Patents by Inventor Ernie F. Brickell

Ernie F. Brickell has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 7571329
    Abstract: Secure storage and retrieval of a unique value associated with a device to/from a memory of a processing system. In at least one embodiment, the device needs to be able to access the unique value across processing system resets, and the device does not have sufficient non-volatile storage to store the unique value itself. Instead, the unique value is stored in the processing system memory in such a way that the stored unique value does not create a unique identifier for the processing system or the device. A pseudo-randomly or randomly generated initialization vector may be used to vary an encrypted data structure used to store the unique value in the memory.
    Type: Grant
    Filed: July 14, 2004
    Date of Patent: August 4, 2009
    Assignee: Intel Corporation
    Inventors: Ernie F. Brickell, Alberto J. Martinez, David W. Grawrock, James A. Sutton, II, Clifford D. Hall
  • Publication number: 20090129600
    Abstract: An apparatus and method is provided for a direct anonymous attestation scheme from short-group signatures. The method may include the creation of a group public/private key pair for a trusted membership group defined by an issuer; and assigning a cryptographic pair that is combined with a unique private member value to form a private membership key. A trusted member device generates the unique private member value during a join procedure of a trusted membership group. In one embodiment, the private member value of the private membership key is unknown to the issuer. A member may sign a message with the private membership key to form a short-group digital signature that is verified using a public key of the trusted membership group to maintain anonymity of trusted member devices. A size of the private membership key may be reduced to enable storage within a trusted platform module. Other embodiments are described and claimed.
    Type: Application
    Filed: September 11, 2008
    Publication date: May 21, 2009
    Inventors: Ernie F. Brickell, Jiangtao Li
  • Publication number: 20090089564
    Abstract: Embodiments of an invention to protection a branch instruction from side channel vulnerabilities are described. In one embodiment, a method includes receiving a request to modify the operation of a processor to protect against side channel attacks, and modifying branch prediction operation in response to the request.
    Type: Application
    Filed: December 6, 2007
    Publication date: April 2, 2009
    Inventors: Ernie F. Brickell, Sergiu Ghetie, Shay Gueron, Adil Karrar, Francis X. McKeen
  • Patent number: 7512785
    Abstract: A server registering a first party as a party relying upon a second party's certificate, revoking the second party's certificate after registering the first party, and initiating communication with the first party to indicate that the second party's certificate has been revoked.
    Type: Grant
    Filed: July 18, 2003
    Date of Patent: March 31, 2009
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 7509498
    Abstract: A second digital credential that includes a first digital credential and a digital signature is received, and the validity of the second digital credential is determined. A determination is made whether the first digital credential is valid based on the validity of the second digital credential.
    Type: Grant
    Filed: June 29, 2001
    Date of Patent: March 24, 2009
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Publication number: 20090041232
    Abstract: A method, system, and apparatus are provided for establishing trust without revealing identity. According to one embodiment, values in a first proof corresponding to a first statement are precomputed, a request for a second proof is received from a challenger, and the first and second proofs are completed.
    Type: Application
    Filed: October 23, 2008
    Publication date: February 12, 2009
    Inventor: Ernie F. Brickell
  • Patent number: 7454611
    Abstract: One aspect of an embodiment of the invention provides a method, system, and device to prove to a challenger that a prover device has a signature from a device manufacturer without revealing the signature to the challenger. According to one implementation, a challenger is provided with the result of a one-way function of a secret held by a prover device. An interactive proof is employed, between the prover device and the challenger, to prove to the challenger that the secret used in the one-way function has been signed by a device signature without revealing the secret or the device signature or the prover device's identity to the challenger.
    Type: Grant
    Filed: January 11, 2007
    Date of Patent: November 18, 2008
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 7444512
    Abstract: A method, system, and apparatus are provided for establishing trust without revealing identity. According to one embodiment, values in a first proof corresponding to a first statement are precomputed, a request for a second proof is received from a challenger, and the first and second proofs are completed.
    Type: Grant
    Filed: April 11, 2003
    Date of Patent: October 28, 2008
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 7395246
    Abstract: The system includes receiving, from a delegator, a designation of a role and a delegate to assume the role, receiving, from a credential service provider, an indication that the designation is valid, issuing a delegation credential in response to receiving the indication, and issuing a confirmation to the delegator, which indicates that the delegation credential was issued.
    Type: Grant
    Filed: November 28, 2001
    Date of Patent: July 1, 2008
    Assignee: Intel Corporation
    Inventors: Ernie F. Brickell, Wesley Deklotz, Jeff U. Glover, Michael R. Premi, Matthew D. Wood, Marion H. Shimoda
  • Patent number: 7366305
    Abstract: One aspect of an embodiment of the invention provides a method and platform to prove to a challenger that a responder device possesses cryptographic information from a certifying manufacturer. This is accomplished by performing a direct proof by the responder device to prove that the responder device possesses the cryptographic information. The direct proof comprises at least one exponentiation being conducted using an exponent having a bit length no more than one-half a bit length of a modulus (n).
    Type: Grant
    Filed: September 30, 2003
    Date of Patent: April 29, 2008
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 7359518
    Abstract: Secured information is stored on a server accessible to a network. A first access component that is required to permit use of the secured information is distributed to a delegate. In the absence of a second access component, the first access component is not sufficient to permit use of the secured information. The second access component can be stored on the server or stored with a third party for distribution to the delegate.
    Type: Grant
    Filed: April 5, 2001
    Date of Patent: April 15, 2008
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 7165181
    Abstract: One aspect of an embodiment of the invention provides a method, system, and device to prove to a challenger that a prover device has a signature from a device manufacturer without revealing the signature to the challenger. According to one implementation, a challenger is provided with the result of a one-way function of a secret held by a prover device. An interactive proof is employed, between the prover device and the challenger, to prove to the challenger that the secret used in the one-way function has been signed by a device signature without revealing the secret or the device signature or the prover device's identity to the challenger.
