Patents Examined by Thomas R. Peeso
-
Patent number: 7644277Abstract: In an authentication apparatus 300, so as to confirm whether a user is legitimate in supplying key information to a resource 500, discernment information for identifying the user is caused to be input, and only in a case where this discernment information coincided with the stored discernment information of the user, the key information is supplied to the resource. Also, in causing the authentication apparatus 300 to register the discernment information of the user, the discernment information is caused to be input, this discernment information is collated with the discernment information registered in a key information management center 200, and in a case where it coincided, the authentication apparatus 300 is caused to register the discernment information.Type: GrantFiled: June 29, 2004Date of Patent: January 5, 2010Assignee: NEC CorporationInventor: Hiroaki Nito
-
Patent number: 7617392Abstract: A system for manipulating a computer file and/or program. The system includes a serving device having access to a computer file and/or program which is unencrypted and which can encrypt the unencrypted computer file and/or program to become an encrypted computer file and/or program and transfer it. The system includes a connector connected to the serving device on which the encrypted computer file and/or program travels and to which the serving device transfers the encrypted computer file and/or program. The system includes a client device which receives the encrypted computer file and/or program and decrypts the encrypted computer file and/or program back to the unencrypted computer file and/or program. The client device does not allow intervention to the encrypted computer file and/or program during a time when the encrypted computer and/or file program is received. The serving device is separate, apart and distinct from the client device. A method for manipulating a computer file and/or program.Type: GrantFiled: July 29, 2003Date of Patent: November 10, 2009Assignee: DMTTLicensing, LLCInventor: Arthur R. Hair
-
Patent number: 7434059Abstract: A method and apparatus is provided for authenticating a candidate user of a microprocessor based system by using performance measures obtained through monitoring the behavior of the candidate user as he participates in an interactive procedure. The candidate user is authenticated if the performance measures compare favorably with predetermined requisite performance measures. The performance of an authorized user during the interactive procedure, as judged by the performance measures, must be reliably repeatable. The requisite performance measures are effectively disguised from the user and any potential onlookers, at once ensuring the integrity of the authentication method against sharing, eavesdropping, and coercion. In essence, the interactive procedure must elicit consistent performance from an authorized user, but in a manner that is not easily described or even understood by the authorized user or any onlookers.Type: GrantFiled: December 20, 2002Date of Patent: October 7, 2008Assignee: Searete LLCInventors: W. Daniel Hillis, Bran Ferren
-
Patent number: 7430665Abstract: A portable security device for providing secure communications over a plurality of networks is presented. In one embodiment, the device comprises, at least one communication port for transfer of audio data, at least one communication port for transfer of digital data, a keypad, an encoding/decoding device, a conversion device operable to covert between audio and digital data and a processor, in communication with a memory, the keypad, the said encoding/decoding device, operable to execute code for selecting a configuration of a transmission and a reception port from among said communication ports dependent upon the presence of a network communication device and an input/output device in communication with said selected ports, providing data received from said selected reception port to said encryption/decryption device for encrypting; and providing said encrypted data to said selected transmission port.Type: GrantFiled: February 15, 2005Date of Patent: September 30, 2008Inventors: Frank J. DiSanto, Denis A. Krusos
-
Patent number: 7418597Abstract: Disclosed herein are several digital certificate discovery and management systems. Detailed information on various example embodiments of the inventions are provided in the Detailed Description below, and the inventions are defined by the appended claims.Type: GrantFiled: August 13, 2004Date of Patent: August 26, 2008Assignee: Venati, Inc.Inventors: Russell S. Thornton, Benjamin Hodson, Jayson Seegmiller
-
Patent number: 7406598Abstract: A system on a chip (SOC) device is disclosed comprising external outputs, and external inputs. A first secure storage location is operably decoupled from all of the external outputs of the SOC device during a normal mode of operation. By being decoupled from all external outputs, representations of the data stored at the first secure device are prevented from being provided to the external outputs. The decryption engine is also included on the system on a chip, comprising a first data input, and a private key input coupled to a first portion of the first secure storage location, and an output coupled to a second secure location. The decryption engine is operable to determine decrypted data from data received at the first data input based upon a private key received at the private key input. The decryption engine is further operable to write the decrypted data only to the first secure memory location and the second secure location.Type: GrantFiled: April 22, 2004Date of Patent: July 29, 2008Assignee: ViXS Systems Inc.Inventor: Paul Ducharme
