Patents Examined by Gilberto Barron
  • Patent number: 8918653
    Abstract: Protection of interpreted programming language code filesystem files from access and alteration may be provided by encrypting a file to be protected in a boot sequence. Run-time examination of a virtual appliance may be deterred by hiding the boot sequence in a restricted virtual appliance platform. No shell or filesystem access may be provided. Thus, permissions on a read-only filesystem (for example) may be kept from being altered. The permissions may be set along with filesystem access control lists to prevent unauthorized examination of the source files.
    Type: Grant
    Filed: August 10, 2012
    Date of Patent: December 23, 2014
    Assignee: International Business Machines Corporation
    Inventor: John I. Buswell
  • Patent number: 8902980
    Abstract: Provided are an apparatus and a method for encoding a high fidelity video, and an apparatus and a method for decoding a high fidelity video.
    Type: Grant
    Filed: September 19, 2008
    Date of Patent: December 2, 2014
    Assignee: Korea Electronics Technology Institute
    Inventors: Yong Hwan Kim, Joo Young Yi, Byeong Ho Choi, Je Woo Kim, Joon Ki Paik
  • Patent number: 8893301
    Abstract: A system includes one or more processors and computer-readable storage media storing instructions executable by a processor to storing a digital good in a cloud data store that is accessible by a user devices associated with a first user and a second user through their respective accounts. When a request to transfer the access rights to the digital good from the account of the first user to the account of a second user, the transfer of the access rights to the digital good is authorized based on satisfaction of one or more business rules and the access rights are transferred from the account of the first user to the account of the second user while said digital good remains in said cloud data store. The access rights are deleted from the account of the first user.
    Type: Grant
    Filed: January 13, 2014
    Date of Patent: November 18, 2014
    Assignee: JRC Holdings, LLC
    Inventors: Jack Bertram Coronel, Joseph R Coronel
  • Patent number: 8751826
    Abstract: Methods and systems for maintaining the confidentiality of data provided by an organization for storage on a third party database system are provided. The data can be encrypted on an internal network of the organization and sent to the third party database system for storage. The third party database system can associate metadata with the encrypted data and can store the encrypted data. Accordingly, when a request for the encrypted data is received from a computing device communicating with an internal network of the organization, the encrypted data and associated metadata can be sent to the computing device. A key that is stored on an internal network of the organization can be called through an applet, which utilizes information within the metadata to locate the key on the internal network of the organization.
    Type: Grant
    Filed: March 30, 2010
    Date of Patent: June 10, 2014
    Assignee: salesforce.com, inc.
    Inventors: Brendan T. O'Connor, James L. Cavalieri, III, Robert C. Fly
  • Patent number: 8752175
    Abstract: The current invention discloses a method and apparatus to detect and mitigate network intrusion by collecting a first log of wireless network traffic in the vicinity of an area and a second log of network traffic from a switch port connected to the area; pre-processing the logs; and then detecting the presence of unauthorized access points (APs) by attempting to identify matching patterns in the pre-processed first and second logs.
    Type: Grant
    Filed: October 31, 2008
    Date of Patent: June 10, 2014
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventor: Richard H. Porter
  • Patent number: 8739266
    Abstract: A universal authentication token is configured to securely acquire security credentials from other authentication tokens and/or devices. In this manner, a single universal authentication token can store the authentication credentials required to access a variety of resources, services and applications for a user. The universal authentication token includes a user interface, memory for storing a plurality of authentication records for a user, and a secure processor. The secure processor provides the required cryptographic operations to encrypt, decrypt, and/or authenticate data that is sent or received by universal token. For example, secure processor may be used to generate authentication data from seed information stored in memory.
    Type: Grant
    Filed: October 28, 2013
    Date of Patent: May 27, 2014
    Assignee: Broadcom Corporation
    Inventor: Mark Buer
  • Patent number: 8739263
    Abstract: A communication apparatus includes a first communication unit that performs a wireless communication with two storage media that store therein association information for establishing a wireless connection and user identification information for identifying a user, respectively, and receives the association information and the user identification from the two storage media; a determination unit that performs user authentication based on the user identification information, determines whether or not to validate the association information based on the user authentication, and if the association information is determined to be valid, sets the association information; and a second communication unit that establishes a wireless connection based on the association information set by the determination unit.
    Type: Grant
    Filed: March 15, 2011
    Date of Patent: May 27, 2014
    Assignee: Ricoh Company, Ltd.