    Type: Grant
    Filed: November 27, 2002
    Date of Patent: January 16, 2007
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 7142674
    Abstract: A key exchange protocol can be performed between components of a system, such as between a computer program being executed by the processor of a PC (or other computer system) and a peripheral. A peripheral with a user input capability and a very limited display capability, such as a keyboard or a mouse, may be used to confirm a key exchange between the system components in a way that requires the user to enter only small amounts of input data (e.g., keystrokes or mouse clicks). Security between components may be enhanced without having a negative impact on usability of the system. Embodiments of the present invention help to deter “man in the middle” attacks wherein an attacker gains control of a system component situated between certain communicating system components.
    Type: Grant
    Filed: June 18, 2002
    Date of Patent: November 28, 2006
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 7130999
    Abstract: In one embodiment of the invention is a method to use authentication certificates to authorize peers to particular applications. In addition to using authentication certificates to authenticate the identity and trustworthiness of a peer, authentication certificates are additionally used to authorize peers to particular applications. A list of certificates is maintained in a Peer Authorized Certificate Store (PACS), where the certificates may comprise any combination of root certificates, intermediate certificates, and peer certificates. When an authentication certificate is received from a peer, the peer is authenticated using the authentication certificate; and authorized by checking the authentication certificate against a Peer Authorized Certificate Store (PACS).
    Type: Grant
    Filed: March 27, 2002
    Date of Patent: October 31, 2006
    Assignee: Intel Corporation
    Inventors: Raju Yasala, Ernie F. Brickell, Donald J. Eckardt
  • Patent number: 7073195
    Abstract: An arrangement is provided for controlled access to identification and status information or delegated credentials. A delegation, formed between a delegator and a delegate, is registered with a delegate credential service provider. The delegate requests a service from a relying party that then requests, based on the requested service and the delegation, delegated credential from the delegate credential service provider. The delegate credential service provider sends the delegated credential to the relying party. According to the received delegated credential, the relying party generates a service response and sends the response to the delegate.
    Type: Grant
    Filed: January 28, 2002
    Date of Patent: July 4, 2006
    Assignee: Intel Corporation
    Inventors: Ernie F. Brickell, Wesley Deklotz, Jeff U. Glover, Michael R. Premi, Matthew D. Wood, Marion H. Shimoda
  • Patent number: 7051209
    Abstract: A system and method is provided for creating and using strong passwords with high entropy. The system and method uses user generated questions and answers. To protect against an adversary from obtaining the questions and researching the answers, multiple levels of questions and answers are used. There are a first set of question(s) and a first set of answer(s) corresponding to the first set of questions as well as a second set of plurality of questions and a second set of plurality of answers corresponding to the second set of plurality of questions. The second set of plurality of answers is concatenated to form a single pass phrase. To enter the pass phrase at a client workstation, a user is presented with a plurality of entries for entering the second set of plurality of answers and an option to request a second set of plurality of questions.
    Type: Grant
    Filed: June 29, 2000
    Date of Patent: May 23, 2006
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Patent number: 6965881
    Abstract: An credential verification service (CVS) authenticates digital credentials, such as, digital certificates, at the request of online service providers. The CVS stores the authentication results and transaction information in a central activity log. The transaction information can include a size of the transaction, the online service requesting the authentication, an internet protocol (IP) address of a computing device originating the transaction and the goods or services involved in the transaction. The CVS generates an activity report from the activity log that lists the authentication results and the transaction information. A fraud detection module within the CVS analyzes the activity log to identify any unusual patterns in order to identify fraudulent activities or general misuse of the digital credential.
    Type: Grant
    Filed: June 30, 2000
    Date of Patent: November 15, 2005
    Assignee: Intel Corporation
    Inventors: Ernie F. Brickell, Wesley Deklotz
  • Patent number: 6834112
    Abstract: A private key may be securely distributed to a user of a remote client computer over an insecure channel. The user's private key is transmitted to the client from a remote server in an encrypted format. A first hash of the user's password is transmitted to the remote server and is used to authenticate the user. A second hash of the user's password remains with the client computer and is used to decrypt the user's private key. The user only has to remember one login name and a single associated password. Thus, the private key can be securely distributed from the remote server to the client computer system. The distribution does not require the user to carry any special hardware devices and only requires a single password. Because the private key is not permanently stored at the client computers, even if an unauthorized user has access to the client computers, they are not likely to be able to obtain the private key.
    Type: Grant
    Filed: April 21, 2000
    Date of Patent: December 21, 2004
    Assignee: Intel Corporation
    Inventor: Ernie F. Brickell
  • Publication number: 20040205341
    Abstract: A method, system, and apparatus are provided for establishing trust without revealing identity. According to one embodiment, values in a first proof corresponding to a first statement are precomputed, a request for a second proof is received from a challenger, and the first and second proofs are completed.
    Type: Application
    Filed: April 11, 2003
    Publication date: October 14, 2004
    Inventor: Ernie F. Brickell
  • Publication number: 20040103281
    Abstract: One aspect of an embodiment of the invention provides a method, system, and device to prove to a challenger that a prover device has a signature from a device manufacturer without revealing the signature to the challenger. According to one implementation, a challenger is provided with the result of a one-way function of a secret held by a prover device. An interactive proof is employed, between the prover device and the challenger, to prove to the challenger that the secret used in the one-way function has been signed by a device signature without revealing the secret or the device signature or the prover device's identity to the challenger.
    Type: Application
    Filed: November 27, 2002
    Publication date: May 27, 2004
    Inventor: Ernie F. Brickell