AU2009210412A1 - Network interface, gaming system and gaming device - Google Patents

Network interface, gaming system and gaming device Download PDF

Info

Publication number
AU2009210412A1
AU2009210412A1 AU2009210412A AU2009210412A AU2009210412A1 AU 2009210412 A1 AU2009210412 A1 AU 2009210412A1 AU 2009210412 A AU2009210412 A AU 2009210412A AU 2009210412 A AU2009210412 A AU 2009210412A AU 2009210412 A1 AU2009210412 A1 AU 2009210412A1
Authority
AU
Australia
Prior art keywords
data
gaming
network interface
network
controller
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
AU2009210412A
Inventor
John Leslie Boesen
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Aristocrat Technologies Australia Pty Ltd
Original Assignee
Aristocrat Technologies Australia Pty Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from AU2008904365A external-priority patent/AU2008904365A0/en
Application filed by Aristocrat Technologies Australia Pty Ltd filed Critical Aristocrat Technologies Australia Pty Ltd
Priority to AU2009210412A priority Critical patent/AU2009210412A1/en
Publication of AU2009210412A1 publication Critical patent/AU2009210412A1/en
Priority to AU2011265486A priority patent/AU2011265486A1/en
Abandoned legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F17/00Coin-freed apparatus for hiring articles; Coin-freed facilities or services
    • G07F17/32Coin-freed apparatus for hiring articles; Coin-freed facilities or services for games, toys, sports, or amusements
    • G07F17/3241Security aspects of a gaming system, e.g. detecting cheating, device integrity, surveillance
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F17/00Coin-freed apparatus for hiring articles; Coin-freed facilities or services
    • G07F17/32Coin-freed apparatus for hiring articles; Coin-freed facilities or services for games, toys, sports, or amusements

