Patents Assigned to ActivIdentity, Inc.
  • Patent number: 8782427
    Abstract: This invention provides for progressive processing of biometric samples to facilitate user verification. A security token performs initial processing. Due to storage and processing limitations, false rejections may occur. To overcome this, the biometric sample is routed to a stateless server with greater processing power and data enhancement capabilities. The stateless server processes and returns an enhanced biometric sample to the security token for another attempt at verification. In another embodiment, the security token may have a second failure when verifying the enhanced biometric sample. It can then send the enhanced or raw biometric sample to a stateful server. The stateful server processes the biometric sample and performs a one to many search of a biometric database having a master set of enrolled authorized user biometric templates. The security token uses signals from the stateful server to grant or deny access. In both embodiments, heuristics remain with the security token.
    Type: Grant
    Filed: March 20, 2012
    Date of Patent: July 15, 2014
    Assignee: Actividentity, Inc.
    Inventors: Dominique Louis Joseph Fedronic, Eric F. Le Saint
  • Publication number: 20140097936
    Abstract: A portable authentication system includes a security module, that may be a smart card, SIM (Subscriber Identity Module), USB controller with a secure chip, or similar module capable of storing one or more credentials, and an interface module such as a digital badge holder that is able to communicate with the security module, for instance by providing a smart card communication interface. The portable authentication system may be either a single integrated system or a dual system where the security module can be removed or disconnected from the interface system.
    Type: Application
    Filed: December 11, 2013
    Publication date: April 10, 2014
    Applicant: ActivIdentity, Inc.
    Inventors: Yves Louis Gabriel Audebert, Eric F. Le Saint, Jason Hart, Dominique Louis Joseph Fedronic
  • Publication number: 20140068267
    Abstract: An anonymous secure messaging method and system for securely exchanging information between a host computer system and a functionally connected cryptographic module. The invention comprises a Host Security Manager application in processing communications with a security executive program installed inside the cryptographic module. An SSL-like communications pathway is established between the host computer system and the cryptographic module. The initial session keys are generated by the host and securely exchanged using a PKI key pair associated with the cryptographic module. The secure communications pathway allows presentation of critical security parameter (CSP) without clear text disclosure of the CSP and further allows use of the generated session keys as temporary substitutes of the CSP for the session in which the session keys were created.
    Type: Application
    Filed: November 7, 2013
    Publication date: March 6, 2014
    Applicant: ACTIVIDENTITY, INC.
    Inventors: Eric F. LE SAINT, Wu WEN
  • Patent number: 8644516
    Abstract: An anonymous secure messaging method and system for securely exchanging information between a host computer system and a functionally connected cryptographic module. The invention comprises a Host Security Manager application in processing communications with a security executive program installed inside the cryptographic module. An SSL-like communications pathway is established between the host computer system and the cryptographic module. The initial session keys are generated by the host and securely exchanged using a PKI key pair associated with the cryptographic module. The secure communications pathway allows presentation of critical security parameter (CSP) without clear text disclosure of the CSP and further allows use of the generated session keys as temporary substitutes of the CSP for the session in which the session keys were created.
    Type: Grant
    Filed: November 1, 2012
    Date of Patent: February 4, 2014
    Assignee: ActivIdentity, Inc.
    Inventors: Eric F. Le Saint, Wu Wen
  • Patent number: 8628019
    Abstract: A portable authentication system includes a security module, that may be a smart card, SIM (Subscriber Identity Module), USB controller with a secure chip, or similar module capable of storing one or more credentials, and an interface module such as a digital badge holder that is able to communicate with the security module, for instance by providing a smart card communication interface. The portable authentication system may be either a single integrated system or a dual system where the security module can be removed or disconnected from the interface system.
    Type: Grant
    Filed: January 3, 2008
    Date of Patent: January 14, 2014
    Assignee: ActivIdentity, Inc.
