Patents Assigned to Entrust, Inc.
-
Patent number: 11496322Abstract: One or more computing devices employs a method that includes requesting a transient credential (e.g., a one-time PKI certificate) as a first identity credential for an application component instance based on a unique identifier associated with the application component instance. The method includes requesting a dynamically-created second identity credential for the application component instance of the application using a request signed (e.g., using the public key of the first identity PKI certificate) based on the transient credential. The method includes receiving the dynamically-created second identity credential and using the dynamically-created second identity credential in a cryptographic function by the application component instance; and managing the replacement of this credential in environments without persistent archival storage accessible by the device/application.Type: GrantFiled: October 11, 2018Date of Patent: November 8, 2022Assignee: ENTRUST, INC.Inventors: Thomas P. Chmara, Lucas J. Koops, Jon Ferguson
-
Patent number: 11438173Abstract: A method and apparatus provides a blockchain that includes one or more blocks that contain a cryptographic binding of a signature-verification public key and/or a data encryption public key to the identity of the holder of the corresponding private key. The binding is performed by one or more key binding entities, referred to herein as a blockchain identity binder. Originators and recipients use the identity binding data to secure block chain transactions.Type: GrantFiled: June 29, 2020Date of Patent: September 6, 2022Assignee: ENTRUST, INC.Inventor: Timothy Edward Moses
-
Patent number: 11159332Abstract: A constrained device includes an exterior surface affixed with a public key associated with the constrained device. Alternatively, or in addition, the public key may be included in a container that stores the constrained device. The constrained device also includes memory, which stores a private key, wherein the private key corresponds to the public key that is affixed on the exterior surface of the constrained device. By displaying the public key on the constrained device, a system administrator may document the public key and related information about the device and its intended role in the network without requiring any human interface or any establishment of power or network at the installation site.Type: GrantFiled: May 28, 2019Date of Patent: October 26, 2021Assignee: Entrust, Inc.Inventor: Timothy Edward Moses
-
Patent number: 11102013Abstract: In one example, an apparatus such as an authorization server and method for secure communication between constrained devices issues cryptographic communication rights among a plurality of constrained devices. Each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function. The method includes receiving a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request, and includes providing a response including an identification of a subset of the plurality of constrained devices that have cryptographic communication rights with the identified first of the plurality of constrained devices. A software update server then updates the cryptographic code modules in the sub-set of the plurality of constrained devices.Type: GrantFiled: June 18, 2020Date of Patent: August 24, 2021Assignee: Entrust, Inc.Inventor: Timothy E. Moses
-
Patent number: 10749684Abstract: A method and apparatus provides a blockchain that includes one or more blocks that contain a cryptographic binding of a signature-verification public key and/or a data encryption public key to the identity of the holder of the corresponding private key. The binding is performed by one or more key binding entities, referred to herein as a blockchain identity binder. Originators and recipients use the identity binding data to secure block chain transactions.Type: GrantFiled: September 26, 2017Date of Patent: August 18, 2020Assignee: Entrust, Inc.Inventor: Timothy Edward Moses
-
Patent number: 10728043Abstract: In one example, an apparatus such as an authorization server and method for secure communication between constrained devices issues cryptographic communication rights among a plurality of constrained devices. Each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function. The method includes receiving a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request, and includes providing a response including an identification of a subset of the plurality of constrained devices that have cryptographic communication rights with the identified first of the plurality of constrained devices. A software update server then updates the cryptographic code modules in the sub-set of the plurality of constrained devices.Type: GrantFiled: July 20, 2016Date of Patent: July 28, 2020Assignee: Entrust, Inc.Inventor: Timothy Edward Moses
-
Patent number: 10645581Abstract: A method and apparatus provides for user authentication. In an example, the method and apparatus includes establishing a very short range wireless communication link between the first apparatus and the second apparatus and authenticating a user of the first apparatus by the second apparatus directly using a different and short range peer to peer wireless communication link between the first apparatus and the second apparatus in response to establishing the very short range wireless communication link.Type: GrantFiled: November 15, 2018Date of Patent: May 5, 2020Assignee: Entrust, Inc.Inventors: Clayton Douglas Smith, Lindsay Martin Kent
-