Description

AUSTRALIA Patents Act 1990 COMPLETE SPECIFICATION Standard Patent Applicant (s): Aristocrat Technologies Australia Pty Limited Invention Title: NETWORK INTERFACE, GAMING SYSTEM AND GAMING DEVICE The following statement is a full description of this invention, including the best method for performing it known to me/us: - 2 NETWORK INTERFACE, GAMING SYSTEM AND GAMING DEVICE Field 5 The field of the invention is networked gaming systems and network connectable gaming devices for use in gaming systems. Background 10 Gaming systems wherein two or more gaming devices are connected via a network are known. A known example of such as networked gaming system is a private network implemented within a gaming venue. In such systems the 15 network security is an important to ensure the gaming system performs correctly for player enjoyment. While such gaming systems provide users with enjoyment, a need exists for alternative gaming systems in order to 20 maintain or increase player enjoyment. Summary of the Invention A first aspect provides a network interface device adapted 25 to connect a gaming device to a network, the network interface device comprising: a data handler having processing and memory resources, the data handler being adapted to perform data handling functions for transferring data between a network 30 and a gaming device controller; and a firewall adapted to inhibit transfer of at least some unauthorised data received from the network to the gaming device controller. 35 In some embodiments the firewall uses processing and memory resources which are independent of the gaming device controller. 1727509 1 (GHMatters) 22/08/08 -3 The firewall can be implemented as a function of the data handler. For example, data handler can be implemented using one or more of a digital signal processor, micro 5 controller, microprocessor, microcomputer or FPGA. The firewall can determine whether to allow or deny data transfer based on fire wall rules. In some embodiments the data handler is programmable to update firewall rules. 10 An embodiment of the network interface device further comprises: a first data port adapted for establishing a data connection with a network; and a second data port for establishing a data 15 connection with a controller of a gaming device. In an embodiment the first data port is an Ethernet port. The second port can be a serial data port. 20 The data handler can be further adapted to convert packetized data received from the network to serial data for outputting to the device controller. 25 The network interface device can be implemented as a network interface card adapted for installation into a gaming device. For example, the network interface card can be an Ethernet card. 30 The gaming device for which the network interface card is adapted can be any one or more of a gaming machine, a gaming server, a game controller, a game tournament controller, a bonus server, a player interface module or a player tracking module. 35 A second aspect provides a gaming device comprising: a controller adapted to execute game functions; and 1727509_1 (GHMatters) 22/08/08 - 4 a network interface comprising: a data handler having processing resources independent of the controller, the data handler being adapted to perform data handling functions for 5 transferring of data between the network and the controller, and a firewall adapted to inhibit transfer of at least some unauthorised data received from the network to the controller. 10 The firewall can be implemented using processing and memory resources which are independent of the controller. The firewall can be implemented as a function of the data 15 handler. The data handler can be implemented using one or more of a digital signal processor, micro-controller, microprocessor, microcomputer or FPGA. 20 The gaming device can be a gaming machine, a gaming server, a game controller, a game tournament controller, a bonus server, a player interface module or a player tracking module. 25 A third aspect provides a networked gaming system comprising: one or more gaming devices connected for data communication via a network, wherein at least one gaming 30 devices comprises: a controller adapted to execute game functions; and a network interface comprising: a data handler having processing resources 35 independent of the controller, the data handler being adapted to perform data handling functions for transferring of data between the network and 1727509_1 (GHMatters) 22/08/08 - 5 the controller, and a firewall adapted to inhibit transfer of at least some unauthorised data received from the network to the controller. 5 In an embodiment of the networked gaming system each gaming device connected via the network includes a network interface having a firewall. 10 A fourth aspect provides a method of enhancing security in a networked gaming system, the method comprising providing a firewall adapted to operate during reception of data from a network to inhibit at least some unauthorised data being transferred to a gaming device controller. 15 The method can further comprise the step of providing a gaming device with a network interface card having data handling processing resources independent of processing resources used by the gaming device for executing gaming 20 functions, wherein the data handling processing resources are used for: receiving data from the network; applying firewall rules to inhibit or allow data; and 25 transferring any allowed data to the gaming device controller. In an embodiment the network interface card is an Ethernet card. 30 The method can further comprise the step of updating firewall rules. A fifth aspect provides a program comprising computer 35 readable instructions which when executed by a processor of a network interface card cause the processor to implement the above method. 1727509 1 (GHMatters) 22/08/08 - 6 A sixth aspect provides a computer readable medium comprising computer readable instructions which when executed by a processor of a network interface card cause 5 the processor to implement the above method. A seventh aspect provides a data signal comprising the above program. 10 An eighth aspect provides a processor device for a network interface programmed with instructions which when executed cause the processor device to implement the above method. Brief Description of Drawings 15 An exemplary embodiment of the invention will now be described with reference to the accompanying drawings in which: 20 Figure 1 is a block diagram of the core components of a gaming system; Figure 2 is a perspective view of a stand alone gaming machine; 25 Figure 3 is a block diagram of the functional components of a gaming machine; Figure 4 is a schematic diagram of the functional 30 components of a memory; Figure 5 is a schematic diagram of a network gaming system; 35 Figure 6 is a further block diagram of a gaming system; Figures 7a and 7b illustrate two embodiments of network 1727509 1 (GHMatters) 22/08/08 -7 interface cards; and Figure 8 is a flow chart of an embodiment. 5 Detailed Description Referring to the drawings, there is shown a gaming system wherein gaming devices, such as player operable gaming machines, of the system can be connected via a network. 