Patents Examined by A. Nobahar
  • Patent number: 7613302
    Abstract: Systems, methods and modulated data signals are described herein that provide an efficient way to derive a single key from which a user can extract virtually any number of data encryption keys. A database is logically divided into segments and a small prime number is associated with each segment. An encryption key is derived for each segment in the database and a key set is determined for distributing a data subset to a user. Each segment is encrypted with the corresponding encryption key. A single key is derived using the prime numbers associated with the data segments and the single key, the encrypted database, and a small amount of public information is provided to the user. The user utilizes this information to extract the encryption key set from the single key. One implementation utilizes a tree structure to significantly reduce the number of modular exponentiations that must be calculated when extracting the encryption keys.
    Type: Grant
    Filed: December 17, 2004
    Date of Patent: November 3, 2009
    Assignee: Microsoft Corporation
    Inventor: Josh D. Benaloh
  • Patent number: 7401358
    Abstract: A method of controlling access to a control register of a microprocessor. The method of controlling access to a control register of a processor having a normal execution mode and a secure execution mode may include storing state and mode information in the control register, allowing a software invoked write access to modify the state and mode information within the control register during the normal execution mode and selectively inhibiting the software invoked write access during the secure execution mode.
    Type: Grant
    Filed: April 18, 2003
    Date of Patent: July 15, 2008
    Assignee: Advanced Micro Devices, Inc.
    Inventors: David S. Christie, Kevin J. McGrath
  • Patent number: 7386721
    Abstract: According to one aspect, a provisioning server comprises a configuration module that configures a network device and an identification certification module that certifies the identity of the network device. With use of the provisioning server, the network device does not require configuration with network connectivity in order to obtain its certified identity. In one embodiment, configuration module configures the device for operation at the device's point of deployment in a network. In one embodiment, the identity certification module is configured to generate a digital certificate for the network device and the configuration module is configured to automatically configure the network device based on its digital certificate. The provisioning server is coupled to the network device with a secure communication link. As a result, a more trusted network device is ultimately deployed into its network of operation.
    Type: Grant
    Filed: March 12, 2003
    Date of Patent: June 10, 2008
    Assignee: Cisco Technology, Inc.
    Inventors: Jan Vilhuber, Max Pritikin
  • Patent number: 7386879
    Abstract: In an interactive broadcast system signals transmitted by a service provider (30) are passed via a gateway (12) to a subscriber terminal (2). In order to gain access to services, the subscriber terminal (2) transmits an authorization request message via the gateway (12) to the RADIUS server (18). This RADIUS server (18) transmits in response to the authorization request message an authorization challenge message to the subscriber terminal (2). In return the subscriber terminal responds to the challenge message with a challenge response. This challenge response is checked by the RADIUS server (18) and if correct, the RADIUS server (18) transmits a message to the gateway to give the subscriber terminal access to the service.
    Type: Grant
    Filed: October 27, 1999
    Date of Patent: June 10, 2008
    Assignee: Koninklijke Philips Electronics N.V.
    Inventor: Engelbertus Van Willigen
  • Patent number: 7370362
    Abstract: Methods and apparatus are disclosed for locating and disabling the switch port of a rogue wireless access point. In one embodiment, a network management device is configured to detect the presence of a rogue access point on a managed wireless network. Once detected, the management device may then instruct a special client, such as a scanning AP, to associate with the rogue access point and send a discovery packet through the rogue access point to network management device. The network management device upon receiving the discovery packet may thereby determine that the rogue access point is connected to a network managed by said network device. The network device may then utilize information contained in the discovery packet to locate the switch port to which the rogue access point is connected, and ultimately disable the switch port to which the rogue access point is connected.
    Type: Grant
    Filed: March 3, 2005
    Date of Patent: May 6, 2008
    Assignee: Cisco Technology, Inc.
    Inventors: Timothy Olson, Pauline Shuen, Ajit Sanzgiri, Nancy Winget, Pejman Roshan
  • Patent number: 7346780
    Abstract: An implementation of a technology, described herein, for facilitating the protection computer-executable instructions, such as software. At least one implementation, described herein, may generate integrity signatures of multiple sets of computer-executable instructions based upon the output trace and/or an execution trace of such sets. With at least one implementation, described herein, a determination may be made about whether two or more of such sets are unaltered duplicates by comparing integrity signatures of such sets. This abstract itself is not intended to limit the scope of this patent. The scope of the present invention is pointed out in the appending claims.
    Type: Grant
    Filed: April 3, 2002
    Date of Patent: March 18, 2008
    Assignee: Microsoft Corporation
    Inventors: Saurabh Sinha, Mariusz H. Jakubowski, Ramarathnam Venkatesan, Yuqun Chen, Matthew Cary, Ruoming Pang
  • Patent number: 7290141
    Abstract: A method and system for authenticating messages received from users across multiple remote devices are provided. A residential gateway authenticates a user using a modified digest authentication scheme by storing a sequence number in the nonce field. Access encryption keys and sequence number spaces may be assigned based on user or on user/remote device pairs. When sequence number spaces are assigned based on user, and the user uses multiple remote devices to access the residential gateway, the sequence number space may be divided into mini-sequence number spaces for each of the multiple remote devices. Access encryption may be two-tiered, such that a secondary key is generated based on a user's primary key, and the secondary key is only valid for a limited amount of time before it expires and a new secondary key must be generated.
