27)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20050180095A1
( en )
1996-11-29
2005-08-18
Ellis Frampton E.
Global network computers
US8125796B2
( en )
*
2007-11-21
2012-02-28
Frampton E. Ellis
Devices with faraday cages and internal flexibility sipes
US12401619B2
( en )
2010-01-26
2025-08-26
Frampton E. Ellis
Computer or microchip with a secure system bios having a separate private network connection to a separate private network
US8429735B2
( en )
2010-01-26
2013-04-23
Frampton E. Ellis
Method of using one or more secure private networks to actively configure the hardware of a computer or microchip
EP3825886B1
( en )
2012-03-29
2024-10-02
Arilou Information Security Technologies Ltd.
Protecting a vehicle electronic system
WO2014055148A2
( en )
*
2012-07-09
2014-04-10
Massachusetts Institute Of Technology
Cryptography and key management device and architecture
US10300779B2
( en )
2013-02-22
2019-05-28
Frampton Ellis
Failsafe devices, including transportation vehicles
DE102014112466A1
( en )
*
2014-06-03
2015-12-03
Fujitsu Technology Solutions Intellectual Property Gmbh
Method of communication between secure computer systems, computer network infrastructure and computer program product
FR3030806B1
( en )
*
2014-12-17
2018-02-02
Thales
CONFIGURABLE ELECTRONIC DATA TRANSFER SYSTEM AND CONFIGURATION METHOD THEREOF
EP3265920A4
( en )
*
2015-03-03
2018-10-17
Gopher Protocol, Inc.
Electronic circuits for secure communications and associated systems and methods
DE102015110190A1
( en )
*
2015-06-24
2016-12-29
Uniscon Universal Identity Control Gmbh
Data processing device and method for operating the same
US9578054B1
( en )
*
2015-08-31
2017-02-21
Newman H-R Computer Design, LLC
Hacking-resistant computer design
US9734095B2
( en )
2015-09-01
2017-08-15
International Business Machines Corporation
Nonvolatile memory data security
EP3583538A4
( en )
*
2017-02-20
2020-11-04
Newman H-R Computer Design, LLC
Hacking-resistant computer design
US11321493B2
( en )
2017-05-31
2022-05-03
Crypto4A Technologies Inc.
Hardware security module, and trusted hardware network interconnection device and resources
CN107463680B
( en )
*
2017-08-07
2020-08-07
浪潮éç¨è½¯ä»¶æéå ¬å¸
Method and device for integrating documents
CN108183901B
( en )
*
2017-12-28
2021-03-16
æ¹å大åå ä¸ç§ææéå ¬å¸
FPGA-based host security protection physical card and data processing method thereof
EP3506587A1
( en )
*
2017-12-29
2019-07-03
Nagravision S.A.
Integrated circuit
US11115383B2
( en )
2018-05-24
2021-09-07
Texas Instruments Incorporated
System on chip firewall memory architecture
TWI700605B
( en )
*
2018-12-28
2020-08-01
æ°åç§æè¡ä»½æéå ¬å¸
Clock frequency attack detectiing system of secure chip
WO2021021070A1
( en )
2019-07-26
2021-02-04
Hewlett-Packard Development Company, L.P.