10 Each gaming device includes a network interface to enable connection to the network. The network interface includes a data handler having processing and memory resources, the data handler being adapted to perform data handling functions for transferring data between a network and a 15 gaming device controller. The network interface can be provided with a firewall to inhibit transfer of at least some unauthorised data from the network to the gaming device controller thus, improving security in the networked gaming system. The firewall can be implemented 20 to use processing and memory resources which are independent of the processing resources used by the gaming device for controlling game play. A gaming system can take a number of different forms. In a 25 first form, a stand alone gaming machine is provided wherein all or most components required for implementing the game are present in a player operable gaming machine. In a second form, a distributed architecture is provided 30 wherein some of the components required for implementing the game are present in a player operable gaming machine and some of the components required for implementing the game are located remotely relative to the gaming machine. For example, a "thick client" architecture may be used 35 wherein part of the game is executed on a player operable gaming machine and part of the game is executed remotely, such as by a gaming server; or a "thin client" 1727509_ 1 (GHMatters) 22/08/08 -8 architecture may be used wherein most of the game is executed remotely such as by a gaming server and a player operable gaming machine is used only to display audible and/or visible gaming information to the player and 5 receive gaming inputs from the player. However, it will be understood that other arrangements are envisaged. For example, an architecture may be provided wherein a gaming machine is networked to a gaming server 10 and the respective functions of the gaming machine and the gaming server are selectively modifiable. For example, the gaming system may operate in stand alone gaming machine mode, "thick client" mode or "thin client" mode depending on the game being played, operating conditions, 15 and so on. Other variations will be apparent to persons skilled in the art. Irrespective of the form, the gaming system comprises several core components. At the broadest level, the core 20 components are a player interface 50 and a game controller 60 as illustrated in Figure 1. The player interface is arranged to enable manual interaction between a player and the gaming system and for this purpose includes the input/output components required for the player to enter 25 instructions to play the game and observe the game outcomes. Components of the player interface may vary from embodiment to embodiment but will typically include a 30 credit mechanism 52 to enable a player to input credits and receive payouts, one or more displays 54, a game play mechanism 56 that enables a player to input game play instructions (e.g. to place a wager), and one or more speakers 58. 35 The game controller 60 is in data communication with the player interface and typically includes a processor 62 1727509 1 (GHMatters) 22/08/08 - 9 that processes the game play instructions in accordance with game play rules and outputs game play outcomes to the display. Typically, the game play instructions are stored as program code in a memory 64 but can also be hardwired. 5 Herein the term "processor" is used to refer generically to any device that can process game play instructions in accordance with game play rules and may include: a microprocessor, microcontroller, programmable logic device or other computational device, a general purpose computer 10 (e.g. a PC) or a server. A gaming system in the form of a stand alone gaming machine 202 is illustrated in Figure 2. The gaming machine 202 includes a console 12 having a display 14 on which are 15 displayed representations of a game 16 that can be played by a player. A mid-trim 20 of the gaming machine 202 houses a bank of buttons 22 for enabling a player to interact with the gaming machine, in particular during game play. The mid-trim 20 also houses a credit input 20 mechanism 24 which in this example includes a coin input chute 24A and a bill collector 24B. Other credit input mechanisms may also be employed, for example, a card reader for reading a smart card, debit card or credit card. Other gaming machines may configure for ticket in 25 such that they have a ticket reader for reading tickets having a value and crediting the player based on the face value of the ticket. A player marketing module (not shown) having a reading device may also be provided for the purpose of reading a player tracking device, for 30 example as part of a loyalty program. The player tracking device may be in the form of a card, flash drive or any other portable storage medium capable of being read by the reading device. In some embodiments, the player marketing module may provide an additional credit mechanism, either 35 by transferring credits to the gaming machine from credits stored on the player tracking device or by transferring credits from a player account in data communication with 1727509 1 (GHMatters) 22/08/08 - 10 the player marketing module. A top box 26 may carry artwork 28, including for example pay tables and details of bonus awards and other 5 information or images relating to the game. Further artwork and/or information may be provided on a front panel 29 of the console 12. A coin tray 30 is mounted beneath the front panel 29 for dispensing cash payouts from the gaming machine 202. 10 The display 14 shown in Figure 2 is in the form of a video display unit, particularly a cathode ray tube screen device. Alternatively, the display 14 may be a liquid crystal display, plasma screen, any other suitable video 15 display unit, or the visible portion of an electromechanical device. The top box 26 may also include a display, for example a video display unit, which may be of the same type as the display 14, or of a different type. 20 Figure 3 shows a block diagram of operative components of a typical gaming machine which may be the same as or different to the gaming machine of Figure 2. 25 The gaming machine 100 includes a game controller 101 having a processor 102. Instructions and data to control operation of the processor 102 are stored in a memory 103, which is in data communication with the processor 102. Typically, the gaming machine 100 will include both 30 volatile and non-volatile memory and more than one of each type of memory, with such memories being collectively represented by the memory 103. The gaming machine has hardware meters 104 for purposes 35 including ensuring regulatory compliance and monitoring player credit, an input/output (I/O) interface 105 for communicating with peripheral devices of the gaming 1727509 1 (GHMatters) 22/08/08 - 11 machine 100. The input/output interface 105 and/or the peripheral devices may be intelligent devices with their own memory for storing associated instructions and data for use with the input/output interface or the peripheral 5 devices. A random number generator module 113 generates random numbers for use by the processor 102. Persons skilled in the art will appreciate that the reference to random numbers includes pseudo-random numbers. 10 In the example shown in Figure 3, a player interface 120 includes peripheral devices that communicate with the game controller 101 comprise one or more displays 106, a touch screen and/or buttons 107 (which provide a game play mechanism), a card and/or ticket reader 108, a printer 15 109, a bill acceptor and/or coin input mechanism 110 and a coin output mechanism 111. Additional hardware may be included as part of the gaming machine 100, or hardware may be omitted as required for the specific implementation. For example, while buttons or touch 20 screens are typically used in gaming machines to allow a player to place a wager and initiate a play of a game any input device that enables the player to input game play instructions may be used. For example, in some gaming machines a mechanical handle is used to initiate a play of 25 the game. In addition, the gaming machine 100 may include a communications interface, for example a network card 112. The network card may, for example, send status 30 information, accounting information or other information to a central controller, server or database and receive data or commands from the central controller, server or database. In embodiments employing a player marketing module, communications over a network may be via player 35 marketing module - i.e. the player marketing module may be in data communication with one or more of the above devices and communicate with it on behalf of the gaming 1727509 1 (GHMatters) 22/08/08 - 12 machine. In accordance with network card embodiments described herein, the network card 112 can include a firewall to inhibit any malicious data circulating on a connected network from being transferred to the game 5 controller processor 102. Figure 4 shows a block diagram of the main components of an exemplary memory 103. The memory 103 includes RAM 103A, EPROM 103B and a mass storage device 103C. The RAM 10 103A typically temporarily holds program files for execution by the processor 102 and related data. The EPROM 103B may be a boot ROM device and/or