    Type: Grant
    Filed: June 27, 2002
    Date of Patent: October 30, 2007
    Assignee: Nokia, Inc.
    Inventors: Senthil Sengodan, Tat Chan
  • Patent number: 7269745
    Abstract: Methods and apparatus for producing an electronic ID number include modifying at least one physical bit element from among each of at least first and second groups of physical bit elements, each physical bit element of each group having a first physical state in which it is operable to produce a signal having a first electrical state, and being capable of permanent modification to a second physical state in which it is operable to produce a signal having a second electrical state; and producing (i) one bit of an identification (ID) number from the respective signals issuing from each of the respective at least first and second groups of physical bit elements, and (ii) a validity signal indicative of whether the one bit of the ID number is valid.
    Type: Grant
    Filed: September 18, 2002
    Date of Patent: September 11, 2007
    Assignee: Sony Computer Entertainment Inc.
    Inventor: Hidetaka Magoshi
  • Patent number: 7237125
    Abstract: A system and method for securely distributing content by automatically deploying security components. The system includes a server having content stored thereon, a client device having a standard application program for accomplishing a task related to the content, and a rights management module operatively coupled to the server and said client device and configured, upon a request to access the content, to determine if security components are coupled to the application program. The rights management module downloads and installs the security components on the client device if the security components are not coupled to the application program.
    Type: Grant
    Filed: April 30, 2003
    Date of Patent: June 26, 2007
    Assignee: Contentguard Holdings, Inc.
    Inventors: Michael Raley, Daniel Chen, Hsi-Cheng Wu, Thanh Ta
  • Patent number: 7234169
    Abstract: One or more embodiments of the invention provide a method, apparatus, system, and article of manufacture for monitoring components of a digital cinema system. A digital cinema system utilizes an exhibitor system (that has one or more components) to display media content. A configuration of the exhibitor system is stored in the exhibitor system. The integrity of the configuration is then determined by querying each of the components. Software agents on each of the components respond to the query. Based on the configuration and the responses received, the integrity of the exhibitor system is determined.
    Type: Grant
    Filed: July 8, 2002
    Date of Patent: June 19, 2007
    Assignee: The Boeing Company
    Inventors: Joseph S. Ng, Ismael Rodriguez, Antonie C. Smith
  • Patent number: 7228569
    Abstract: A programmable unit is described. The programmable unit has a memory device and a read protection device by which it is possible to prevent data from being read from the memory device. The described programmable unit is distinguished in that the read protection device prevents data from being read from the memory device only when a locking tag is set, and in that the programmable unit sets or does not set the locking tag automatically as a function of the operating mode that the programmable unit is in.
    Type: Grant
    Filed: May 29, 2002
    Date of Patent: June 5, 2007
    Assignee: Infineon Technologies AG
    Inventor: Jens Barrenscheen
  • Patent number: 7219224
    Abstract: An apparatus and method for sending and receiving fragmented Audio/Video Control packets using a communication software layer that is separate from a processing software layer. The method and apparatus may be used in a system for transferring copy protected digital audio/video signals between devices. In one embodiment of the present invention, a connection is established between a source and a sink device. Next, a communication layer of code on the source device receives at least one packet of data from the sink device. Next, the communication software on the source sends to the sink a response for each of the packets of data. Next, this embodiment of the source communication software sends all the packets as one group to a processing layer of code on the source device.
    Type: Grant
    Filed: June 16, 2000
    Date of Patent: May 15, 2007
    Assignees: Sony Corporation, Sony Electronics, Inc.
    Inventor: Jadie Soo Sun
  • Patent number: 7216227
    Abstract: A system and method for controlling the use of addresses by using address computation techniques is described. A system comprising alias address creation software generates multiple alias addresses representing a single real address of a particular recipient. Each alias address is computed from data representing a prospective sender and a recipient. A sender is provided with an alias address by a recipient for communicating back to said recipient. Messages sent by a sender, employing alias addresses are analysed to a forwarding server which validates each alias address and checks it against a blocking list. Messages which pass these checks are directed to the recipient's real address registered with said forwarding server.
    Type: Grant
    Filed: March 13, 2003
    Date of Patent: May 8, 2007
    Inventor: Amiram Grynberg
  • Patent number: 7209561
    Abstract: A method for generating a seed value for use in symmetric encryption includes creating and storing a first data set and generating a hashed value based on the first data set. A replacement position in the first data set is selected, and at least a portion of the hashed value is written into the first data set at the replacement position. A seed portion of the first data set is selected as the seed value. By varying a number of iterations, a balance can be struck between performance (fewer iterations) and security (more iterations).
