Patents Examined by Benjamin E. Lanier
  • Patent number: 7516332
    Abstract: This invention provides multi-key content processing systems and methods, for processing content with at least one distribution target position. Each of the distribution target positions corresponds to an authorization key. An example method includes the steps of: encrypting said content with a content key; forming a key link based on said content key and the authorization key of said at least one distribution target position; and attaching said key link to the encrypted content.
    Type: Grant
    Filed: March 17, 2005
    Date of Patent: April 7, 2009
    Assignee: International Business Machines Corporation
    Inventors: Jian Zhang, Ling Shao, Dong Xie
  • Patent number: 7467304
    Abstract: Some demonstrative embodiments of the invention include a method, device and/or system of selectively allowing a host processor to access a host-executable code. A host apparatus may include, for example, a host processor; and a protected memory module comprising: a memory to maintain a host-executable code to be executed by the host processor; and a memory controller to authenticate the host-executable code, and to selectively allow the host processor to access the host-executable code based on an authenticity of the host-executable code. Other embodiments are described and claimed.
    Type: Grant
    Filed: June 22, 2006
    Date of Patent: December 16, 2008
    Assignee: Discretix Technologies Ltd.
    Inventors: Hagai Bar-El, David Deitcher, David Voschina, Eran Rippel
  • Patent number: 7464409
    Abstract: A device for mitigating data flooding in a data communication network. The device can include a first module and a second module. The first module can identify flooding data transmitted from at least one offending host and intended for at least one threatened host. The second module can generate a data rate limit that is communicated to at least one of the plurality of edge nodes defining an entry node. The data rate limit can be based upon an observed rate of transmission of flooding data transmitted from the offending host to the entry node and a desired rate of transmission of flooding data transmitted to the threatened host from at least one other of the plurality of edge nodes defining an exit node.
    Type: Grant
    Filed: June 25, 2004
    Date of Patent: December 9, 2008
    Assignee: University of Florida Research Foundation, Inc.
    Inventor: Shigang Chen
  • Patent number: 7457411
    Abstract: A system and method providing secure information. An encryption key is regenerated by performing byte addition of an encryption key, encrypted data, and a hash vector based upon an encryption key. A hash vector is hashed by scanning indexed bytes of an encryption key and using indices and associated values of indices of an encryption key as indices of two bytes in the hash vector to be swapped. An authentication key is regenerated by performing byte addition of an authentication key, an auxiliary key, and a hash vector based upon an authentication key.
    Type: Grant
    Filed: December 12, 2003
    Date of Patent: November 25, 2008
    Assignee: New Mexico Technical Research Foundation
    Inventor: Hamdy Soliman
  • Patent number: 7458095
    Abstract: The invention is a method of connecting user equipment to at least one network, a communication system, and a user equipment. In a communication system comprising at least one network, including network entities which provide connectivity to user equipment, a method of connecting the user equipment to the at least one network in accordance with the invention includes establishing a secure tunnel which provides connection between the user equipment and one of the network entities; and authenticating the user equipment with another of the network entities; and wherein the authenticating of the user equipment with the another of the network entities occurs at least partially simultaneously with the establishing of the secure tunnel.
    Type: Grant
    Filed: November 18, 2003
    Date of Patent: November 25, 2008
    Assignee: Nokia Siemens Networks Oy
    Inventor: Dan Forsberg
  • Patent number: 7454794
    Abstract: An access control method executed by a computer system, including applying an access rate limit until a user issuing access requests is verified, a first control level involving verifying the user, a second control level applying hack program detection tests to the access requests and verifying the user, a third control level requiring use of predetermined download software for transmitting the access requests and verifying the user, a fourth control level blocking access to the service on the basis of at least one communications address corresponding to the access requests, and invoking the control levels sequentially depending on a number of failed attempts to verify the user.
    Type: Grant
    Filed: September 13, 2000
    Date of Patent: November 18, 2008
    Assignee: Telstra Corporation Limited
    Inventor: Timothy Winston Hibberd
  • Patent number: 7444676
    Abstract: A system and method for direct authentication and/or authorization of transactions. The system includes a trusted Digital Identity (DID) Network connecting an Originating Participating Financial Institution (OPFI) and a Receiving Participating Financial Institution (RPFI) through a DID Operator. The DID Operator may further be coupled to a DID System that calculates digital identities for Originators. According to the method, direct authentication of the Originator and/or authorization of the transaction is initiated upon the Originator communicating its digital identity to the Receiver. The Receiver subsequently provides the digital identity to the RPFI. The RPFI is then able to communicate with the OPFI for authentication of the Originator and/or authorization of the transaction through the DID Operator based on Originator's digital identity.
