Patents Examined by Christopher Brown
  • Patent number: 9160732
    Abstract: A method of establishing a communication channel between a network client and a computer server over a network is described. The network client may be configured to communicate with the computer server over the network and to communicate with a token manager. The token manager may be configured with a parent digital certificate that is associated with the token manager. The token manager or network client generates a credential from the parent digital certificate, and transmits the credential to the computer server. The credential may be associated with the computer server. The network client may establish the communications channel with the computer server in accordance with an outcome of a determination of validity of the credential by, the computer server.
    Type: Grant
    Filed: October 31, 2013
    Date of Patent: October 13, 2015
    Assignee: SECUREKEY TECHNOLOGIES INC.
    Inventors: Troy Jacob Ronda, Pierre Antoine Roberge, Patrick Hans Engel, Rene McIver, Greg Wolfond, Andre Boysen
  • Patent number: 9160733
    Abstract: A system and method for providing key challenge validation is provided. In example embodiments, an initiation of a transaction is detected and a challenge comprising a string of characters is generated based on the detection. The string of characters includes transaction specific information indicating a detail of the transaction. The challenge is presented whereby the string of characters includes a challenge key. A response to the challenge is received that includes the challenge key. In various example embodiments, the transaction is validated based on an identification of the key challenge of the string of characters.
    Type: Grant
    Filed: January 13, 2014
    Date of Patent: October 13, 2015
    Assignee: eBay, Inc.
    Inventors: Grahame Andrew Jastrebski, Dhanurjay A. S. Patil
  • Patent number: 9154480
    Abstract: In conjunction with a registration mode of operation, a first cryptographic device in one embodiment sends challenges to a second cryptographic device comprising a symmetric-key cryptographic module or other key-based cryptographic module that utilizes one or more secret keys. The first cryptographic device receives from the second cryptographic device responses to respective ones of the challenges, and stores information characterizing the responses. In conjunction with an authentication mode of operation, the first cryptographic device sends a selected one of the challenges to the second cryptographic device, receives from the second cryptographic device a response to the selected challenge, and authenticates the second cryptographic device utilizing the response to the selected challenge and the stored information.
    Type: Grant
    Filed: December 12, 2012
    Date of Patent: October 6, 2015
    Assignee: EMC Corporation
    Inventor: Ari Juels
  • Patent number: 9148424
    Abstract: Systems and methods for account security are provided. In one example embodiment, a first login request including a username and a password is analyzed to identify a first internet protocol (IP) address and a first request time associated with the first login request. A login history comprising login request data for the server computer is analyzed to identify a plurality of usernames, wherein each username of the plurality of usernames is associated with a corresponding login request from the first IP address within a threshold time period of the first request time. In response to determining a login success ratio is below a threshold login success ratio and a number of unique usernames in the analyzed data is above the unique username threshold, the system automatically performs a security action.
    Type: Grant
    Filed: March 13, 2015
    Date of Patent: September 29, 2015
    Assignee: Snapchat, Inc.
    Inventor: Jinlin Yang
  • Patent number: 9146975
    Abstract: Various arrangements for managing access to unstructured data are presented. A plurality of access requests may be received from a plurality of remote computer systems to a plurality of business entities stored by a content management server. In response to receiving a request for access to a business entity of the plurality of business entities stored by a content management server from a remote computer system, an identifier request may be transmitted to the content management server. A response from the content management server may be received in response to the identifier request. A resource locator that comprises the identifier may be created. The resource locator may be transmitted to the remote computer system for use in accessing the business entity.
    Type: Grant
    Filed: April 26, 2012
    Date of Patent: September 29, 2015
    Assignee: Oracle International Corporation
    Inventors: Sreekanth Chintala, Rama Vijjapurapu, Todd Price, Nathan Angstadt, Hari Charan Ramachandra Rao
  • Patent number: 9141647
    Abstract: The embodiments include a method for providing security for a set of configuration files corresponding to a remote monitoring application. The method may include accessing a server configured to store the set of configuration files. The server is also configured to receive a connection request, over a network, from an agent having the remote monitoring application, generate an encryption key in response to receiving the connection request, transmit the encryption key, over the network, to the agent, encrypt the set of configuration files according to an encryption algorithm and the encryption key, and transmit the encrypted set of configuration files to the agent. According to one embodiment, the server may be accessed by performing one or more maintenance actions on the server.
    Type: Grant
    Filed: April 26, 2012
    Date of Patent: September 22, 2015
    Assignee: SAP SE
    Inventors: Fabrice Diaz, Luc Margaron
  • Patent number: 9141825
    Abstract: A system and method for controlling access to digital assets in an online media sharing system based on keywords are provided. In general, each digital asset is tagged with a number of keywords. The owner of the digital assets defines a guest list including a number of guests. For each guest, the owner defines permissions controlling the guest's access to the digital assets based on keywords. Thereafter, when a request to view the digital assets is received from a guest node associated with one of the guests, the digital assets that the guest is permitted to view are identified based on the permissions assigned to the guest and provided to the guest at the guest node.
