Patents Examined by Christopher J. Brown
  • Patent number: 8627410
    Abstract: A system includes a remote authentication dial in user service (RADIUS) server in communication with a network access server. The network access server provides an authentication request to the RADIUS server. The authentication request includes at least a user identifier and a device identifier. The RADIUS server determines an authentication format utilized by the network access server based on the received authentication request. The system may also determine an authorization level to provide with an authentication response.
    Type: Grant
    Filed: December 19, 2007
    Date of Patent: January 7, 2014
    Assignee: Verizon Patent and Licensing Inc.
    Inventors: Jeffrey W. Hughes, Andrew L. Bates, Jared M. Allison
  • Patent number: 8266446
    Abstract: A method for protecting information in a device includes providing a device with a non-secure hardware domain, a processor having a software-controlled mode of operation, and a secure hardware domain having a secure memory that is inaccessible by the processor when the processor is operating in the software-controlled mode of operation. Data from the non-secure hardware domain is established in the secure hardware domain. Computing operations are executed on the data in the secure hardware domain to produce a result. The secure hardware domain is purged, while retaining the result therein. The result is thereafter returned from the secure hardware domain into the non-secure hardware domain.
    Type: Grant
    Filed: October 17, 2008
    Date of Patent: September 11, 2012
    Assignee: SanDisk IL Ltd.
    Inventors: Boris Dolgunov, Arseniy Aharonov, Raphael Slepon Ben-Yaish
  • Patent number: 7362973
    Abstract: A method for protecting a data entry device from eavesdropping includes masking a signature of entry resulting from entry of data by a user of the data entry device so as to reduce the detectability of the signature by eavesdropping. The signature may include a temperature differential in the data entry device from data entry by the user and the masking may include controlling the external temperature of the data entry device to reduce temperature differentials left in the data entry device by the user. Alternatively, the signature may include sound waves emitted from the data entry device and the masking may include masking sound waves emitted from the data entry device to reduce the detectability of the sound waves. A system may also be employed for protecting data entry to a data entry device from eavesdropping.
    Type: Grant
    Filed: September 15, 1999
    Date of Patent: April 22, 2008
    Assignee: International Business Machines Corporation
    Inventors: Bruce Dickson, David Louis Kaminsky, Marcia Lambert Peters
  • Patent number: 7360075
    Abstract: The invention provides a method and apparatus for transmitting data securely using an unreliable communication protocol, such as User Datagram Protocol. In one variation, the invention retains compatibility with conventional Secure Sockets Layer (SSL) and SOCKS protocols, such that secure UDP datagrams can be transmitted between a proxy server and a client computer in a manner analogous to conventional SOCKS processing. In contrast to conventional SSL processing, which relies on a guaranteed delivery service such as TCP and encrypts successive data records with reference to a previously-transmitted data record, encryption is performed using a nonce that is embedded in each transmitted data record. This nonce acts both as an initialization vector for encryption/decryption of the record, and as a unique identifier to authenticate the record.
    Type: Grant
    Filed: February 13, 2001
    Date of Patent: April 15, 2008
    Assignee: Aventail Corporation, a wholly owned subsidiary of SonicWALL, Inc.
    Inventors: Marc D. VanHeyningen, Rodger D. Erickson
  • Patent number: 7281133
    Abstract: Documents and other items can be delivered electronically from sender to recipient with a level of trustedness approaching or exceeding that provided by a personal document courier. A trusted electronic go-between can validate, witness and/or archive transactions while, in some cases, actively participating in or directing the transaction. Printed or imaged documents can be marked using handwritten signature images, seal images, electronic fingerprinting, watermarking, and/or steganography. Electronic commercial transactions and transmissions take place in a reliable, “trusted” virtual distribution environment that provides significant efficiency and cost savings benefits to users in addition to providing an extremely high degree of confidence and trustedness. The systems and techniques have many uses including but not limited to secure document delivery, execution of legal documents, and electronic data interchange (EDI).
    Type: Grant
    Filed: April 7, 2005
    Date of Patent: October 9, 2007
    Assignee: Intertrust Technologies Corp.