may contain some system or game related code. The mass storage device 103C is typically used to store game programs, the 15 integrity of which may be verified and/or authenticated by the processor 102 using protected code from the EPROM 103B or elsewhere. It is also possible for the operative components of the 20 gaming machine 100 to be distributed, for example input/output devices 106,107,108,109,110,111 to be provided remotely from the game controller 101. Figure 5 shows a gaming system 200 in accordance with an 25 alternative embodiment. The gaming system 200 includes a network 201, which for example may be an Ethernet network. Gaming machines 202, shown arranged in three banks 203 of two gaming machines 202 in Figure 5, are connected to the network 201. The gaming machines 202 provide a player 30 operable interface and may be the same as the gaming machines 10,100 shown in Figures 2 and 3, or may have simplified functionality depending on the requirements for implementing game play. While banks 203 of two gaming machines are illustrated in Figure 5, banks of one, three 35 or more gaming machines are also envisaged. One or more displays 204 may also be connected to the 1727509_1 (GHMatters) 22/08/08 - 13 network 201. For example, the displays 204 may be associated with one or more banks 203 of gaming machines. The displays 204 may be used to display representations associated with game play on the gaming machines 202, 5 and/or used to display other representations, for example promotional or informational material. In a thick client embodiment, game server 205 implements part of the game played by a player using a gaming machine 10 202 and the gaming machine 202 implements part of the game. With this embodiment, as both the game server and the gaming device implement part of the game, they collectively provide a game controller. A database management server 206 may manage storage of game programs 15 and associated data for downloading or access by the gaming devices 202 in a database 206A. Typically, if the gaming system enables players to participate in a Jackpot game, a Jackpot server 207 will be provided to perform accounting functions for the Jackpot game. A loyalty 20 program server 212 may also be provided. In a thin client embodiment, game server 205 implements most or all of the game played by a player using a gaming machine 202 and the gaming machine 202 essentially 25 provides only the player interface. With this embodiment, the game server 205 provides the game controller. The gaming machine will receive player instructions, pass these to the game server which will process them and return game play outcomes to the gaming machine for 30 display. In a thin client embodiment, the gaming machines could be computer terminals, e.g. PCs running software that provides a player interface operable using standard computer input and output components. Other client/server configurations are possible, and further details of a 35 client/server architecture can be found in WO 2006/052213 and PCT/SE2006/000559, the disclosures of which are incorporated herein by reference. 1727509 1 (GHMatters) 22/08/08 - 14 Servers are also typically provided to assist in the administration of the gaming network 200, including for example a gaming floor management server 208, and a 5 licensing server 209 to monitor the use of licenses relating to particular games. An administrator terminal 210 is provided to allow an administrator to run the network 201 and the devices connected to the network. 10 Persons skilled in the art will appreciate that in accordance with known techniques, functionality at the server side of the network may be distributed over a plurality of different computers. For example, elements may be run as a single "engine" on one server or a 15 separate server may be provided. For example, the game server 205 could run a random generator engine. Alternatively, a separate random number generator server could be provided. Further, persons skilled in the art will appreciate that a plurality of game servers could be 20 provided to run different games or a single game server may run a plurality of different games as required by the terminals. The gaming system 200 may communicate with other gaming 25 systems, other local networks, for example a corporate network, and/or a wide area network such as the Internet, for example through a firewall 211. Persons skilled in the art should appreciate that the firewall 211 acts to prevent malicious data which may exist on an external 30 network, such as the Internet or a wide area network, from entering the gaming network. For example the firewall 211 may be associated with an access server providing a connection to another network. 35 Great care is taken in gaming venues to ensure the security of the gaming network 201. Typical security measures include limiting physical access to the gaming 1727509_1 (GHMatters) 22/08/08 - 15 system network cabling and servers. Data access is also limited to authorised personnel or equipment through use of passwords and authorised access procedures from within the gaming network 201. The external firewall 211 is 5 provided to protect the gaming network 201 against external attacks or malicious data present on an external network. Prohibiting physical access to gaming servers and control 10 equipment is effective where most gaming functionality is resident in the servers, for example the thin client embodiment described above. However, physical isolation of all equipment implementing critical game functions is not possible in a thick client embodiment where part of 15 the game is implemented in the gaming machines 202 on the gaming floor. Similarly some stand alone game machines may be network connectable, for example for monitoring or player tracking. In these cases the game is implemented entirely in the gaming machine 202 which is played by the 20 user on the gaming venue floor. It should be appreciated that while gaming devices are publicly accessible on a gaming floor there is a risk of the devices or the network connecting such devices being 25 compromised and malicious data being injected into the gaming network. This is a particular problem where networked gaming devices on the gaming floor may have game server functionality. For example, a player operable gaming machine may have both game client and gamer server 30 capability to enable implementation of games where one game machine operates as a game server to control aspects of a game being played on other gaming machines acting as game clients. It should be understood that in such embodiments the gaming server is more vulnerable to attack 35 than an embodiment where the game server is inaccessible to the public. 1727509 1 (GHMatters) 22/08/08 - 16 Malicious data may effect the operation of individual gaming machines, servers or degrade network performance in an unacceptable manner, for example preventing the system from operating in compliance within regulatory 5 requirements. This risk exists in all network connected gaming systems and the ability to mitigate this risk is severely limited in current systems. Figure 6 illustrates and example of a network interface 10 600 for use in a network connectable gaming device 610. The network interface 600 includes a data handler 630 and a firewall 620. The data handler 630 is adapted to process the transfer of data between a connected network 605 and a gaming device processor 630 using processing 15 resources independent of those used for processing game play functions. For example, the data handler performs protocol stack operations for transmitting data from the gaming device to the network and receiving data for the gaming device from the network. The protocol stack 20 processing performed by the data handler may vary depending on the embodiment. The firewall 620 is adapted to inhibit transfer of at least some unauthorised data between a network 605 and a gaming device controller 640. The firewall may be implemented as a hardware firewall or 25 as a firewall engine in a processor adapted to apply firewall rules to inhibit or allow data transfer. In various embodiments firewall rules can be defined specific for the gaming device and game being played. 