Patents Assigned to ActivIdentity, Inc.
-
Patent number: 8782427Abstract: This invention provides for progressive processing of biometric samples to facilitate user verification. A security token performs initial processing. Due to storage and processing limitations, false rejections may occur. To overcome this, the biometric sample is routed to a stateless server with greater processing power and data enhancement capabilities. The stateless server processes and returns an enhanced biometric sample to the security token for another attempt at verification. In another embodiment, the security token may have a second failure when verifying the enhanced biometric sample. It can then send the enhanced or raw biometric sample to a stateful server. The stateful server processes the biometric sample and performs a one to many search of a biometric database having a master set of enrolled authorized user biometric templates. The security token uses signals from the stateful server to grant or deny access. In both embodiments, heuristics remain with the security token.Type: GrantFiled: March 20, 2012Date of Patent: July 15, 2014Assignee: Actividentity, Inc.Inventors: Dominique Louis Joseph Fedronic, Eric F. Le Saint
-
Publication number: 20140097936Abstract: A portable authentication system includes a security module, that may be a smart card, SIM (Subscriber Identity Module), USB controller with a secure chip, or similar module capable of storing one or more credentials, and an interface module such as a digital badge holder that is able to communicate with the security module, for instance by providing a smart card communication interface. The portable authentication system may be either a single integrated system or a dual system where the security module can be removed or disconnected from the interface system.Type: ApplicationFiled: December 11, 2013Publication date: April 10, 2014Applicant: ActivIdentity, Inc.Inventors: Yves Louis Gabriel Audebert, Eric F. Le Saint, Jason Hart, Dominique Louis Joseph Fedronic
-
Publication number: 20140068267Abstract: An anonymous secure messaging method and system for securely exchanging information between a host computer system and a functionally connected cryptographic module. The invention comprises a Host Security Manager application in processing communications with a security executive program installed inside the cryptographic module. An SSL-like communications pathway is established between the host computer system and the cryptographic module. The initial session keys are generated by the host and securely exchanged using a PKI key pair associated with the cryptographic module. The secure communications pathway allows presentation of critical security parameter (CSP) without clear text disclosure of the CSP and further allows use of the generated session keys as temporary substitutes of the CSP for the session in which the session keys were created.Type: ApplicationFiled: November 7, 2013Publication date: March 6, 2014Applicant: ACTIVIDENTITY, INC.Inventors: Eric F. LE SAINT, Wu WEN
-
Patent number: 8644516Abstract: An anonymous secure messaging method and system for securely exchanging information between a host computer system and a functionally connected cryptographic module. The invention comprises a Host Security Manager application in processing communications with a security executive program installed inside the cryptographic module. An SSL-like communications pathway is established between the host computer system and the cryptographic module. The initial session keys are generated by the host and securely exchanged using a PKI key pair associated with the cryptographic module. The secure communications pathway allows presentation of critical security parameter (CSP) without clear text disclosure of the CSP and further allows use of the generated session keys as temporary substitutes of the CSP for the session in which the session keys were created.Type: GrantFiled: November 1, 2012Date of Patent: February 4, 2014Assignee: ActivIdentity, Inc.Inventors: Eric F. Le Saint, Wu Wen
-
Patent number: 8628019Abstract: A portable authentication system includes a security module, that may be a smart card, SIM (Subscriber Identity Module), USB controller with a secure chip, or similar module capable of storing one or more credentials, and an interface module such as a digital badge holder that is able to communicate with the security module, for instance by providing a smart card communication interface. The portable authentication system may be either a single integrated system or a dual system where the security module can be removed or disconnected from the interface system.Type: GrantFiled: January 3, 2008Date of Patent: January 14, 2014Assignee: ActivIdentity, Inc.Inventors: Yves Louis Gabriel Audebert, Eric Fernand Le Saint, Jason Hart, Dominique Fedronic
-
Patent number: 8626947Abstract: Managing a Personal Security Device (PSD) includes retrieving proprietary information from a remote storage location using a first Remote Computer System, providing at least one Client as a host to the PSD and establishing a communications pipe over a first network between the PSD and the Remote Computer System. The communications pipe communicates with the PSD through the Client. Managing a PSD also includes transmitting the proprietary information from the Remote Computer System to the PSD by sending a PSD-formatted message through the communications pipe, where the proprietary information provided in the PSD-formatted message and passing through the Client is at least partially inaccessible by the Client, processing the PSD-formatted messages at the PSD to extract the proprietary information and storing the proprietary information in the PSD.Type: GrantFiled: August 24, 2011Date of Patent: January 7, 2014Assignee: ActivIdentity, Inc.Inventors: Yves Louis Gabriel Audebert, Olivier Clemot
-
Patent number: 8402275Abstract: A method and a system is provided for establishing a communications path over a communications network between a personal security device (PSD) and a remote computer system without requiring the converting of high-level messages such as API-level messages to PSD-formatted messages such as APDU-formatted messages (and inversely) to be installed on a local client device in which the PSD is connected.Type: GrantFiled: October 27, 2010Date of Patent: March 19, 2013Assignee: Actividentity, Inc.Inventors: Yves Louis Gabriel Audebert, Olivier Clemot
-
Patent number: 8141141Abstract: This invention provides for progressive processing of biometric samples to facilitate verification of an authorized user. The initial processing is performed by a security token. Due to storage space and processing power limitations, excessive false rejections may occur. To overcome this shortfall, the biometric sample is routed to a stateless server, which has significantly greater processing power and data enhancement capabilities. The stateless server receives, processes and returns the biometric sample to the security token for another attempt at verification using the enhanced biometric sample. In a second embodiment of the invention, a second failure of the security token to verify the enhanced biometric sample sends either the enhanced or raw biometric sample to a stateful server. The stateful server again processes the biometric sample and performs a one to many search of a biometric database.Type: GrantFiled: June 30, 2009Date of Patent: March 20, 2012Assignee: ActivIdentity, Inc.Inventors: Dominique Louis Joseph Fedronic, Eric F. Le Saint