    Inventors: Karl L. Ginter, Victor H. Shear, Francis J. Spahn, David M. Van Wie, Robert P. Weber
  • Patent number: 7257836
    Abstract: A method for setting up and managing secure data/audio/video links with secure key exchanges, authentication and authorization is described. An embodiment of the invention enables establishment of a secure link with limited privileges using the machine identifier of a trusted machine. This is particularly useful if the user of the machine does not have a user identifying information suitable for authentication. Furthermore, the presentation of a default user identifying information by a user advantageously initiates intervention by a system administrator instead of a blanket denial. This decentralized procedure allows new users access to the network without having to physically access a centralized facility to present their credentials. Another embodiment of the invention enables a remote user to connect to a secure network with limited privileges.
    Type: Grant
    Filed: October 23, 2000
    Date of Patent: August 14, 2007
    Assignee: Microsoft Corporation
    Inventors: Timothy M. Moore, Arun Ayyagari, Sachin C. Sheth, Pradeep Bahl
  • Patent number: 7251326
    Abstract: A method and apparatus for use in encrypting and decrypting digital communications converting an initial block to final block based on freely selectable control information and secret key information having double the length of prior art keys and maintaining compatibility with the prior art encryption system.
    Type: Grant
    Filed: June 29, 2001
    Date of Patent: July 31, 2007
    Assignee: Harris Corporation
    Inventor: Michael Thomas Kurdziel
  • Patent number: 7248693
    Abstract: An Internet-based printing system allows for the distribution and printing of documents and images in a secure, controlled manner. The system includes a secure printer that receives, decrypts and prints documents supplied by a document server. Security of the system is realized by an aggregate of a secure communication protocol, smart card technology and the computational infeasibility of breaking a public key cryptographic system. The system may be used for electronic commerce, in which copies are made on a “pay-per-print” basis.
    Type: Grant
    Filed: January 13, 2000
    Date of Patent: July 24, 2007
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Daniel R. Tretter, Thomas D. Kite, Qian Lin, Hugh P. Nguyen, Ping Wah Wong
  • Patent number: 7243242
    Abstract: A cellular phone in the form of a shell downloads and reproduces encrypted content data distributed from a distribution server. The cellular phone includes a detection unit detecting whether its casing in the form of the shell is open/closed. If with the cellular phone currently downloading or reproducing encrypted content data its casing in the form of the shell is closed, a controller controls a power supply unit to supply power required for completing the download process or the reproduction process. Thus if the casing is closed the cellular phone still can complete the download or reproduction process. Thus with the casing having been closed the cellular phone can download or reproduce data.
    Type: Grant
    Filed: August 20, 2001
    Date of Patent: July 10, 2007
    Assignee: Sanyon Electric Co., Ltd.
    Inventor: Shinsuke Moriai
  • Patent number: 7200233
    Abstract: A system for fast data encryption/decryption is provided. The system includes a transmitter system having a transmitter direct digital synthesizer (DDS). The DDS includes at least three transmitter pseudo-noise (PN) component code generators PNx, PNy, PNz, where each transmitter PN component code generator is adapted to generate relatively prime transmitter PN component codes when compared with each of the other transmitter PN component code generators. The transmitter also includes a first processor coupled to the transmitter DDS, where the first processor is adapted to determine a time slot number (TSN) relative to at least two of the relatively prime transmitter PN component codes. Also included in the transmitter is an encryptor for encrypting clear data in accordance with the TSN. The system includes a receiver system having a second processor adapted to determine the TSN; and a decryptor coupled to the second processor.
    Type: Grant
    Filed: December 10, 2002
    Date of Patent: April 3, 2007
    Assignee: L-3 Communications Corporation
    Inventors: Merle L. Keller, Vaughn L. Mower, Steve J. McEntire, Victor D. Albertini
  • Patent number: 7197644
    Abstract: A secure document processing system for receiving an original document and for printing a secure hardcopy version of the original document, wherein the secure hardcopy version includes a machine-readable encoded image signature which represents an image segment of the original document. Such hardcopy secure documents can be validated by inputting them to an secure document validation system operable to identify and process the machine readable encoded representation and in response to determine whether the recovered image signature indicates that the document is counterfeit or has been altered.