Storage enclosures
CN111008165A
( en )
*
2019-10-31
2020-04-14
èå·æµªæ½®æºè½ç§ææéå ¬å¸
Four-way server BIOS FLASH control device and method
US11711137B2
( en )
*
2019-12-27
2023-07-25
Hughes Network Systems Llc
Satellite beam determination
CN112911185B
( en )
*
2021-01-18
2022-10-18
æµæ±å¤§åææ¯è¡ä»½æéå ¬å¸
Fault processing method and device for double-control equipment
US12095868B2
( en )
*
2021-11-23
2024-09-17
Oracle International Corporation
Cloud based cross domain systemâvirtual data diode
US11863455B2
( en )
2021-11-23
2024-01-02
Oracle International Corporation
Cloud based cross domain systemâCDSaaS
US11853813B2
( en )
2021-11-23
2023-12-26
Oracle International Corporation
Cloud based cross domain systemâCDS with disaggregated parts
Citations (278)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US3539876A
( en )
1967-05-23
1970-11-10
Ibm
Monolithic integrated structure including fabrication thereof
US3835530A
( en )
1967-06-05
1974-09-17
Texas Instruments Inc
Method of making semiconductor devices
US4245306A
( en )
1978-12-21
1981-01-13
Burroughs Corporation
Selection of addressed processor in a multi-processor network
US4276594A
( en )
1978-01-27
1981-06-30
Gould Inc. Modicon Division
Digital computer with multi-processor capability utilizing intelligent composite memory and input/output modules and method for performing the same
US4278837A
( en )
1977-10-31
1981-07-14
Best Robert M
Crypto microprocessor for executing enciphered programs
US4370515A
( en )
*
1979-12-26
1983-01-25
Rockwell International Corporation
Electromagnetic interference
US4467400A
( en )
1981-01-16
1984-08-21
Burroughs Corporation
Wafer scale integrated circuit
US4489397A
( en )
1980-08-21
1984-12-18
Burroughs Corporation
Chain configurable polycellular wafer scale integrated circuit
US4703436A
( en )
1984-02-01
1987-10-27
Inova Microelectronics Corporation
Wafer level integration technique
US4736317A
( en )
1985-07-17
1988-04-05
Syracuse University
Microprogram-coupled multiple-microprocessor module with 32-bit byte width formed of 8-bit byte width microprocessors
US4747139A
( en )
1984-08-27
1988-05-24
Taaffe James L
Software security method and systems
US4827508A
( en )
1986-10-14
1989-05-02
Personal Library Software, Inc.
Database usage metering and protection system and method
US4855903A
( en )
1984-12-20
1989-08-08
State University Of New York
Topologically-distributed-memory multiprocessor computer
US4882752A
( en )
1986-06-25
1989-11-21
Lindman Richard S
Computer security system
US4893174A
( en )
1985-07-08
1990-01-09
Hitachi, Ltd.
High density integration of semiconductor circuit
US4907228A
( en )
1987-09-04
1990-03-06
Digital Equipment Corporation
Dual-rail processor with error checking at single rail interfaces
US4918596A
( en )
1985-07-01
1990-04-17
Akira Nakano
Hierarchical information processing system
US4969092A
( en )
1988-09-30
1990-11-06
Ibm Corp.
Method for scheduling execution of distributed application programs at preset times in an SNA LU 6.2 network environment
US5025369A
( en )
1988-08-25
1991-06-18
David Schwartz Enterprises, Inc.
Computer system
US5031089A
( en )
1988-12-30
1991-07-09
United States Of America As Represented By The Administrator, National Aeronautics And Space Administration
Dynamic resource allocation scheme for distributed heterogeneous computer systems
DE4008335A1
( en )
1990-03-15
1991-09-26
Panavia Aircraft Gmbh
SHIELDED PC
US5068780A
( en )
1989-08-01
1991-11-26
Digital Equipment Corporation
Method and apparatus for controlling initiation of bootstrap loading of an operating system in a computer system having first and second discrete computing zones
US5103393A
( en )
1990-06-29
1992-04-07
Digital Equipment Corporation
Method of dynamically allocating processors in a massively parallel processing system
US5109512A
( en )
1990-05-31
1992-04-28
International Business Machines Corporation
Process for dispatching tasks among multiple information processors
US5109329A
( en )
1987-02-06
1992-04-28
At&T Bell Laboratories
Multiprocessing method and arrangement
US5136708A
( en )
1987-06-09
1992-08-04
Oce-Nederland B.V.
Distributed office automation system with specific task assignment among workstations
US5155808A
( en )
1988-07-11
1992-10-13
Nec Corporation
System for cooperatively executing programs by sequentially sending a requesting message to serially connected computers
US5195031A
( en )
1988-10-24
1993-03-16
Reuters Limited
Trading system for providing real time context sensitive trading messages based on conversation analysis
US5212780A
( en )
1988-05-09
1993-05-18
Microchip Technology Incorporated
System for single cycle transfer of unmodified data to a next sequentially higher address in a semiconductor memory
US5214657A
( en )
1990-09-21
1993-05-25
Micron Technology, Inc.