Patent number: 10581618Abstract: In one example, an enrollment device, such as a smart phone with an enrollment application executing thereon, obtains in situ enrollment information from at least one or more target device of a plurality of target devices in a network. The enrollment device provides the in situ enrollment information that is obtained from the at least one target device, to a security management device, such as a public key certificate generator (e.g., a certification authority) for the network, to facilitate target device configuration certificate generation for the at least one target device. The security management device uses the in situ enrollment information and other device specific information as well as operational information that is desired for a device, and issues a configuration certificate for the at least one target device. A system and methods are also set forth.Type: GrantFiled: July 9, 2015Date of Patent: March 3, 2020Assignee: Entrust, Inc.Inventor: Timothy Edward Moses
-
Patent number: 10165440Abstract: A method and apparatus provides for user authentication. In an example, the method and apparatus includes receiving a selected signal strength for smart card emulation authentication. The method and apparatus also includes receiving a signal from a portable wireless device radio transceiver. The method also includes measuring the signal strength of the signal. The method and apparatus also includes, if the signal is at or above the selected signal strength, transmitting one or more signals to the portable radio device radio transceiver requesting user authentication, and if the signal is not at or above a selected signal strength, refusing a request to authenticate by the portable radio device radio transceiver. The method and apparatus also includes receiving one or more authentication response signals from the portable radio device in response to the request for user authentication, the one or more response signals including at least authentication information unique to a user.Type: GrantFiled: March 15, 2013Date of Patent: December 25, 2018Assignee: Entrust, Inc.Inventors: Clayton Douglas Smith, Lindsay Martin Kent
-
Patent number: 10009378Abstract: A method and apparatus provides first or second factor authentication by providing selectability of a plurality of second factor authentication policies associated with a second factor authentication article. The first or second factor authentication article includes authentication information, such as a plurality of data elements in different cells or locations on the authentication article, which can be located by using corresponding location information. The method and apparatus provides second factor authentication based on the first or second factor authentication article by enforcing at least one of the plurality of selected authentication policies.Type: GrantFiled: November 16, 2015Date of Patent: June 26, 2018Assignee: Entrust, Inc.Inventors: Michael Chiviendacz, Steve Neville, Chris Voice, Michael Morgan
-
Patent number: 9994054Abstract: An apparatus and methods for generating an identity document obtain unique machine data related to an identity document generation system. The apparatus and methods obtain personalization data related to an intended holder of the identity document. The apparatus and methods generate a unique machine and personalization data object that includes values of the unique machine data and the personalization data. The apparatus and methods digitally sign the unique machine and personalization data object. The apparatus and methods incorporate the signed unique machine and personalization data object into the identity document.Type: GrantFiled: August 18, 2015Date of Patent: June 12, 2018Assignee: Entrust, Inc.Inventors: Mark Andrew Joynes, Gregory James Wetmore, Gordon William Coulson, Sharon Marie Boeyen
-
Patent number: 9954860Abstract: In one example, a proxy server acts as a gateway to a website and modifies the traffic between a web browser on a user device and the website server, as necessary to request protection by providing step-up authentication and/or transaction verification. The proxy server blocks transactions when protection is required but has not occurred (either because the authentication was not proper or due to the detection of another problem). Associated methods and systems are also provided.Type: GrantFiled: March 13, 2014Date of Patent: April 24, 2018Assignee: Entrust, Inc.Inventors: Christopher D. Wood, Michael Holtstrom, Roland Thomas Lockhart, Murray McCulligh, Serge Jean Maurice Mister, Greg Wetmore
-
Patent number: 9876793Abstract: A method for providing authentication of a user of a recipient unit when the recipient unit is off-line includes storing one or a plurality of one-time challenge-reply sets based on an on-line communication with a sender unit. In one example, each of the one-time challenge-reply sets includes at least a one-time challenge-reply pair for use in off-line authentication of the user for a particular resource available through the recipient unit. When the user is offline, the method includes selecting at least one of the plurality of stored one-time challenge-reply sets for off-line authentication of the user for the particular resource available through the recipient unit. The one-time challenge-reply sets may be associated with an article.Type: GrantFiled: March 7, 2016Date of Patent: January 23, 2018Assignee: Entrust, Inc.Inventors: Chris Voice, Marc Smith, Murray McCulligh, Robert Zuccherato
-