    Type: Grant
    Filed: December 16, 2002
    Date of Patent: March 27, 2007
    Assignee: Xerox Corporation
    Inventor: Grace T. Brewington
  • Patent number: 7152243
    Abstract: A trusted component on a device includes a secure HWID therein and is verified by obtaining a key from the device, and verifying each signed component of the operating system of the device therewith. A driver table is examined to locate a HWID driver which is verified as containing a pointer back to an address inside a kernel. The verified operating system is called to obtain the secure HWID from a HWID component by way of the HWID driver and to return same to the trusted component. Thereafter, the returned HWID is verified as matching the HWID included with the trusted component.
    Type: Grant
    Filed: June 27, 2002
    Date of Patent: December 19, 2006
    Assignee: Microsoft Corporation
    Inventors: Steven Bourne, Vinay Krishnaswamy, Michael P. Calligaro, Randal Ramig, David Brian Wecker
  • Patent number: 7150042
    Abstract: The present invention relates to a proxy device, computer program product and method for performing malware scanning of files stored within a file storage device of a computer network. The computer network has a plurality of client devices arranged to issue access requests using a dedicated file access protocol to the file storage device in order to access files stored on the file storage device, with the proxy device being arranged so as to intercept access requests issued to the file storage device. The proxy device comprises a first interface for receiving an access request issued by one of the client devices to the file storage device using the dedicated file access protocol, and a second interface for communicating with the file storage device to cause the file storage device to process the access request. Further, processing logic is provided for causing selected malware scanning algorithms to be executed to determine whether the file identified by the access request is to be considered as malware.
    Type: Grant
    Filed: December 6, 2001
    Date of Patent: December 12, 2006
    Assignee: McAfee, Inc.
    Inventors: Daniel Joseph Wolff, Joel Robert Spurlock, Jonathan Lewis Edwards
  • Patent number: 7139918
    Abstract: A method and system to allow multiple users of a client computer to establish a secure connection for each of the multiple users between the client computer and a server computer. Each user is allowed to unlock a keyfile unique to that user. The unique keyfile is able to authenticate the user's identity to the server computer. Access to the users unique keyfile is accomplished by the user inputting into the client computer a unique user password for the user's unique keyfile. A Graphical User Interface (GUI) is provided to allow the user to input the unique user password for that user's unique keyfile. Upon input of the password, the selected keyfile is opened to enable a user authentication process to authenticate the user's identity to the server computer, thus creating an authenticated secure connection between the server computer and the client computer for the specific user.
    Type: Grant
    Filed: January 31, 2002
    Date of Patent: November 21, 2006
    Assignee: International Business Machines Corporation
    Inventors: David Yu Chang, Robert Howard High, Jr.
  • Patent number: 7124294
    Abstract: In order to limit users who can check for validity of a certificate in a system which uses public key certificates, a validity check permit permitting a request to check for validity of the certificate is issued by a permit issuing server 120 to the applicant of the certificate. The certificate applicant sends the validity check permit to a relevant user when the certificate is used (step 701). When having a certificate validity checking server check for validity of the certificate, the user sends the validity check permit of the certificate to be checked to the certificate validity checking server (step 704). The certificate validity checking server verifies the validity check permit (step 706).
    Type: Grant
    Filed: January 31, 2002
    Date of Patent: October 17, 2006
    Assignee: Hitachi, Ltd.