    Type: Grant
    Filed: September 20, 2002
    Date of Patent: April 24, 2007
    Assignee: Cybersource Corporation
    Inventors: Vishnu Shankar, Jason Eaton
  • Patent number: 7203963
    Abstract: A method of adaptively classifying information using a binary tree comprises establishing a binary tree including a set of binary sequences each representing one or more network addresses. Once network traffic is received having identifiers describing network traffic sources, the identifiers are correlated to binary sequences within the binary tree. A revision metric is formed based on this correlating, and the binary tree is then revised according to this revision metric. A method of blocking a DDOS attack comprises establishing a binary tree including a set of binary sequences, each of these binary sequences representing one or more network addresses. When network traffic is received having identifiers describing network traffic sources, the identifiers are correlated to binary sequences within the binary tree. Once a DDOS attack notification signal is received, a selected binary tree path within the binary tree is identified as a low cost blocking path within the binary tree.
    Type: Grant
    Filed: June 13, 2002
    Date of Patent: April 10, 2007
    Assignee: McAfee, Inc.
    Inventors: Shyhtsun Felix Wu, Aiguo Fei, Fengmin Gong
  • Patent number: 7203967
    Abstract: Methods and apparatus for content protection in a wireless network. A method is provided for operating a protection system to protect an application from unauthorized distribution, wherein the application will fail to operate on a device that is outside a predetermined operating region. The method includes associating a geographic identifier with the application, wherein the geographic identifier identifies the predetermined operating region, and downloading the application and the geographic identifier to the device. The method also includes receiving a request to execute the application on the device, wherein the request includes the geographic identifier, and determining a device location. The method also includes comparing the device location with the predetermined operating region identified by the geographic identifier, and preventing the application from executing when the device is outside the predetermined operating region.
    Type: Grant
    Filed: September 10, 2003
    Date of Patent: April 10, 2007
    Assignee: Qualcomm Incorporated
    Inventors: Mazen Chmaytelli, Laurence Lundblade
  • Patent number: 7185199
    Abstract: Authentication information is generated for a group where members within a group are able to communicate with each other, but a non-members is not able to participate in that communication. The authentication information provides the determination of whether the member belongs to the group.
    Type: Grant
    Filed: August 30, 2002
    Date of Patent: February 27, 2007
    Assignee: Xerox Corporation
    Inventors: Dirk Balfanz, Diana K. Smetters, Paul S. Stewart, Daniel C. Swinehart
  • Patent number: 7143282
    Abstract: In a gateway device for carrying out a data relaying at a transport or upper layer between a first terminal device and a second terminal device which are capable of carrying out communications through networks, information regarding a security association set up between the first terminal device and the second terminal device in order to carry out communications with guaranteed data secrecy or in order to carry out communications with guaranteed data authenticity managed, and the decryption/encryption processing or the authentication processing is carried out according to the managed information regarding the security association along with the data relaying at the transport or upper layer.
    Type: Grant
    Filed: May 23, 2001
    Date of Patent: November 28, 2006
    Assignee: Kabushiki Kaisha Toshiba
    Inventors: Masahiro Takagi, Masahiro Ishiyama
  • Patent number: 7140037
    Abstract: A signal (801) of a first code string made through replacing a part of a code string of a predetermined format with dummy data is sent to code string rewriting means (1802) via code string resolution means (1801). A signal (806) of a second code string for complementing the dummy data part in the signal (801) is sent to the code string rewriting means (1802) via control means (1805) and the dummy data in the first code string is rewritten to the second code string. At the time of trial viewing/listening, a signal (802) from the code string resolution means (1801) is selected by a switch (1808), and when the second code string (806) is acquired through content purchase, a signal (803) from the code string rewriting means (1802) is selected by the switch (1808). Thus, trial viewing/listening of a content such as music is made possible while the possibility of decryption is eliminated. By acquiring a relatively small quantity of data, reproduction of a high-quality content is made possible.
    Type: Grant
    Filed: February 8, 2002
    Date of Patent: November 21, 2006
    Assignee: Sony Corporation
    Inventors: Kyoya Tsutsui, Tadao Yoshida, Kenzo Akagiri, Naoya Haneda
  • Patent number: 7131138
    Abstract: Information communication terminals for transmitting/receiving information that includes a plurality of elements are connected to each other via a network. A information communication terminal at a transmitting side sets security-coupling levels to a plurality of elements, sets a dividing rule for dividing the information into a plurality of pieces of loosely coupled information based on the set security-coupling levels, divides the information into a plurality of pieces of loosely coupled XML data based on the set dividing rule, and transmits the divided plurality of pieces of loosely coupled XML data and the set dividing rule.
    Type: Grant
    Filed: November 19, 2001
    Date of Patent: October 31, 2006
    Assignee: Yumirlink, Inc.
    Inventor: Minoru Ikeda