Patent number: 9767627Abstract: Apparatus, systems and methods are disclosed that utilize a vehicle user's input to provide logical context of legitimate vehicle usage through a remote access device to defend the vehicle from theft. As such, an additional level of security is employed and may be used in addition to other security and theft prevention technologies of the vehicle. In one example, a legitimate automobile operator signals the context of the vehicle's state to a hardware security module in the vehicle. The states include, for example, to disallow all diagnostic system access or to allow diagnostic access for servicing.Type: GrantFiled: July 9, 2015Date of Patent: September 19, 2017Assignee: Entrust, Inc.Inventor: Jason Aurele Soroko
-
Patent number: 9519770Abstract: A transaction card comprising, such as a credit card or debit card, includes transaction card serial number information that identifies the transaction card, sender authentication information identifiable by location information and location information is on the transaction card. In addition, account information is also on the transaction card.Type: GrantFiled: September 23, 2011Date of Patent: December 13, 2016Assignee: Entrust, Inc.Inventors: Christopher Brian Voice, Michael Chiviendacz, Edward Pillman
-
Publication number: 20160072845Abstract: A method and apparatus provides first or second factor authentication by providing selectability of a plurality of second factor authentication policies associated with a second factor authentication article. The first or second factor authentication article includes authentication information, such as a plurality of data elements in different cells or locations on the authentication article, which can be located by using corresponding location information. The method and apparatus provides second factor authentication based on the first or second factor authentication article by enforcing at least one of the plurality of selected authentication policies.Type: ApplicationFiled: November 16, 2015Publication date: March 10, 2016Applicant: ENTRUST, INC.Inventors: Michael Chiviendacz, Steve Neville, Chris Voice, Michael Morgan
-
Patent number: 9281945Abstract: A method for providing authentication of a user of a recipient unit when the recipient unit is off-line includes storing one or a plurality of challenge-reply sets associated with an article based on an on-line communication with a sender unit. Each of the challenge-reply sets includes at least a challenge-reply pair for use in off-line authentication of the user for a particular resource available through the recipient unit. When the user is offline, the method includes selecting at least one of the plurality of stored challenge-reply sets for off-line authentication of the user for the particular resource available through the recipient unit.Type: GrantFiled: September 30, 2005Date of Patent: March 8, 2016Assignee: Entrust, Inc.Inventors: Chris Voice, Marc Smith, Murray McCulligh, Robert Zuccherato
-
Patent number: 9191215Abstract: A method and apparatus provides first or second factor authentication by providing selectability of a plurality of second factor authentication policies associated with a second factor authentication article. The first or second factor authentication article includes authentication information, such as a plurality of data elements in different cells or locations on the authentication article, which can be located by using corresponding location information. The method and apparatus provides second factor authentication based on the first or second factor authentication article by enforcing at least one of the plurality of selected authentication policies.Type: GrantFiled: December 12, 2005Date of Patent: November 17, 2015Assignee: Entrust, Inc.Inventors: Michael Chiviendacz, Steve Neville, Chris Voice, Michael Morgan
-
Patent number: 9100194Abstract: A method, apparatus and/or system generates a challenge for user authentication, having a challenge data element from a stored pool of challenge data elements. The challenge is based on rule data and stored usage data associated with at least some of the challenge data elements in the stored pool of challenge data elements. The generated challenge is sent for use in an authentication of a user to a sender. A method, apparatus and/or system also generates sender authentication and corresponding location information, having a data element from a stored pool of challenge data elements. Selection of the data elements is based on rule data and stored usage data associated with at least some of the data elements in the stored pool of data elements.Type: GrantFiled: November 26, 2012Date of Patent: August 4, 2015Assignee: Entrust Inc.Inventors: Serge Mister, Steve Neville, Robert J. Zuccherato, Christopher Voice, Michael Morgan
-
Patent number: 8966579Abstract: A method, apparatus and/or system generates a challenge for user authentication, having a challenge data element from a stored pool of challenge data elements. The challenge is based on rule data and stored usage data associated with at least some of the challenge data elements in the stored pool of challenge data elements. The generated challenge is sent for use in an authentication of a user to a sender. A method, apparatus and/or system also generates sender authentication and corresponding location information, having a data element from a stored pool of challenge data elements. Selection of the data elements is based on rule data and stored usage data associated with at least some of the data elements in the stored pool of data elements.Type: GrantFiled: December 12, 2005Date of Patent: February 24, 2015Assignee: Entrust, Inc.Inventors: Serge Mister, Steve Neville, Robert J. Zuccherato, Chris Voice, Michael Morgan