    Type: Grant
    Filed: November 18, 2005
    Date of Patent: September 22, 2015
    Assignee: Qurio Holdings, Inc.
    Inventor: Hugh Svendsen
  • Patent number: 9137207
    Abstract: An object of the present invention is to more appropriately filter a packet from an external device. This object is achieved by: obtaining address information of the external device from the packet; judging whether or not the address information of the external device has been registered as filter information; extracting, when it is judged that the address information has not been registered, device discrimination information of the external device from the address information of the external device; judging whether or not address information having the same device discrimination information as the extracted device discrimination information has been registered as the filter information; and registering, when it is judged that the address information having the same device discrimination information has been registered, the address information of the external device as the filter information.
    Type: Grant
    Filed: September 13, 2012
    Date of Patent: September 15, 2015
    Assignee: CANON KABUSHIKI KAISHA
    Inventor: Masamichi Tanji
  • Patent number: 9135468
    Abstract: There is disclosed an image forming apparatus to which one or more programs can be added. The image forming apparatus includes a managing part configured to manage access authorization information set for each of groups into which the programs are categorized, a displaying part configured to display a setting screen in which access authorization setting information is set in correspondence with each of the programs, a changing part configured to change a range of access authorization granted to the programs according to access authorization change information, the access authorization change information including definitions of change information corresponding to the access authorization setting information set in the setting screen, and a determining part configured to determine whether the access authorization can be granted to the programs.
    Type: Grant
    Filed: April 15, 2009
    Date of Patent: September 15, 2015
    Assignee: RICOH COMPANY, LTD.
    Inventor: Mitsuo Ando
  • Patent number: 9124425
    Abstract: Systems, methods, and apparatuses are provided for ciphering error detection and recovery. A method may include using a first set of one or more cipher input parameters to decipher ciphered data ciphered using a second set of one or more cipher input parameters. The method may further include comparing a value of at least a portion of the deciphered data to an expected value. The method may additionally include determining an occurrence of a ciphering error when the value of the at least a portion of the deciphered data is not equal to the expected value. The method may also include initiating a ciphering resynchronization procedure in response to the determination that a ciphering error occurred so as to resynchronize at least one of the first set of cipher input parameters with at least one of the second set of cipher input parameters. Corresponding systems and apparatuses are also provided.
    Type: Grant
    Filed: June 30, 2009
    Date of Patent: September 1, 2015
    Assignee: Nokia Technologies Oy
    Inventor: Keiichi Kubota
  • Patent number: 9124417
    Abstract: An efficient encryption system for improving the computation speed of a garbled circuit is set forth. The garbled circuit includes a number of garbled Boolean gates having first and second garbled Boolean gate input wires. The system includes a first key ki on a first garbled gate input wire. A second key kj is also provided on a second garbled gate input wire. A programmable function is provided for combining the first key ki and the second key kj to obtain an encrypted output key. A method for expediting encryption and decryption of a garbled circuit having a number of encryptions for a garbled table of a garbled gate is also set forth. The method includes the steps of: forming the garbled table with a number of secret keys by applying a function to the secret keys to produce less than twice the number of secret keys as the number of encryptions for the garbled table, and evaluating the garbled table to decrypt an output key of the garbled table.
    Type: Grant
    Filed: March 5, 2010
    Date of Patent: September 1, 2015
    Assignee: Alcatel Lucent
    Inventor: Vladimir Y. Kolesnikov
  • Patent number: 9106679
    Abstract: A method and system for authenticating delivery including the steps of receiving by a receiver a delivery information package from a deliverer over a network during a communication between the receiver and the deliverer, wherein the delivery package includes deliverer identity information, sending an authentication request of the received delivery package from the receiver to an authentication module having a hardware processor, over at least one of a call network and an additional network, and authenticating the received delivery package using the deliverer identity information.
    Type: Grant
    Filed: December 19, 2011
    Date of Patent: August 11, 2015
    Assignee: TP Lab Inc.
    Inventors: Chi Fai Ho, Shin Cheung Simon Chiu
  • Patent number: 9100222
    Abstract: As individuals increasingly employ their wireless devices to engage in different types of activities they face a growing threat from, possibly among other things, identity theft, financial fraud, information misuse, etc. and the serious consequences or repercussions of same. Leveraging the ubiquitous nature of wireless devices and the popularity of (Short Message Service, Multimedia Message Service, etc.) messaging, an infrastructure that enhances the security of the different types of activities within which a wireless device user may participate through dynamically configurable levels of authentication. The infrastructure may optionally leverage the capabilities of a centrally-located Messaging Inter-Carrier Vendor.