30 Incorporating the firewall into the network interface enables firewall operations to be executed using processing and memory resources which are independent of the gaming device processing resources used for controlling game play. 35 It should be appreciated that a network interface having a firewall can be utilised in a number of different types of 1727509_1 (GHMatters) 22/08/08 - 17 gaming devices, such as stand alone gaming machines, networked gaming machines for thin or thick client embodiments, gaming servers, game controllers etc. By integrating a firewall into the network interface for 5 individual devices, the devices can be protected individually from malicious data which may be injected into the internal gaming network. Figures 7a and 7b illustrate two alternative embodiments 10 of a network interface in the form of an Ethernet card adapted for installation in a gaming device. The Ethernet card 710 represented in Figure 7a has an Ethernet port 715 for connection to a network (not shown) and a serial port 740 for establishing a data connection to the processor of 15 a gaming device (not shown). It should be appreciated by a person skilled in the art that the serial port 740 may be connected to a motherboard of a gaming device via a direct connection, cable or wired connection or via a backplane or other connecting board to provide data 20 communication between a gaming device controller and the network interface. In this embodiment the data handler 730 and firewall 720 are provided using different hardware components. For 25 example, the data handler 730 may be a digital signal processor (DSP) adapted to perform data link layer and network layer protocol stack processing. In this embodiment the firewall 720 is implemented using a separate processor. For example, the firewall may be 30 implemented using a microprocessor having firewall rules programmed in microprocessor memory. The firewall 720 may also be implemented using a hardware device having firewall rules hardwired or programmed into the device, for example an application specific integrated circuit 35 (ASIC) or field programmable gate array (FPGA). Using an ASIC or FPGA for implementing the firewall can minimise the hardware required and provide processing speed 1727509_1 (GHMatters) 22/08/08 - 18 advantages over a generic microprocessor. Further an ASIC embodiment having fixed firewall rules and no re programming facility can have an advantage in that the firewall itself cannot be compromised by a malicious 5 attempt to reprogram the firewall rules. However, there is a trade off in such an embodiment wherein authorised reprogramming of firewall rules hardwired in the ASIC is also not possible. 10 The firewall processor and DSP are in data communication, such that the firewall can inspect each data packet as it is processed by the data handler and apply firewall rules to allow or deny data transfer. Allowed packets will be processed by the data handler and the data transferred to 15 the gaming device processor via the serial port 740. Denied data packets can be ignored, also known as being dropped, by the data handler and processing discontinued for these packets. 20 The firewall can be implemented as a rule engine in communication with the data handler to apply firewall rules to the data being processed by the data handler, and instruct accepting or rejecting of data packets. For example, firewall rules may define that data packets only 25 originating from a group of defined addresses may be allowed. The firewall microprocessor is provided with a packet origin address by the data handler, checks whether the address is valid and instructs the data handler to drop a data packet from an unknown and invalid address and 30 continue processing of a packet from a known and valid address. Alternatively or additionally, the firewall rules may require the firewall to inspect the data format or content to determine whether the data packet complies with a gaming system specific protocol or is relevant to a 35 particular game being played. The firewall may also be adapted to perform additional 1727509 1 (GHMatters) 22/08/08 - 19 actions, such as send an alarm signal to a server or send a signal to cause the gaming device to shut down, inhibit further game play or otherwise quarantine the gaming device from malicious data. For example, in response to 5 malicious data detection from the firewall a game machine may inhibit play and display an "out of order" message. Any patron playing the machine when the detection occurred may be directed to contact the gaming floor supervisor or staff. Alternatively, a stand alone gaming machine may 10 close its network connection in response to detection of malicious data by the firewall. This enables gaming to continue locally but prevents any network accessible features. For example, in this case the gaming machine may still be played using credit entered at the gaming 15 machine in the form of physical notes, coins, tokens or tickets, but be disabled from a player using credit from a network accessible account. The game machine will also be prevented from participating in any network implemented bonus scheme while disconnected from the network. 20 Participation in jackpots or multiplayer features may also be inhibited. The firewall 725 can be implemented in the same processor as the data handler 735. An example of an embodiment 25 having an integrated firewall 725 and data handler 735 is illustrated in Figure 7b. In this embodiment the data handler processor 735 executes both firewall and data handling functions. For example, a digital signal processor may be programmed to apply firewall rules while 30 processing a data packet though a protocol stack. The firewall rules applicable for each protocol layer can be applied to the data packet during processing operations for that layer. In accordance with the firewall rules the processing of the next layer can continue or be 35 terminated. In some embodiment the firewall may be provided with 1727509 _1 (GHMatters) 22/08/08 - 20 additional information by a gaming processor, such as a game state, which may also be used when applying game rules. For example, a game state may be used to select appropriate rules such as a "reject all" rule if the game 5 is in a state where no data is expected to be received from the network. In an alternative example the game state may be information applied during processing of a firewall rule, such as identifying a mismatch where a data packet is received from a valid origin but when the game 10 is in a state where no data is expected from this origin. In an alternative embodiment the firewall may be adapted to read additional information such as a game state from memory used by the gaming processor. The game state may be stored in memory used by the firewall processor which 15 is independent of memory used for processing game play functions, for example a game processor may send a game state signal to a firewall processor to update the game state stores in firewall memory each time the game state changes. The firewall processor can then use the game 20 state stored in memory so no exchange of information between the separate game processor and firewall processor is required during application of firewall rules to received packets. 