    Inventors: Yves Louis Gabriel Audebert, Eric Fernand Le Saint, Jason Hart, Dominique Fedronic
  • Patent number: 8626947
    Abstract: Managing a Personal Security Device (PSD) includes retrieving proprietary information from a remote storage location using a first Remote Computer System, providing at least one Client as a host to the PSD and establishing a communications pipe over a first network between the PSD and the Remote Computer System. The communications pipe communicates with the PSD through the Client. Managing a PSD also includes transmitting the proprietary information from the Remote Computer System to the PSD by sending a PSD-formatted message through the communications pipe, where the proprietary information provided in the PSD-formatted message and passing through the Client is at least partially inaccessible by the Client, processing the PSD-formatted messages at the PSD to extract the proprietary information and storing the proprietary information in the PSD.
    Type: Grant
    Filed: August 24, 2011
    Date of Patent: January 7, 2014
    Assignee: ActivIdentity, Inc.
    Inventors: Yves Louis Gabriel Audebert, Olivier Clemot
  • Patent number: 8402275
    Abstract: A method and a system is provided for establishing a communications path over a communications network between a personal security device (PSD) and a remote computer system without requiring the converting of high-level messages such as API-level messages to PSD-formatted messages such as APDU-formatted messages (and inversely) to be installed on a local client device in which the PSD is connected.
    Type: Grant
    Filed: October 27, 2010
    Date of Patent: March 19, 2013
    Assignee: Actividentity, Inc.
    Inventors: Yves Louis Gabriel Audebert, Olivier Clemot
  • Patent number: 8141141
    Abstract: This invention provides for progressive processing of biometric samples to facilitate verification of an authorized user. The initial processing is performed by a security token. Due to storage space and processing power limitations, excessive false rejections may occur. To overcome this shortfall, the biometric sample is routed to a stateless server, which has significantly greater processing power and data enhancement capabilities. The stateless server receives, processes and returns the biometric sample to the security token for another attempt at verification using the enhanced biometric sample. In a second embodiment of the invention, a second failure of the security token to verify the enhanced biometric sample sends either the enhanced or raw biometric sample to a stateful server. The stateful server again processes the biometric sample and performs a one to many search of a biometric database.
    Type: Grant
    Filed: June 30, 2009
    Date of Patent: March 20, 2012
    Assignee: ActivIdentity, Inc.
    Inventors: Dominique Louis Joseph Fedronic, Eric F. Le Saint
  • Patent number: 7802293
    Abstract: A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials from those entities authorized to share the credentials. A security policy table is provided which allows the sharing entity to selectively authorize or revoke digital credential sharing among a plurality of entities. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.
    Type: Grant
    Filed: April 5, 2006
    Date of Patent: September 21, 2010
    Assignee: ActivIdentity, Inc.
    Inventors: John Jules Alexander Boyer, Eric Fernand Le Saint
  • Patent number: 7787661
    Abstract: A system is used for authorizing access to a Personal Security Device. This system comprises a Personal Security Device 75 and another device 105 which is in functional communication with said Personal Security Device. Said Personal Security Device comprises identification information retrieval data and a biometric authentication application 200 which transfers said identification information retrieval data to said other device 105 in response to an identified match between biometric data sent by said other device and a predetermined biometric reference. Said other device 105 comprises a security executive application 230 for retrieving an Identification Information with at least said identification information retrieval data, thus generating a retrieved Identification Information, and transferring said retrieved Identification Information to said Personal Security Device 75.
    Type: Grant
    Filed: March 29, 2006
    Date of Patent: August 31, 2010
    Assignee: ActivIdentity, Inc.