    Inventor: Yoshikazu Azuma
  • Patent number: 7606364
    Abstract: A cipher engine performs cipher processing (encrypting/decrypting) on logical data streams in a physical data stream in a storage device. As the physical data stream changes from a first logical data stream to a second logical data stream, and the cipher engine switches from cipher processing the first logical data stream to the second logical data stream, cipher information of the first logical data stream is stored in a cipher state memory, cipher information of the second logical data stream is retrieved from the cipher state memory, and the cipher engine resumes cipher processing the second logical data stream using the cipher information of the second logical data stream. Advantageously, a virtually unlimited number of logical data streams is supported and duplicate cipher hardware is avoided.
    Type: Grant
    Filed: April 23, 2002
    Date of Patent: October 20, 2009
    Assignee: Seagate Technology LLC
    Inventor: Yin Shih
  • Patent number: 7426636
    Abstract: A compact secure data communication method is disclosed. In one embodiment, a compact security protocol provides cryptographic services on IP, UDP, and TCP packets with minimal bandwidth degradation due to encapsulation overhead. The disclosed protocol may be used, for example, in converged networks that carry both voice-over-IP and data traffic in and wireless networks, in which it is imperative to minimize per-packet overhead. The disclosed protocol provides as much security as possible, by authenticating the uncompressed headers rather than the compressed headers.
    Type: Grant
    Filed: June 2, 2003
    Date of Patent: September 16, 2008
    Assignee: Cisco Technology, Inc.
    Inventors: David A. McGrew, Jan Vilhuber
  • Patent number: 7421733
    Abstract: When a user successfully logs into an account, the user is provided with a first-class login token, which entitles the user to one or more unsuccessful login attempts without experiencing delays the user would otherwise experience. If attempts with a second-class login token or an expired first-class login token is impermissible, a subsequent login attempt is subject to delays the user would otherwise not experience. The delays minimize the effectiveness of dictionary attacks. Additionally, if the user attempts to login without a login token or an invalid login token, the login attempt is impermissible and the user is provided with a second-class login token for use in a delayed, subsequent login attempt.
    Type: Grant
    Filed: February 6, 2002
    Date of Patent: September 2, 2008
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Steven Charles Glassman, Mark Steven Manasse
  • Patent number: 7415113
    Abstract: Security keys for the provision of a secure service such as content provision are generated in an ancestral hierarchy, so that invalidation of a key in the hierarchy results in a need to reconfigure all other keys in the hierarchy to the extent they share common ancestry. When a user subscription to the service lapses, a decision on invalidation of their key is based in a determination of whether it's more costly to the subscriber to invalidate the key, or continue providing an unpaid-for service. Keys can be allocated to users from domains of the hierarchy on the basis of their economic value to the provider, with higher value users being allocated keys from domains which share fewer common ancestors with other users of other domains than those users share with each other, to minimize inconvenience to high value users of key reconfiguration.
    Type: Grant
    Filed: July 30, 2003
    Date of Patent: August 19, 2008
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Antonio Lain, Richard Taylor, Christopher Tofts
  • Patent number: 7412718
    Abstract: Provided are a method, system and article of manufacture for bidirectional data transfer. In certain embodiments a link layer login is sent from a first port to a second port. Subsequently, an application layer login is sent from the first port to the second port to establish a first data path, wherein the first data path is from the first port to the second port. Subsequently, another application layer login is sent from the second port to the first port to establish a second data path, wherein the second data path is from the second port to the first port. In certain other embodiments, a first data path is established from a first port to a second port. A determination is made at the first port, whether the second port has a second data path established from the second port to the first port. An application layer logout is sent from the first port to the second port, in response to determining that the second port has the second data path established from the second port to the first port.
    Type: Grant
    Filed: November 20, 2003
    Date of Patent: August 12, 2008
    Assignee: International Business Machines Corporation
    Inventors: Steven Edward Klein, James Chien-Chiung Chen, Patricia Ching Lu, Minh-Ngoc Le Huynh
  • Patent number: 7392383
    Abstract: A method, apparatus, and computer instructions for process-based access controls on computer resources to processes. An access mechanism is provided in which a specific invoker obtains an object access identity (ACI). Another mechanism is provided in which a specific object, such as a file system resource, requires a specific object access identity to obtain one of the forms of access denoted by an access control list. A process may “grant” an identifier that is later “required” for a system resource access. Objects may specify their own access requirements and permitted access modes. The granted identifier, ACI, is stored in the process's credentials once these credentials match a specific “grant” entry in the access control list. This identifier has no meaning outside of being used to make an access decision for a specific resource. When a process tries to access the object, the object's access control list is scanned for “required” entries.
