Patents Assigned to Vasco Data Security, Inc.
  • Publication number: 20100122333
    Abstract: The present invention relates to the field of authentication of users of services over a computer network, more specifically within the paradigms of federated authentication or single sign-on. A known technique consists of associating different trust levels to different authentication mechanisms, wherein the respective trust levels give access to different information resources, notably to provide the possibility to protect more sensitive resources with a stronger form of authentication. The present invention provides a mechanism to allow the trust level to decrease without re-authenticating with the single sign on system, down to the level at which it is no longer sufficient to obtain access to a desired resource. Only then, the user needs to reauthenticate.
    Type: Application
    Filed: November 13, 2008
    Publication date: May 13, 2010
    Applicant: VASCO Data Security, Inc.
    Inventor: Frederik Noe
  • Publication number: 20100065646
    Abstract: The present invention is directed towards authentication tokens that are completely embedded in a non-conductive enclosure. The invention is based on the insight that it would be advantageous to separate the electronic data personalization of such tokens from the visual device personalization. The present application concerns an authentication token that allows communication with an external unit after the production of the nonconductive enclosure, in order to transmit or receive device identification data. As this communication need only take place during the manufacturing process, a low-power close-range transmission technique such as inductive coupling, capacitive coupling, or RFID communication suffices for this purpose. Accordingly, the present application discloses a method for manufacturing authentication tokens, and a token manufactured according to said method.
    Type: Application
    Filed: September 15, 2008
    Publication date: March 18, 2010
    Applicants: VASCO DATA SECURITY, INC., VASCO DATA SECURITY INTERNATIONAL GMBH
    Inventors: Guy Louis Couck, Frank Hoornaert
  • Publication number: 20100058317
    Abstract: The operations required to verify the origin and the authenticity of a software module for an electronic device can advantageously be divided between a general-purpose computer, hereinafter the host, having the electronic device attached to it, and the electronic device itself. More specifically, memory and processing intensive tasks such as syntax checking are done at the host, while security-critical tasks such as cryptographic verifications are done at the electronic device. The present invention thus provides a method for updating software on an electronic device in a trusted way, wherein verification steps are divided between a host system connected to the electronic device, and the electronic device itself. The present invention thus further provides a storage medium containing a program for a host system, causing this host system to perform verification steps with respect to a software update for an attached electronic device, and to appropriately interact with said electronic device.
    Type: Application
    Filed: September 2, 2008
    Publication date: March 4, 2010
    Applicant: VASCO DATA SECURITY, INC.
    Inventor: Harm Braams
  • Publication number: 20090322766
    Abstract: The invention relates to a method to efficiently transmit a digital message over a unidirectional optical link, such as the link between a computer screen and a security token equipped with photosensitive elements. It is an object of this invention to provide a source coding scheme that is optimized for transmissions of alphanumerical data containing frequent occurrences of numerals and less frequent occurrences of non-numerical data. This is achieved by using a modified Huffman code for source coding, consisting of a nibble-based prefix-free binary code. The output of the coder is efficiently mapped onto a 6B4T channel code, wherein unused ternary codewords can be used to signal data-link layer events. This efficient signalling of data-link layer events, in turn, allows for a synchronization scheme based on repeated transmissions of a finite-length message, combined with an out-of-band clock signal.
    Type: Application
    Filed: April 28, 2008
    Publication date: December 31, 2009
    Applicant: VASCO DATA SECURITY, INC.
    Inventor: Dirk Marien
  • Publication number: 20090235339
    Abstract: The invention defines a strong authentication token that remedies a vulnerability to a certain type of social engineering attacks, by authenticating the server or messages purporting to come from the server prior to generating a one-time password or transaction signature; and, in the case of the generation of a transaction signature, signing not only transaction values but also transaction context information and, prior to generating said transaction signature, presenting said transaction values and transaction context information to the user for the user to review and approve using trustworthy output and input means.
    Type: Application
    Filed: March 11, 2008
    Publication date: September 17, 2009
    Applicant: VASCO DATA SECURITY, INC.
    Inventors: Frederik Mennes, Frank Hoornaert
  • Publication number: 20090232515
    Abstract: The present invention provides a method and a device to convert a time varying optical pattern emitted by a display into a digital data signal. More specifically the invention allows a handheld security token to convert a time-varying light intensity pattern emitted by a source such as a computer screen into a digital signal including a sequence of coded data symbols. The invention is based on the insight that the intensity of light emitted by regions of said source can be easily sampled by a simple low-cost processor if appropriate A/D conversion hardware converts the incident light into an electrical signal which is time varying, whereby the base frequency of this electrical signal is a function of the light intensity. Intensity levels used for channel coding and symbol clock can be recovered from the signal by the receiver.
    Type: Application
    Filed: December 12, 2008
    Publication date: September 17, 2009
    Applicant: VASCO Data Security, Inc.
    Inventor: Dirk Marien
  • Publication number: 20090193511
    Abstract: The present patent application discloses a USB token that advantageously mimics a human interface device such as a keyboard in interacting with a host computer, thus removing the need for pre-installation of a dedicated device driver. This is accomplished by requiring the host computer to direct the input of the attached human interface devices of the keyboard type, including the USB token, exclusively to the program interacting with the USB token, by using cryptographic algorithms based on a shared secret, which require less data to be transferred than PKI-based algorithms, and by employing an efficient encoding scheme that minimizes the time needed to exchange information with the USB token, and minimizes the probability of generating ambiguity with input that might legitimately be generated by other attached human interface devices.
    Type: Application
    Filed: June 13, 2008
    Publication date: July 30, 2009
    Applicant: Vasco Data Security, Inc.
    Inventors: Frederik Noe, Frank Hoornaert, Dirk Marien, Nicolas Fort
  • Patent number: 6880079
    Abstract: Methods and systems for secure transmission of information are provided. In accordance with a method of the present invention, a client sends to a server, a request, at least one unique identifier and an encryption key. The server generates a reply to the request and identifies a mobile device (based on the at least one unique identifier) to which to send the reply. The server also encrypts the reply, using the encryption key, to thereby produce an encrypted reply. The encrypted reply is then sent from the server to the mobile device (e.g., a mobile phone). Once received by the mobile device, the encrypted reply is available for transfer (automatically or manually) from the mobile device to the client. Once provided to the client, the client can decrypt the encrypted reply using the encryption key. The decrypted reply is then available for use at (e.g., by) the client.
    Type: Grant
    Filed: April 25, 2002
    Date of Patent: April 12, 2005
    Assignee: Vasco Data Security, Inc.
    Inventors: Mark Gregory Kefford, Alain Marie Eric Vanderstraeten, Mario Raymond Louis Houthooft