    Type: Grant
    Filed: December 31, 2008
    Date of Patent: August 4, 2015
    Assignee: Sybase, Inc.
    Inventors: Dilip Sarmah, Zhang Jian, Yang Xu
  • Patent number: 9094209
    Abstract: A system and method for generating a limited use login credential associated with an account maintained by an institution, where the credential facilitates secure access to the account.
    Type: Grant
    Filed: October 5, 2010
    Date of Patent: July 28, 2015
    Assignee: Miri Systems, LLC
    Inventors: Ludwik F. Zon, Ronald W. Sandstrom
  • Patent number: 9081936
    Abstract: A system and method for tracking a downloaded digital media file which employs reheader splicing of the digit media file for digital rights management (DRM) are provided. The system and method provide for receiving a request for a first file from a client, accessing the first file and a second file that is representative of the first file, applying data identifying the client into the second file, and combining the first and second file such that a size of the combined file is substantially the same size as the accessed first file, and downloading the combined first and second file to the client. The combining of the first and second file includes replacing corresponding object components of the first file with the objects components of the second file. The data identifying the client includes at least one of a transaction ID, merchant ID, user ID and order ID.
    Type: Grant
    Filed: November 12, 2008
    Date of Patent: July 14, 2015
    Assignee: THOMSON LICENSING, LLC
    Inventors: Peter Tadeusz Matuchniak, Bryan Bledstein, Walterlance Ware
  • Patent number: 9077521
    Abstract: A system and method for secure communication is provided. Outgoing messages to another computing device are encrypted using a first shared key shared with said other computing device, and a first counter, said first shared key and said first counter being stored in storage of a computing device. Incoming messages from said other computing device are decrypted using said first shared key and a second counter stored in said storage of said computing device.
    Type: Grant
    Filed: February 16, 2011
    Date of Patent: July 7, 2015
    Assignee: IMS HEALTH INC.
    Inventor: Salah Machani
  • Patent number: 9071416
    Abstract: A system including a nonce module and an encryption module. The nonce module is configured to generate a nonce for each packet of a plurality of packets to be encrypted using a first temporal key. Each nonce includes a packet number that is different than packet numbers associated with other nonces generated by the nonce module for the plurality of packets. The packet number is greater than N bits in length, where N is an integer greater than 40. The encryption module is configured to encrypt, without reusing a value of the packet number, more than 2(N?1) packets of the plurality of packets using (i) the first temporal key and (ii) the nonces corresponding to the more than 2(N?1) packets using Galois/Counter Mode encryption.
    Type: Grant
    Filed: October 14, 2013
    Date of Patent: June 30, 2015
    Assignee: Marvell World Trade LTD.
    Inventors: Yong Liu, Paul A. Lambert, Raja Banerjea
  • Patent number: 9065632
    Abstract: A method for authenticating a message by a wireless device is described. The wireless device obtains the input message. The wireless device generates a keystream. The wireless device computes a message authentication code using the keystream and a universal hash function. The universal hash function is computed using carryless multiplication.
    Type: Grant
    Filed: February 20, 2013
    Date of Patent: June 23, 2015
    Assignee: QUALCOMM Incorporated
    Inventors: Billy B. Brumley, Alexander W. Dent
  • Patent number: 9060014
    Abstract: A system and method for monitoring, modeling and assessing networked devices. A continuous device profiling (CDP) system builds and maintains device-specific and network-specific behavioral models based on observation of network traffic. The behavioral models may be used for network management, detecting misconfigured or malware infected devices, performing network asset inventory, network access control, network discovery in support of network integration, and information security incident response management. CDP models and monitors the active roles that devices assume on the network based on a set of matching profiles, monitors transitions between roles, and triggers corrective action when role transitions violate the policies of the network.
    Type: Grant
    Filed: October 28, 2013
    Date of Patent: June 16, 2015
    Assignee: Observable Networks, Inc.
    Inventor: Patrick Crowley
  • Patent number: 9060038
    Abstract: Methods, systems, and computer-readable media for updating a domain name server are provided. A console may receive a first request to access the console. The console may verify first permission to access the console. The console may receive a second request to access the domain name server. The console may verify second permission to access the domain name server. The console may receive an instruction to modify an entry in the domain name server. The instruction may specify that a previous Internet Protocol address in the entry is replaced with a new Internet Protocol address. The console may transmit the instruction from the console to the domain name server. The domain name server may be configured to replace the previous Internet Protocol address with a new Internet Protocol address in the entry in response to the instruction.
    Type: Grant
    Filed: May 16, 2011
    Date of Patent: June 16, 2015
    Assignee: AT&T Intellectual Property I, L.P.
    Inventor: Norman Yale