-
Patent number: 7802293Abstract: A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials from those entities authorized to share the credentials. A security policy table is provided which allows the sharing entity to selectively authorize or revoke digital credential sharing among a plurality of entities. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.Type: GrantFiled: April 5, 2006Date of Patent: September 21, 2010Assignee: ActivIdentity, Inc.Inventors: John Jules Alexander Boyer, Eric Fernand Le Saint
-
Patent number: 7787661Abstract: A system is used for authorizing access to a Personal Security Device. This system comprises a Personal Security Device 75 and another device 105 which is in functional communication with said Personal Security Device. Said Personal Security Device comprises identification information retrieval data and a biometric authentication application 200 which transfers said identification information retrieval data to said other device 105 in response to an identified match between biometric data sent by said other device and a predetermined biometric reference. Said other device 105 comprises a security executive application 230 for retrieving an Identification Information with at least said identification information retrieval data, thus generating a retrieved Identification Information, and transferring said retrieved Identification Information to said Personal Security Device 75.Type: GrantFiled: March 29, 2006Date of Patent: August 31, 2010Assignee: ActivIdentity, Inc.Inventors: Eric Fernand Le Saint, Dominique Louis Fedronic, John Jules Alexander Boyer, Hong Liu
-
Publication number: 20100023776Abstract: The invention concerns a method for obtaining assurance that a content control key is securely stored in a remote security module for further secure communications between a content provider and said security. A security module manufacturer, which has a pre-established trustful relation with the security module, imports a symmetric transport key into the security module, wherein the symmetric transport key is unique to the security module. The content provider shares the symmetric transport key with the security module manufacturer and exchanges messages with the security module through a security module communication manager in order to get the proof that the security module stores the content control key. At least a portion of the messages exchanged between the content provider and the security module are protected using the symmetric transport key.Type: ApplicationFiled: March 15, 2007Publication date: January 28, 2010Applicant: ACTIVIDENTITY INC.Inventors: Dominique Fedronic, Eric Le Saint, John Babbidge, Hong Liu
-
Publication number: 20090193264Abstract: A strong authentication method and system using a Secure ICC component coupled with a Personal device, and relying on the existing cryptographic protocols and keys for managing the secure ICC to generate One-Time-Passwords when the necessary authentication keys or cryptographic protocols are not already present in the Secure ICC configuration for that purpose.Type: ApplicationFiled: September 22, 2008Publication date: July 30, 2009Applicant: ActivIdentity, Inc.Inventors: Dominique FEDRONIC, Eric LE SAINT, John BOYER, William BOGGESS
-
Publication number: 20070195998Abstract: A system is used for authorizing access to a Personal Security Device. This system comprises a Personal Security Device 75 and another device 105 which is in functional communication with said Personal Security Device. Said Personal Security Device comprises identification information retrieval data and a biometric authentication application 200 which transfers said identification information retrieval data to said other device 105 in response to an identified match between biometric data sent by said other device and a predetermined biometric reference. Said other device 105 comprises a security executive application 230 for retrieving an Identification Information with at least said identification information retrieval data, thus generating a retrieved Identification Information, and transferring said retrieved Identification Information to said Personal Security Device 75.Type: ApplicationFiled: March 29, 2006Publication date: August 23, 2007Applicant: ACTIVIDENTITY, INC.Inventors: Eric Le Saint, Dominique Fedronic, John Boyer, Hong Liu
-
Publication number: 20060273176Abstract: A blocking Personal Security Device (PSD) is disclosed which is intended to protect the privacy of one or more contactless PSDs present within a common RF field generated by a contactless PSDs RF reader. The blocking PSD is programmed to exploit an anti-collision protocol used by the RF reader. The blocking PSD prevents the RF reader from accessing a contactless PSD within the common RF field by ignoring wait time commands and repeatedly responding to the RF reader's interrogations.Type: ApplicationFiled: June 5, 2006Publication date: December 7, 2006Applicant: ActivIdentity, Inc.Inventors: Yves Audebert, Wu Wen
-
Publication number: 20060230437Abstract: A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials from those entities authorized to share the credentials. A security policy table is provided which allows the sharing entity to selectively authorize or revoke digital credential sharing among a plurality of entities. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.Type: ApplicationFiled: April 5, 2006Publication date: October 12, 2006Applicant: ACTIVIDENTITY, INC.Inventors: John Alexander Boyer, Eric Le Saint
-
Patent number: H2270Abstract: A suite of efficient authentication and key establishment protocols for securing contact or contactless interfaces between communicating systems. The protocols may be used in secure physical access, logical access and/or transportation applications, among other implementations. The system authenticates a mobile device such as a smart card and/or mobile phone equipped with a secure element presented to one or more host terminals and establishes shared secure messaging keys to protect communications between the device and terminal. Secure messaging provides an end-to-end protected path of digital documents or transactions through the interface. The protocols provide that the device does not reveal identification information to entities different from a trusted host.Type: GrantFiled: July 9, 2010Date of Patent: June 5, 2012Assignee: Actividentity, Inc.Inventors: Eric F. Le Saint, Dominique Louis Joseph Fedronic