25 An example of a process for receiving a data packet from the network is illustrated in Figure 8. A data packet is received from the network 810 by the network interface. The initial packet reception can include error detection, such as checksum tests, performed by the data handler to 30 ensure the physical reception of data from the network is of adequate quality before beginning data processing. The packet header is examined and address information is read from the data packet header, for example media access control (MAC) address information. Firewall rules can be 35 applied to this address information 825 to determine whether the address information indicates an invalid packet. For example, the firewall rules may compare the 1727509_1 (GHMattera) 22/08/08 - 21 address information against known authorised packet origin addresses or known blocked/unauthorised addresses. Packets from blocked addresses will be deemed invalid. In some cases packets from unknown addresses may also be 5 deemed invalid depending on the defined rule. Alternatively, parts of the address information may be compared against defined criteria and the packet deemed invalid if the criteria are not met. For example, multicast data packets may be automatically deemed 10 invalid. Processing for the packet is stopped 880 if the packet is deemed invalid. Otherwise the processing continues with examination of the packet payload data 830. Firewall rules may define allowed formats for the packet 15 payload data. For example, a header of packet payload data may be read to determine whether the data format is valid in accordance with firewall rules 840 and processing stopped for any invalid packets 880. The game state may also be checked 850 to determine whether or not the data 20 packet is valid in the context of the game 860. For example, based on whether or not the data is expected in the read game state or whether the data is in the correct format for the game state. Where the data packet is allowed in accordance with the firewall rules the data 25 packet is processed 870 as necessary for transfer to the processor executing gaming functions and transferred 875 to the gaming device processor. It should be appreciated that the gaming device processor has been quarantined from the data and not been involved in any data processing 30 until the data is transferred in step 875. Where the packet is deemed invalid in accordance with the firewall rules the processing is stopped 880. The data handler then proceeds to process the next packet received 35 from the network 810. It should be appreciated that the level of packet data 1727509_1 (GHMatters) 22/08/08 - 22 analysis by the firewall may vary in different embodiments. For example, the firewall may act as a simple packet filter accepting or rejecting packets based on packet header data, or perform more comprehensive 5 analysis of packet payload data to determine whether the data is valid in the gaming system or in the context of game play. The complexity of the firewall may vary depending on the type of gaming device enabling the firewall functionality to be targeted to protection 10 required for the specific type of gaming device. In some embodiments the firewall can be implemented using a programmable processor or using rules stored in programmable memory, thus enabling the firewall to be 15 updated and firewall rules modified if necessary. This also enables game specific firewall modifications, such as adding rules for new game states or to recognise game data specific to a particular game. 20 Integrating a firewall into the network interface of a gaming device can have advantages for hardware footprint minimisation. This is important advantage for gaming venues where the number of gaming devices which can be made available to patrons for their enjoyment is limited 25 by the physical size of the gaming devices. An embodiment having an integrated data handler and firewall implemented in a single processor can have advantages for minimising the hardware required for the 30 device. This embodiment may also provide processing and programming advantages as the need for interwork between separate data handler and firewall processors is alleviated. However, the program for the data handler may be complicated by including the application of firewall 35 rules and any required additional instructions for actions taken in the event of malicious data being detected. 1727509_ 1 (GHMatters) 22/08/08 - 23 A set of instructions or program integrating the data handler and firewall may be installed in a processor of a pre-existing network interface card to upgrade the card to have the firewall functionality. For example, a pre 5 existing Ethernet card having a sufficiently powerful DSP or microprocessor, may be re-programmed using a set of instructions for an integrated data handler and firewall. Although the above embodiments describe a separate network 10 interface card, the network interface including a firewall can also be provided on a main circuit board for a gaming device to minimise the hardware footprint, in this instance the main circuit board would include two separate processors, a first processor for executing gaming 15 functions and a second processor for executing the data handling and firewall functions of the network interface. It should be appreciated from the above examples that the processing resources used in the network interface for 20 data handling and implementing firewall functionality are independent of the processing resources used by the gaming device for implementing aspects of game play. For example, in the embodiments illustrated in Figures 7a and b the network interface is implemented as an Ethernet card 25 having one or more processors which are adapted to perform data handling and firewall functions. Any data which is allowed by the firewall, in accordance with the firewall rules, is transferred via serial port 740 to a main board of the gaming device on which resides a main processor for 30 implementing gaming functions, such as functions of a game controller, outcome generator or player interface. Using processing capability which is independent of the gaming device processing capability isolates firewall 35 processing from game processing. For example, if a software firewall was implemented in a gaming machine the firewall processing and game processing will both execute 1727509 1 (GHMatters) 22/08/08 - 24 on the gaming machine processor, sharing the processing resources. If the gaming machine has a random number generator which executes in the gaming machine processor, this presents a risk of the random number generation 5 function failing to operate in accordance with regulatory requirements if the processor becomes overloaded. For example, if the Ethernet network connecting the game machines was compromised and a flood of data injected into 10 the network, then the firewall may consume all or substantially all the processing capacity of the gaming machine processor for handling and filtering the malicious data packets. As a consequence the operation of the random number generator may be slowed or affected in some 15 way which compromises the randomness of the results. It should be appreciated by persons skilled in the art that maintaining the integrity of the random number generation process is critical to the operation of a gaming machine or system. It should further be appreciated that by using 20 processing resources for firewall functions which are independent of processing resources used for random number generation the above problem can be avoided. Embodiments can provide the network interface and gaming 25 processing resources on a single circuit board using one or more processors for gaming functions which are separate from one or more processors used for data handling and firewall functions. In some embodiments some resources, such as memory resources, may be shared or accessible to 30 both processors. Care must be taken in such an embodiment that interference does not occur to effect performance of the processor executing gaming functions. In other embodiments each processor has its own independent memory resources. 35 It will be understood to persons skilled in the art of the invention that many modifications may be made without 1727509_1 (GHMatters) 22/08/08 - 25 departing from the spirit and scope of the invention, in particular it will be apparent that certain features of the invention can be combined to form further embodiments. Although an Ethernet network has been used as an example, 5 embodiments of the network interface for alternative networks, including various embodiments of wired, optical and wireless networks, are envisaged. It is to be understood that, if any prior art publication 10 is referred to herein, such reference does not constitute an admission that the publication forms a part of the common general knowledge in the art, in Australia or any other country. 15 In the claims which follow and in the preceding description, except where the context requires otherwise due to express language or necessary implication, the word "comprise" or variations such as "comprises" or "comprising" is used in an inclusive sense, i.e. to 20 specify the presence of the stated features but not to preclude the presence or addition of further features in various embodiments of the invention. 1727509 1 (GHMatters) 22/08/08