    Inventors: Shunji Kawamura, Taminori Tomita
  • Patent number: 7096357
    Abstract: A cryptographic communication terminal serving as one of information transmitting and receiving terminals in cryptographic communication includes a cryptographic algorithm storage section for storing one or more types of cryptographic algorithm used for cryptographic communication, and outputting a designated cryptographic algorithm, a key information storage section for storing a key used for cryptographic communication corresponding to the cryptographic algorithm, and outputting a designated key, a control section for designating, with respect to the cryptographic algorithm storage section and the key information storage section, which cryptographic algorithm and key are to be used in the cryptographic communication, and an encryption/decryption section for decrypting received encryption information by using the cryptographic algorithm designated with respect to the cryptographic algorithm storage section and the key designated with respect to the key information storage section, and encrypting information
    Type: Grant
    Filed: March 3, 2000
    Date of Patent: August 22, 2006
    Assignee: Kabushiki Kaisha Toshiba
    Inventors: Kouya Tochikubo, Naoki Endoh
  • Patent number: 7076653
    Abstract: A system and method for establishing a secure connection with an entity protected by an access control mechanism. A trusted arbitrator is used as an intermediary between a computer network employing the access control mechanism and external entities seeking to communicate securely with an entity inside the computer network. Connection requests for establishing a secure connection from an external entity are routed to the trusted arbitrator, which interacts with both the external entity and entities within the computer network. A secure connection is established between the external entity and the trusted arbitrator. Another secure connection is established between the entities within the computer network and the trusted arbitrator. The trusted arbitrator decrypts and encrypts from one connection to another, allowing the external entity to communicate securely with the computer network.
    Type: Grant
    Filed: June 27, 2000
    Date of Patent: July 11, 2006
    Assignee: Intel Corporation
    Inventors: Eric B. Remer, David A. King, David L. Remer
  • Patent number: 7069593
    Abstract: The present invention relates to an integrated circuit device containing a memory area, which comprises, on the one hand, a data memory and a program memory, and on the other hand, a program having N code blocks Bi (i=1, . . . , N). It also relates to a method for making such a device secure. The present invention is characterized in that the memory area has M replicas Cj (j=1, . . . , M) of x program code blocks Bi (x=1, . . . , N), which replicas reside at different addresses in said memory area, and in that said device has selection means for randomly selecting one replica Cj of at least one of the x blocks Bi, as a block replica to be used when executing said program. In particular, the present invention can be applied to smart cards.
    Type: Grant
    Filed: October 28, 1999
    Date of Patent: June 27, 2006
    Assignee: Axalto S.A.
    Inventor: Eric Gerbault
  • Patent number: 7013389
    Abstract: An approach for establishing secure multicast communication among multiple event service nodes is disclosed. The event service nodes, which can be distributed throughout an enterprise domain, are organized in a logical tree that mimics the logical tree arrangement of domains in a directory server system. The attributes of the event service nodes include the group session key and the private keys of the event service nodes that are members of the multicast or broadcast groups. The private keys provide unique identification values for the event service nodes, thereby facilitating distribution of such keys. Because keys as well as key version information are housed in the directory, multicast security can readily be achieved over any number of network domains across the entire enterprise. Key information is stored in, and the logical tree is supported by, a directory service. Replication of the directory accomplishes distribution of keys.
    Type: Grant
    Filed: September 29, 1999
    Date of Patent: March 14, 2006
    Assignee: Cisco Technology, Inc.
    Inventors: Sunil K. Srivastava, Jonathan Trostle, Raymond Bell, Ramprasad Golla
  • Patent number: 7008456
    Abstract: A technique for prohibiting access to a computer having a security function when a security device is illegally removed from the computer. The security device is a hardware component that constitutes a part of a security function for a computer. When the security device is illegally removed from the computer, access to the computer is prohibited. Data indicating that the security device is attached to the computer are stored in a nonvolatile memory. Then, when a specific event, such as a power-ON event, is used as a trigger, the procedure for prohibiting the access to the computer is initiated. Following this, based on the data stored in the memory, it is detected that the security device was once attached to the computer and that it has now been removed. If currently the security device is not attached to the computer, although it was attached before, the access to the computer is prohibited.
    Type: Grant
    Filed: January 20, 2000
    Date of Patent: March 7, 2006
    Assignee: International Business Machines Corporation
    Inventors: Jun Tanaka, Masahiko Nomura, Hideto Horikoshi, Hideyuki Usui, Seita Horikoshi, Fumio Tamura