    Type: Grant
    Filed: September 25, 2003
    Date of Patent: June 24, 2008
    Assignee: International Business Machines Corporation
    Inventors: Mounir Emil Basibes, Julianne Frances Haugh
  • Patent number: 7389427
    Abstract: A method and platform for maintaining the security of output data in an isolated execution environment. A system memory has an isolated output area readable only by secure output controllers having an isolated execution mode. The output controllers may make a request for access to the isolated output area, upon proper authentication if the request access is granted. The output device may either DMA the content of the isolated output area to an output end point, such as a display, or load it into local storage, the security of which is guaranteed by the controller.
    Type: Grant
    Filed: September 28, 2000
    Date of Patent: June 17, 2008
    Assignee: Intel Corporation
    Inventors: Francis X. McKeen, Ken Reneris, David W. Grawrock
  • Patent number: 7389420
    Abstract: The disclosure describes methods for using digital watermarking to authenticate digital media signals, such as images, audio and video signals. It also describes techniques for using embedded watermarks to repair altered parts of a media signal when alteration is detected. Alteration is detected using hashes, digital watermarks, and a combination of hashes and digital watermarks.
    Type: Grant
    Filed: October 18, 2001
    Date of Patent: June 17, 2008
    Assignee: Digimarc Corporation
    Inventor: Jun Tian
  • Patent number: 7389537
    Abstract: A network device coordinates with other devices in a network to create a distributed filtering system. The device detects an attack in the network, such as a distributed denial of service attack, and forwards attack information to the other devices. The devices may categorize data into one or more groups and rate limit the amount of data being forwarded based on rate limits for the particular categories. The rate limits may also be updated based on the network conditions. The rate limits may further be used to guarantee bandwidth for certain categories of data.
    Type: Grant
    Filed: May 8, 2003
    Date of Patent: June 17, 2008
    Assignee: Juniper Networks, Inc.
    Inventors: Ross W. Callon, Frank Kastenholz
  • Patent number: 7383441
    Abstract: The invention relates to a method for confirming the authenticity of a document. According to the invention, said method is carried out in such a way that the authenticity is confirmed using a digital signature, the signed confirmation of authenticity is integrated into the document by means of a secret watermark and that the document is also provided with a public watermark.
    Type: Grant
    Filed: July 18, 2002
    Date of Patent: June 3, 2008
    Assignee: Thomson Licensing
    Inventors: Jan C. Vorbrüggen, Wolfgang Kubbilun, Eckhard Koch, Ingo A. Kubbilun, Hans Joachim Bickenbach, Marcus Belke
  • Patent number: 7383436
    Abstract: An approach for establishing secure multicast communication among multiple multicast proxy service nodes is disclosed. The multicast proxy service nodes, which can be distributed throughout an enterprise domain, are organized in a logical tree that mimics the logical tree arrangement of domains in a directory server system. The attributes of the multicast proxy service nodes include the group session keys that are members of the secure multicast or broadcast groups. Because keys as well as key version information are housed in the directory, multicast security can be achieved over any number of network domains across the entire enterprise. Key information is stored in, and the logical tree is supported by, a directory service. Replication of the directory accomplishes distribution of keys. Multicast proxy service nodes may obtain current key information from a local copy of the replicated directory.
    Type: Grant
    Filed: September 29, 2004
    Date of Patent: June 3, 2008
    Assignee: Cisco Technology, Inc.
    Inventors: Sunil Srivastava, Jonathan Trostle, Raymond Bell, Ramprasad Golla
  • Patent number: 7376841
    Abstract: A portable data processing system having a chassis base unit and a chassis cover unit pivotably attached with the chassis base unit is provided. A hand impression is disposed on a bottom surface of the chassis base unit. A portable data processing system having a chassis base unit and a chassis cover unit each having a partial hand impression disposed on respective surface is provided.
    Type: Grant
    Filed: January 12, 2004
    Date of Patent: May 20, 2008
    Assignee: International Business Machines Corporation
    Inventor: Alvaro Sanchez-Cifuentes
  • Patent number: RE40334
    Abstract: A method and apparatus for the transmission and reception of scrambled data is disclosed. In some embodiments, the method and apparatus includes transmitting a scrambled data stream to a decoder, sending the scrambled data stream to a portable security module inserted in the decoder, descrambling the scrambled data stream, encrypting a descrambled data stream, and using the encrypted data stream to the decoder, decrypting the encrypted data stream, and using the decrypted data stream.
    Type: Grant
    Filed: January 13, 2006
    Date of Patent: May 20, 2008
    Assignee: Nagra Thomson Licensing
    Inventors: Michel Maillard, Christian Benardeau, Jean-Luc Dauvois