Method for fabricating wafer-scale integration wafers and method for utilizing defective wafer-scale integration wafers
US5237507A
( en )
1990-12-21
1993-08-17
Chasek Norman E
System for developing real time economic incentives to encourage efficient use of the resources of a regulated electric utility
US5260943A
( en )
1992-06-16
1993-11-09
Motorola, Inc.
TDM hand-off technique using time differences
WO1994001964A1
( en )
1992-07-08
1994-01-20
Bell Atlantic Network Services, Inc.
Media server for supplying video and multi-media data over the public telephone switched network
US5282272A
( en )
1990-12-21
1994-01-25
Intel Corporation
Interrupt distribution scheme for a computer bus
US5283819A
( en )
1991-04-25
1994-02-01
Compuadd Corporation
Computing and multimedia entertainment system
US5291494A
( en )
1989-08-01
1994-03-01
Digital Equipment Corporation
Method of handling errors in software
US5291502A
( en )
1992-09-04
1994-03-01
The Board Of Trustees Of The Leland Stanford, Jr. University
Electrostatically tunable optical device and optical interconnect for processors
US5291505A
( en )
1993-01-21
1994-03-01
Hughes Aircraft Company
Active energy control for diode pumped laser systems using pulsewidth modulation
US5341477A
( en )
1989-02-24
1994-08-23
Digital Equipment Corporation
Broker for computer network server selection
US5349682A
( en )
1992-01-31
1994-09-20
Parallel Pcs, Inc.
Dynamic fault-tolerant parallel processing system for performing an application function with increased efficiency using heterogeneous processors
US5357632A
( en )
1990-01-09
1994-10-18
Hughes Aircraft Company
Dynamic task allocation in a multi-processor system employing distributed control processors and distributed arithmetic processors
US5357404A
( en )
1991-11-18
1994-10-18
The Whitaker Corporation
EMI shield, and assembly using same
US5361362A
( en )
1989-02-24
1994-11-01
At&T Bell Laboratories
Adaptive job scheduling for multiprocessing systems with master and slave processors executing tasks with opposite anticipated execution times respectively
WO1995001060A1
( en )
1993-06-03
1995-01-05
Lincoln Mint Hong Kong, Ltd.
Interactive communications system with data distribution
US5381534A
( en )
1990-07-20
1995-01-10
Temple University Of The Commonwealth System Of Higher Education
System for automatically generating efficient application - customized client/server operating environment for heterogeneous network computers and operating systems
US5388211A
( en )
1989-04-28
1995-02-07
Softel, Inc.
Method and apparatus for remotely controlling and monitoring the use of computer software
US5392400A
( en )
1992-07-02
1995-02-21
International Business Machines Corporation
Collaborative computing system using pseudo server process to allow input from different server processes individually and sequence number map for maintaining received data sequence
EP0647052A1
( en )
1993-10-04
1995-04-05
France Telecom
Management system for charging of database queries in a telecommunications network
US5410651A
( en )
1988-01-29
1995-04-25
Hitachi, Ltd.
Program loading method and system for distributed processing system
US5426741A
( en )
1991-02-20
1995-06-20
Digital Equipment Corporation
Bus event monitor
US5428783A
( en )
1990-11-28
1995-06-27
Motorola, Inc.
Lan based loosely coupled large grain parallel processing method
US5434998A
( en )
1988-04-13
1995-07-18
Yokogawa Electric Corporation
Dual computer system
US5446843A
( en )
1990-12-20
1995-08-29
Alcatel Italia Spa
Interface unit for dynamically configuring a buffer in different modes to store data transfers based upon different connection details of connected processing units
US5457797A
( en )
1993-08-03
1995-10-10
Forte Software, Inc.
Flexible multi-platform partitioning for computer applications
US5475606A
( en )
1993-03-05
1995-12-12
International Business Machines Corporation
Faraday cage for a printed circuit card
US5497465A
( en )
1992-03-25
1996-03-05
Nippon Sheet Glass Co., Ltd.
Parallel digital processing system using optical interconnection between control sections and data processing sections
US5515511A
( en )
<td itemprop="priori