    Type: Grant
    Filed: September 30, 2005
    Date of Patent: October 28, 2008
    Inventors: Nader Asghari-Kamrani, Kamran Asghari-Kamrani
  • Patent number: 7441275
    Abstract: An apparatus and a corresponding method provide for real-time recovery of compromised information in a computer network. The method includes analyzing data objects in the computer network to determine data objects that comprise minimal essential information, collecting the minimal essential information, and storing the minimal essential information. To limit potential exposure of the minimal essential information, the stored minimal essential information is hidden in the computer network.
    Type: Grant
    Filed: May 14, 2003
    Date of Patent: October 21, 2008
    Assignee: Northrop Grumman Corporation
    Inventors: Dennis Hain McCallam, Ronald Kenneth Newland
  • Patent number: 7404205
    Abstract: A method for controlling connections from an IP entity to a server. Initially, a limit count, representing a number of concurrently allowable connections between the IP entity and the server, is determined. When an incoming IP packet is received, the packet is processed to determine the source and destination IP addresses for the packet. An entry is then created in a limit table for the IP entity, if no entry for that IP entity exists in the table. A determination is made as to whether a pending connection should be allowed for the packet, by referring to the limit count and the entry in the limit table. The connection is allowed, and the limit count for the entry is incremented, if the attempted connection would not exceed the limit count for the IP entity; otherwise, the packet is blocked if the attempted connection would exceed the limit count for the IP entity.
    Type: Grant
    Filed: June 3, 2003
    Date of Patent: July 22, 2008
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Eric C. Scoredos, Hrishikesh Talgery, David Hsing Lin
  • Patent number: 7401224
    Abstract: A hand-held token can be operated to generate an acoustic signal representing the digital signature generated by a private key of a public key/private key pair. Verifiers that might be located at, e.g., buildings, in vehicles, at bank ATMs, etc. receive the signal and retrieve the corresponding public key to selectively grant access authorization to components served by the verifiers. Methods and systems permit adding and removing a token from the access list of a verifier. Other methods and systems enable the token to be used with several verifiers that are nearby each other, such as might be the case with multiple vehicles owned by the same user and parked nearby each other, without more than one verifier being operated to grant access.
    Type: Grant
    Filed: June 13, 2002
    Date of Patent: July 15, 2008
    Assignee: Qualcomm Incorporated
    Inventors: Alexander Gantman, Gregory G. Rose
  • Patent number: 7392387
    Abstract: Authentication information is generated for a group where members within a group are able to communicate with each other, but a non-members is not able to participate in that communication. The authentication information provides the determination of whether the member belongs to the group.
    Type: Grant
    Filed: February 26, 2007
    Date of Patent: June 24, 2008
    Assignee: Xerox Corporation
    Inventors: Dirk Balfanz, Diana Smetters, Paul Stewart, Daniel C. Swinehart
  • Patent number: 7373516
    Abstract: Disclosed is a method of authorizing access to an item that maintains a lockout count and blocks access to the item if the lockout count exceeds a predetermined value. One feature is that the invention “variably” increments the lockout count if the presented password fails to exactly match the stored password. In this process the invention increments the lockout count different amounts depending upon how closely the presented password matches the stored password. The invention also provides a methodology that allocates a plurality of the same passwords to a plurality of users who share the same userid. The invention allows continuous operation of the item being accessed by providing that each of the passwords has a different expiration date. Also, when dealing with situations where a plurality of users who share the same userid also share the same password, the invention maps information associated with the users to the password in a data file and periodically updates the data file.
    Type: Grant
    Filed: August 19, 2004
    Date of Patent: May 13, 2008
    Assignee: International Business Machines Corporation
    Inventors: Guru S. Ashok, Raymond P. Dunki-Jacobs, Robert J. Milne, Rahul Nahar, Ashit M. Shah, Shreesh S. Tandel, Muthuswamy Venkatachalam
  • Patent number: 7370346
    Abstract: One embodiment disclosed relates to a method for a switch to respond to a new client. A new client is detected at a port of the switch. The switch temporarily assigns the port to be an untagged member of a virtual local area network (VLAN) which is configured for unauthorized clients. Initialization services are provided to the new client via the unauthorized-client VLAN. The new client may be authenticated by way of an authentication session using the unauthorized-client VLAN. If the new client is authenticated, then the untagged membership of the port in the unauthorized-client VLAN is dropped, and the port is assigned to be an untagged member of a specified VLAN.
    Type: Grant
    Filed: April 29, 2003
    Date of Patent: May 6, 2008
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventor: Paul T. Congdon
  • Patent number: 7367058
    Abstract: A method is described that provides efficient, secure web-based recognition services. More particularly, an embodiment of the method relates to confidential encoding by dissociating image information into individual word segments, or snippets, at a distribution point and distributing the snippets over a network to users who subscribe to provide their services. Users could include college students, housewives, or any individual with Internet access. The users view the snippets, enter equivalent ASCII information for the snippets, and send the ASCII information back over the network to the distribution point for reassembly.