-
Patent number: 7395426Abstract: A method of authenticating a content provider and assuring content integrity by which the content provider is authenticated and the content integrity is assured upon download, exchange or transfer of a variety of multimedia contents through a wired/wireless communication network. The method of authenticating the content provider and assuring the content integrity, including downloading packaged contents with an electronic signature made thereto into a device of a user through a wired/wireless communication network, finding a URL address from which a certificate for verification of a signature of the content provider is provided, in a header of the contents, acquiring the certificate of the content provider after moving to the URL address, extracting a public key required for the verification of the electronic signature from the acquired certificate, and verifying the electronic signature by using the extracted public key.Type: GrantFiled: April 22, 2004Date of Patent: July 1, 2008Assignee: Samsung Electronics Co., Ltd.Inventors: Byung-rae Lee, Kyung-ah Chang
-
Firewall system for interconnecting two IP networks managed by two different administrative entities
Patent number: 7392379Abstract: Firewall system for interconnecting a first IP network (10) to a second IP network (16), these networks belonging to two different entities having each a different administration wherein any data packet transmitted/received by the first IP network is filtered by using a first firewall function and any data packet transmitted/received by the second IP network is filtered by using a second firewall function. The system comprises essentially a single firewall device (20) including filtering means (41, 43) performing both first firewall function and second firewall function, a console port (37) enabling the administrator in charge of each IP network to enter filtering rules for updating the associated firewall function and control means (39, 47, 49) interconnecting the console port and the filtering means for transmitting thereto the filtering rules so that each administrator may independently manage the system from the console port.Type: GrantFiled: July 31, 2007Date of Patent: June 24, 2008Inventors: Jean-François Le Pennec, Aurélien Bruno, Nicolas Grisi, Jean-Marie Sommerlatt -
Patent number: 7386719Abstract: A system and method for providing anti-virus protection to a web server. The method comprises the steps of: receiving web pages that are to be stored at the web server; stripping active elements from the web pages being stored at the web server; storing the web pages at the web server; receiving a request for a web page to be served by the web server; determining if active elements are required for the requested web page; inserting active elements into the requested web page if active elements are required; and serving the requested web page.Type: GrantFiled: July 29, 2003Date of Patent: June 10, 2008Assignee: International Business Machines CorporationInventor: Bruce Wallman
-
Patent number: 7380138Abstract: First data to be sent by a first party to a second party is encrypted using an encryption key that is formed using at least a hash value generated by a keyed hash of at least one condition that typically serves as an identifier of an intended recipient of the first data. The encrypted first data is provided to a data recipient who requests a decryption key from the trusted party. The trusted party is responsible for verifying that the recipient meets the specified conditions before providing the decryption key. A valid decryption key is only provided if the correct conditions have been supplied to the trusted party.Type: GrantFiled: April 22, 2004Date of Patent: May 27, 2008Assignee: Hewlett-Packard Development Company, L.P.Inventors: Liqun Chen, Keith Alexander Harrison
-
Patent number: 7380119Abstract: A method, an apparatus, a system, and a computer program product is presented for virtualizing trusted platform modules within a data processing system. A virtual trusted platform module along with a virtual endorsement key is created within a physical trusted platform module within the data processing system using a platform signing key of the physical trusted platform module, thereby providing a transitive trust relationship between the virtual trusted platform module and the core root of trust for the trusted platform. The virtual trusted platform module can be uniquely associated with a partition in a partitionable runtime environment within the data processing system.Type: GrantFiled: April 29, 2004Date of Patent: May 27, 2008Assignee: International Business Machines CorporationInventors: Steven A. Bade, Linda Nancy Betz, Andrew Gregory Kegel, Michael J. Kelly, William Lee Terrell
-