Claims (35)

1. A network interface device adapted to connect a gaming device to a network, the network interface device 5 comprising: a data handler having processing and memory resources, the data handler being adapted to perform data handling functions for transferring data between a network and a gaming device controller; and 10 a firewall adapted to inhibit transfer of at least some unauthorised data received from the network to the gaming device controller.
2. A network interface device as claimed in claim 1 15 wherein the firewall uses processing and memory resources which are independent of the gaming device controller.
3. A network interface device as claimed in claim 2 wherein the firewall is implemented as a function of the 20 data handler.
4. A network interface device as claimed in claim 3 wherein the data handler is implemented using one or more of a digital signal processor, micro-controller, 25 microprocessor, microcomputer or FPGA.
5. A network interface device as claimed in claim 4 wherein the firewall determines whether to allow or deny data transfer based on fire wall rules. 30
6. A network interface device as claimed in claim 5 wherein the data handler is programmable to update firewall rules. 35
7. A network interface device as claimed in claim 1 further comprising: a first data port adapted 'for establishing a data 1727509_ 1 (GHMatters) 22/08/08 - 27 connection with a network; and a second data port for establishing a data connection with a controller of a gaming device. 5
8. A network interface device as claimed in claim 7 wherein the first data port is an Ethernet port.
9. A network interface device as claimed in claim 8 wherein the second data port is a serial data port. 10
10. A network interface as claimed in claim 9 wherein the data handler is further adapted to convert packetized data received from the network to serial data for outputting to the device controller. 15
11. A network interface device as claimed in claim 7 implemented as a network interface card adapted for installation into a gaming device. 20
12. A network interface device as claimed in claim 11 wherein the network interface card is an Ethernet card.
13. A network interface device as claimed in claim 11 wherein the gaming device for which the network interface 25 card is adapted is any one or more of a gaming machine, a gaming server, a game controller, a game tournament controller, a bonus server, a player interface module or a player tracking module. 30
14. A gaming device comprising: a controller adapted to execute game functions; and a network interface comprising: a data handler having processing resources independent of the controller, the data handler 35 being adapted to perform data handling functions for transferring of data between the network and the controller, and 1727509_1 (GHMatters) 22/08/08 - 28 a firewall adapted to inhibit transfer of at least some unauthorised data received from the network to the controller. 5
15. A gaming device as claimed in claim 14 wherein the firewall is implemented using processing and memory resources which are independent of the controller.
16. A gaming device as claimed in claim 14 wherein the 10 firewall is implemented as a function of the data handler.
17. A gaming device as claimed in claim 16 wherein the data handler is implemented using one or more of a digital signal processor, micro-controller, microprocessor, 15 microcomputer or FPGA.
18. A gaming device as claimed in claim 17 wherein the firewall determines whether to allow or deny data transfer based on fire wall rules. 20
19. A gaming device as claimed in claim 18 wherein the data handler is programmable to update firewall rules.
20. A gaming device as claimed in claim 14 wherein the 25 network interface further comprises: a first data port adapted for establishing a data connection with a network; and a second data port for establishing a data connection with the controller. 30
21. A gaming device as claimed in claim 20 wherein the first data port is an Ethernet port.
22. A gaming device as claimed in claim 21 wherein the 35 second data port is a serial data port.
23. A gaming device as claimed in claim 20 wherein the 1727509_1 (GHMatters) 22/08/08 - 29 network interface is a network interface card.
24. A gaming device as claimed in claim 23 wherein the network interface card is an Ethernet card. 5
25. A gaming device as claimed in claim 14 wherein the gaming device is a gaming machine, a gaming server, a game controller, a game tournament controller, a bonus server, a player interface module or a player tracking module. 10
26. A networked gaming system comprising: one or more gaming devices connected for data communication via a network, wherein at least one gaming devices comprises: 15 a controller adapted to execute game functions; and a network interface comprising: a data handler having processing resources independent of the controller, the data handler 20 being adapted to perform data handling functions for transferring of data between the network and the controller, and a firewall adapted to inhibit transfer of at least some unauthorised data received from 25 the network to the controller.
27. A networked gaming system as claimed in claim 26 wherein each gaming device connected via the network includes a network interface having a firewall. 30
28. A method of enhancing security in a networked gaming system, the method comprising providing a firewall adapted to operate during reception of data from a network to inhibit at least some unauthorised data being transferred 35 to a gaming device controller.
29. A method as claimed in claim 28 further comprising 1727509_1 (GHMatters) 22/08/08 - 30 the step of providing a gaming device with a network interface card having data handling processing resources independent of processing resources used by the gaming device for executing gaming functions, wherein the data 5 handling processing resources are used for: receiving data from the network; applying firewall rules to inhibit or allow data; and transferring any allowed data to the gaming device 10 controller.
30. A method as claimed in claim 29 wherein the network interface card is an Ethernet card. 15
31. A method as claimed in claim 29 further comprising the step of updating firewall rules.
32. A program comprising computer readable instructions which when executed by a processor of a network interface 20 card cause the processor to implement the method of claim 28.
33. A computer readable medium comprising computer readable instructions which when executed by a processor 25 of a network interface card cause the processor to implement the method of claim 28.
34. A data signal comprising the program of claim 32. 30
35. A processor device for a network interface programmed with instructions which when executed cause the processor device to implement the method of claim 28. 1727509_1 (GHMatters) 22/08/08
AU2009210412A 2008-08-22 2009-08-21 Network interface, gaming system and gaming device Abandoned AU2009210412A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
AU2009210412A AU2009210412A1 (en) 2008-08-22 2009-08-21 Network interface, gaming system and gaming device
AU2011265486A AU2011265486A1 (en) 2008-08-22 2011-12-22 Network interface, gaming system and gaming device