    Type: Grant
    Filed: May 28, 2002
    Date of Patent: April 29, 2008
    Assignee: United States Postal Service
    Inventor: Alfred D. Lawson
  • Patent number: 7360252
    Abstract: Software is securely distributed with limited usage rights. The software may be an executable program and/or one or more data files such as image or multimedia data files. The software includes an access control object which prevents at least some usage of the software without the use of a first access control code. The first access control code is produced based on selected information characteristic of the user's computer system. The access control code is produced in a server computer to which the user directs a request for the access control code. The user makes a payment to receive the access control code, which is then downloaded to the user's computer system.
    Type: Grant
    Filed: March 9, 2000
    Date of Patent: April 15, 2008
    Assignee: Macrovision Corporation
    Inventor: Andres Torrubia-Saez
  • Patent number: 7353541
    Abstract: An information receiving apparatus receives identification information and encrypted identification information and makes a comparison between them to allow prevention of illegal utilization of contents data. Also, a data storage apparatus can record contents data encrypted by a content key and the content key so that the contents data can be reproduced on other apparatuses to improve versatility. Moreover, a management apparatus can manage the contents data in the data storage apparatus to allow other apparatuses to utilize it. And also, an information regulating apparatus can verify a signature on available data to prevent illegal utilization of the contents data. Furthermore, the data storage apparatus can store the content key, its handling policies, the contents data encrypted by the content key and its license conditions information so as to safely provide the contents data. In addition, an information recording apparatus can select favorite contents data and store it on the data storage apparatus.
    Type: Grant
    Filed: September 7, 2000
    Date of Patent: April 1, 2008
    Assignee: Sony Corporation
    Inventors: Yoshihito Ishibashi, Tateo Oishi, Akihiro Muto, Jun Kitahara, Taizou Shirai
  • Patent number: 7352863
    Abstract: Enhancements to a video anticopying process that causes an abnormally low amplitude video signal to be recorded on a illegal copy. The enhancement in one version include a negative going waveform that appears to the television receiver or videotape recorder to be a sync signal, thereby causing an early horizontal or vertical retrace. In another version, selected horizontal sync pulses are narrowed, causing irregular vertical retraces. In another version, post-pseudo sync pulses that have a minimum level above the minimum level of sync pulses are added to enhance anti-copy effectiveness. The post pseudo-sync pulses may be amplitude modulated.
    Type: Grant
    Filed: August 16, 2005
    Date of Patent: April 1, 2008
    Assignee: Macrovision Corporation
    Inventor: Ronald Quan
  • Patent number: 7353400
    Abstract: A CPU is provided with an ability to modify its operation, with respect to error correction, as a programmable feature. An error correction scheme is selected to be performed by the error correcting circuit. The compiled program may have intentionally introduced errors which are predictably corrected by the selected error correction scheme. When a program is compiled, the program is modified by the intentional insertion of errors which would result from the execution of the program. By providing error correction schema selected during program compilation, errors can be inserted in the program code, but are handled in a predictable manner by the error correction.
    Type: Grant
    Filed: August 18, 1999
    Date of Patent: April 1, 2008
    Assignee: Sun Microsystems, Inc.
    Inventor: Alan Folmsbee
  • Patent number: RE40334
    Abstract: A method and apparatus for the transmission and reception of scrambled data is disclosed. In some embodiments, the method and apparatus includes transmitting a scrambled data stream to a decoder, sending the scrambled data stream to a portable security module inserted in the decoder, descrambling the scrambled data stream, encrypting a descrambled data stream, and using the encrypted data stream to the decoder, decrypting the encrypted data stream, and using the decrypted data stream.
    Type: Grant
    Filed: January 13, 2006
    Date of Patent: May 20, 2008
    Assignee: Nagra Thomson Licensing
    Inventors: Michel Maillard, Christian Benardeau, Jean-Luc Dauvois
  • Patent number: RE40702
    Abstract: A method for protecting the video memory on a computer system from being illicitly copied. The invention decrypts a previously encrypted image and displays it on the video screen. During the time the image is displayed, the invention protects it from being copied by other running applications. This is accomplished in multithreaded operating systems by first issuing a multithreaded locking primitive to the video memory resource, and then inserting a pending video hardware request that will take precedence over any subsequent video memory access requests. The pending request serves the purpose of destroying the contents of video memory. The pending request is passive in that it does not execute unless a malicious program has removed the video memory lock.
    Type: Grant
    Filed: May 4, 2006
    Date of Patent: April 21, 2009
    Assignee: Visual Advances LLC
    Inventors: Carlos Pizano, Gregory Heileman