    Inventors: Eric Fernand Le Saint, Dominique Louis Fedronic, John Jules Alexander Boyer, Hong Liu
  • Publication number: 20100023776
    Abstract: The invention concerns a method for obtaining assurance that a content control key is securely stored in a remote security module for further secure communications between a content provider and said security. A security module manufacturer, which has a pre-established trustful relation with the security module, imports a symmetric transport key into the security module, wherein the symmetric transport key is unique to the security module. The content provider shares the symmetric transport key with the security module manufacturer and exchanges messages with the security module through a security module communication manager in order to get the proof that the security module stores the content control key. At least a portion of the messages exchanged between the content provider and the security module are protected using the symmetric transport key.
    Type: Application
    Filed: March 15, 2007
    Publication date: January 28, 2010
    Applicant: ACTIVIDENTITY INC.
    Inventors: Dominique Fedronic, Eric Le Saint, John Babbidge, Hong Liu
  • Publication number: 20090193264
    Abstract: A strong authentication method and system using a Secure ICC component coupled with a Personal device, and relying on the existing cryptographic protocols and keys for managing the secure ICC to generate One-Time-Passwords when the necessary authentication keys or cryptographic protocols are not already present in the Secure ICC configuration for that purpose.
    Type: Application
    Filed: September 22, 2008
    Publication date: July 30, 2009
    Applicant: ActivIdentity, Inc.
    Inventors: Dominique FEDRONIC, Eric LE SAINT, John BOYER, William BOGGESS
  • Publication number: 20070195998
    Abstract: A system is used for authorizing access to a Personal Security Device. This system comprises a Personal Security Device 75 and another device 105 which is in functional communication with said Personal Security Device. Said Personal Security Device comprises identification information retrieval data and a biometric authentication application 200 which transfers said identification information retrieval data to said other device 105 in response to an identified match between biometric data sent by said other device and a predetermined biometric reference. Said other device 105 comprises a security executive application 230 for retrieving an Identification Information with at least said identification information retrieval data, thus generating a retrieved Identification Information, and transferring said retrieved Identification Information to said Personal Security Device 75.
    Type: Application
    Filed: March 29, 2006
    Publication date: August 23, 2007
    Applicant: ACTIVIDENTITY, INC.
    Inventors: Eric Le Saint, Dominique Fedronic, John Boyer, Hong Liu
  • Publication number: 20060273176
    Abstract: A blocking Personal Security Device (PSD) is disclosed which is intended to protect the privacy of one or more contactless PSDs present within a common RF field generated by a contactless PSDs RF reader. The blocking PSD is programmed to exploit an anti-collision protocol used by the RF reader. The blocking PSD prevents the RF reader from accessing a contactless PSD within the common RF field by ignoring wait time commands and repeatedly responding to the RF reader's interrogations.
    Type: Application
    Filed: June 5, 2006
    Publication date: December 7, 2006
    Applicant: ActivIdentity, Inc.
    Inventors: Yves Audebert, Wu Wen
  • Publication number: 20060230437
    Abstract: A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials from those entities authorized to share the credentials. A security policy table is provided which allows the sharing entity to selectively authorize or revoke digital credential sharing among a plurality of entities. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.
    Type: Application
    Filed: April 5, 2006
    Publication date: October 12, 2006
    Applicant: ACTIVIDENTITY, INC.
    Inventors: John Alexander Boyer, Eric Le Saint
  • Patent number: H2270
    Abstract: A suite of efficient authentication and key establishment protocols for securing contact or contactless interfaces between communicating systems. The protocols may be used in secure physical access, logical access and/or transportation applications, among other implementations. The system authenticates a mobile device such as a smart card and/or mobile phone equipped with a secure element presented to one or more host terminals and establishes shared secure messaging keys to protect communications between the device and terminal. Secure messaging provides an end-to-end protected path of digital documents or transactions through the interface. The protocols provide that the device does not reveal identification information to entities different from a trusted host.
    Type: Grant
    Filed: July 9, 2010
    Date of Patent: June 5, 2012
    Assignee: Actividentity, Inc.
    Inventors: Eric F. Le Saint, Dominique Louis Joseph Fedronic