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
AU2008904365 2008-08-22
AU2008904365A AU2008904365A0 (en) 2008-08-22 Network interface, gaming system and gaming device
AU2009210412A AU2009210412A1 (en) 2008-08-22 2009-08-21 Network interface, gaming system and gaming device

Related Child Applications (1)

Application Number Title Priority Date Filing Date
AU2011265486A Division AU2011265486A1 (en) 2008-08-22 2011-12-22 Network interface, gaming system and gaming device

Publications (1)

Publication Number Publication Date
AU2009210412A1 true AU2009210412A1 (en) 2010-03-11

Family

ID=41696900

Family Applications (1)

Application Number Title Priority Date Filing Date
AU2009210412A Abandoned AU2009210412A1 (en) 2008-08-22 2009-08-21 Network interface, gaming system and gaming device

Country Status (2)

Country Link
US (1) US20100048304A1 (en)
AU (1) AU2009210412A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113688093A (en) * 2021-08-24 2021-11-23 中电科申泰信息科技有限公司 Intelligent network card based on Ethernet controller

Families Citing this family (46)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6676127B2 (en) 1997-03-13 2004-01-13 Shuffle Master, Inc. Collating and sorting apparatus
US6254096B1 (en) 1998-04-15 2001-07-03 Shuffle Master, Inc. Device and method for continuously shuffling cards
US6655684B2 (en) 1998-04-15 2003-12-02 Shuffle Master, Inc. Device and method for forming and delivering hands from randomly arranged decks of playing cards
US8590896B2 (en) 2000-04-12 2013-11-26 Shuffle Master Gmbh & Co Kg Card-handling devices and systems
US8337296B2 (en) 2001-09-28 2012-12-25 SHFL entertaiment, Inc. Method and apparatus for using upstream communication in a card shuffler
US7753373B2 (en) 2001-09-28 2010-07-13 Shuffle Master, Inc. Multiple mode card shuffler and card reading device
US8011661B2 (en) 2001-09-28 2011-09-06 Shuffle Master, Inc. Shuffler with shuffling completion indicator
US8616552B2 (en) 2001-09-28 2013-12-31 Shfl Entertainment, Inc. Methods and apparatuses for an automatic card handling device and communication networks including same
US7677565B2 (en) 2001-09-28 2010-03-16 Shuffle Master, Inc Card shuffler with card rank and value reading capability
US6886829B2 (en) 2002-02-08 2005-05-03 Vendingdata Corporation Image capturing card shuffler
US9126102B2 (en) 2002-05-20 2015-09-08 Bally Gaming, Inc. Four-card poker game with variable wager
US20160136511A9 (en) 2002-05-20 2016-05-19 Bally Gaming, Inc. Four Card Poker Game with Variable Wager
US20060284376A1 (en) 2005-06-17 2006-12-21 Shuffle Master, Inc. Casino table variant of Texas hold'em poker
US9183705B2 (en) 2004-09-10 2015-11-10 Bally Gaming, Inc. Methods of playing wagering games
US20060066048A1 (en) 2004-09-14 2006-03-30 Shuffle Master, Inc. Magnetic jam detection in a card shuffler
US7764836B2 (en) 2005-06-13 2010-07-27 Shuffle Master, Inc. Card shuffler with card rank and value reading capability using CMOS sensor
US7556266B2 (en) 2006-03-24 2009-07-07 Shuffle Master Gmbh & Co Kg Card shuffler with gravity feed system for playing cards
US8353513B2 (en) 2006-05-31 2013-01-15 Shfl Entertainment, Inc. Card weight for gravity feed input for playing card shuffler
US8579289B2 (en) 2006-05-31 2013-11-12 Shfl Entertainment, Inc. Automatic system and methods for accurate card handling
US8342525B2 (en) 2006-07-05 2013-01-01 Shfl Entertainment, Inc. Card shuffler with adjacent card infeed and card output compartments
US8070574B2 (en) 2007-06-06 2011-12-06 Shuffle Master, Inc. Apparatus, system, method, and computer-readable medium for casino card handling with multiple hand recall feature
US8919775B2 (en) 2006-11-10 2014-12-30 Bally Gaming, Inc. System for billing usage of an automatic card handling device
US7988152B2 (en) 2009-04-07 2011-08-02 Shuffle Master, Inc. Playing card shuffler
US8967621B2 (en) 2009-04-07 2015-03-03 Bally Gaming, Inc. Card shuffling apparatuses and related methods
US8800993B2 (en) 2010-10-14 2014-08-12 Shuffle Master Gmbh & Co Kg Card handling systems, devices for use in card handling systems and related methods
US9731190B2 (en) 2011-07-29 2017-08-15 Bally Gaming, Inc. Method and apparatus for shuffling and handling cards
US8485527B2 (en) 2011-07-29 2013-07-16 Savant Shuffler LLC Card shuffler
US8974305B2 (en) 2012-01-18 2015-03-10 Bally Gaming, Inc. Network gaming architecture, gaming systems, and related methods
US9120007B2 (en) 2012-01-18 2015-09-01 Bally Gaming, Inc. Network gaming architecture, gaming systems, and related methods
US9165428B2 (en) 2012-04-15 2015-10-20 Bally Gaming, Inc. Interactive financial transactions
US8960674B2 (en) 2012-07-27 2015-02-24 Bally Gaming, Inc. Batch card shuffling apparatuses including multi-card storage compartments, and related methods
US9511274B2 (en) 2012-09-28 2016-12-06 Bally Gaming Inc. Methods for automatically generating a card deck library and master images for a deck of cards, and a related card processing apparatus
US9378766B2 (en) 2012-09-28 2016-06-28 Bally Gaming, Inc. Card recognition system, card handling device, and method for tuning a card handling device
EP3113855B1 (en) 2014-04-11 2019-04-10 Bally Gaming, Inc. Method and apparatus for shuffling and handling cards
US9474957B2 (en) 2014-05-15 2016-10-25 Bally Gaming, Inc. Playing card handling devices, systems, and methods for verifying sets of cards
US9566501B2 (en) 2014-08-01 2017-02-14 Bally Gaming, Inc. Hand-forming card shuffling apparatuses including multi-card storage compartments, and related methods
USD764599S1 (en) 2014-08-01 2016-08-23 Bally Gaming, Inc. Card shuffler device
US9504905B2 (en) 2014-09-19 2016-11-29 Bally Gaming, Inc. Card shuffling device and calibration method
US9993719B2 (en) 2015-12-04 2018-06-12 Shuffle Master Gmbh & Co Kg Card handling devices and related assemblies and components
US10339765B2 (en) 2016-09-26 2019-07-02 Shuffle Master Gmbh & Co Kg Devices, systems, and related methods for real-time monitoring and display of related data for casino gaming devices
US10933300B2 (en) 2016-09-26 2021-03-02 Shuffle Master Gmbh & Co Kg Card handling devices and related assemblies and components
US11896891B2 (en) 2018-09-14 2024-02-13 Sg Gaming, Inc. Card-handling devices and related methods, assemblies, and components
US11376489B2 (en) 2018-09-14 2022-07-05 Sg Gaming, Inc. Card-handling devices and related methods, assemblies, and components
US11338194B2 (en) 2018-09-28 2022-05-24 Sg Gaming, Inc. Automatic card shufflers and related methods of automatic jam recovery
CN112546608A (en) 2019-09-10 2021-03-26 夏佛马士特公司 Card handling apparatus for defect detection and related methods
US11173383B2 (en) 2019-10-07 2021-11-16 Sg Gaming, Inc. Card-handling devices and related methods, assemblies, and components

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080220880A1 (en) * 2005-09-07 2008-09-11 Bally Gaming, Inc. Trusted Cabinet Identification System
US20070255861A1 (en) * 2006-04-27 2007-11-01 Kain Michael T System and method for providing dynamic network firewall with default deny
TWI368848B (en) * 2007-05-09 2012-07-21 Arcadyan Technology Corp Remote control system and method thereof

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113688093A (en) * 2021-08-24 2021-11-23 中电科申泰信息科技有限公司 Intelligent network card based on Ethernet controller

Also Published As

Publication number Publication date
US20100048304A1 (en) 2010-02-25

Similar Documents

Publication Publication Date Title
US20100048304A1 (en) Network interface, gaming system and gaming device
EP2047437B1 (en) Virtual player tracking and related services
US8262451B2 (en) Bingo system with discrete payout categories
US20080108405A1 (en) Self-correcting configuration items
US20070026935A1 (en) Methods and devices for managing gaming networks
US8469795B2 (en) Method of gaming and a gaming system
US9424712B2 (en) Authenticating components in wagering game systems
WO2007030472A2 (en) Gaming device with a virtualization manager
US20150356827A1 (en) Method of gaming, a game controller, and a gaming system
US11495092B2 (en) System and method for implementing a lottery game
US20190180568A1 (en) Method of gaming and a gaming system
US9842470B2 (en) Method of gaming, a gaming system and a game controller
US10431043B2 (en) Integrated game-specific progressive controller shared in a gaming system
AU2011265486A1 (en) Network interface, gaming system and gaming device
US20160321872A1 (en) Method of gaming, a game controller and a gaming system
US10861282B2 (en) Server process validation
US20140243080A1 (en) Gaming system and method
US8998696B2 (en) Gaming system and a method of gaming
US20130267303A1 (en) Electronic Gaming System, Device, Machine and Method

Legal Events

Date Code Title Description
MK5 Application lapsed section 142(2)(e) - patent request and compl. specification not accepted