Patent number: 7376837Abstract: System for using a manufacturer issued certificate to authenticate a CTA device during registration with an IP telephony network. In response to providing the manufacturer issued certificate, the issuance of another certificate allows the CTA to be provisioned by a specific IP telephony network. The system includes a method of operating a cable telephony adapter in an IP telephony network. The method includes steps of storing a manufacturer issued certificate in the cable telephony adapter, providing the manufacturer issued certificate to the telephony network, receiving a network issued certificate, and registering for telephony services with the telephony network using the network issued certificate.Type: GrantFiled: April 7, 2000Date of Patent: May 20, 2008Assignee: General Instrument CorporationInventor: Alexander Medvinsky
-
Methods, systems and computer program products for monitoring user behavior for a server application
Patent number: 7373524Abstract: Methods, systems and computer program products are disclosed for monitoring user behavior for a server application in a computer network. The methods, systems, and computer program products can monitor communication data between a server application and a client. The methods, systems, and computer program products can also include applying one or more detectors to the communication data to identify a variety of predetermined activity. Further, the methods, systems, and computer program products can include generating a threat score associated with the predetermined activity by comparing the identified predetermined activity with a security threshold criteria.Type: GrantFiled: February 24, 2004Date of Patent: May 13, 2008Assignee: Covelight Systems, Inc.Inventors: David Lee Motsinger, David Byron Logan, Kenneth Robert Gramley, Garth Douglas Somerville, Albert Ming Choy, Douglas Wayne Hester, Virgil Montgomery Wall, Jr., Byron Lee Hargett -
Patent number: 7373510Abstract: The invention prevents robots from browsing a Web site beyond a welcome page. When an initial request from an undefined originator is received, the Web site responds to it with a welcome page including a challenge. Then, on receiving a further request from the undefined originator, the Web site can check whether the challenge is fulfilled or not. If fulfilled, the undefined originator is assumed to be a human being and authorized to go on. If the challenge is not fulfilled, the undefined originator is assumed to be a robot, in which case site access is further denied. The invention prevents Web site contents from being investigated by robots while not requiring users to have to log on.Type: GrantFiled: July 9, 2001Date of Patent: May 13, 2008Assignee: International Business Machines CorporationInventors: Marc Lamberton, Eric Levy-Abegnoli, Pascal Thubert
-
Patent number: 7373505Abstract: The present invention provides a method and system for providing a security element that is directed at inhibiting malicious activity by displaying a browser window in such a way that the user can trust and know the source of the window. Additional information and ornamentation is displayed on the window to help ensure that an end user is not confused or misled (“spoofed”) into believing that the window originates from a trusted source. When a call is made to open a browser window, the status bar is displayed by default. The status bar provides additional information, such as the security zone, to the user to help the user in determining the source of the content. The security zone informs the user the location from where the content is originating. This additional information helps to ensure that the user has the necessary information on whether or not to trust the source.Type: GrantFiled: April 15, 2004Date of Patent: May 13, 2008Assignee: Microsoft CorporationInventors: Ann Seltzer, Steve Dirickson, Roland Tokumi, Roberto A. Franco
-
Patent number: 7370192Abstract: A method for preventing cloning of a genuine security element is described. The method includes associating a random number generator (RNG) in the security element with a portion of a non-volatile memory (NVM) in the security element, and activating the RNG to automatically write, during a normal operation mode of the security element, a new random number into the portion of the NVM whenever an attempt is made to write into the portion of the NVM. Any unit other than the RNG is preferably prevented from writing data into the portion of the NVM during the normal operation mode of the security element. Related apparatus and method are also described.Type: GrantFiled: March 31, 2003Date of Patent: May 6, 2008Assignee: NDS Ltd.Inventor: Reuben Sumner
-
Patent number: 7366892Abstract: A telematics system that includes a security controller is provided. The security controller is responsible for ensuring secure access to and controlled use of resources in the vehicle. The security measures relied on by the security controller can be based on digital certificates that grant rights to certificate holders, e.g., application developers. In the case in which applications are to be used with vehicle resources, procedures are implemented to make sure that certified applications do not jeopardize vehicle resource'0 security and vehicle users' safety. Relationships among interested entities are established to promote and support secure vehicle resource access and usage. The entities can include vehicle makers, communication service providers, communication apparatus vendors, vehicle subsystem suppliers, application developers, as well as vehicle owners/users.Type: GrantFiled: January 28, 2004Date of Patent: April 29, 2008Assignee: Cellport Systems, Inc.Inventors: Charles W. Spaur, Patrick J. Kennedy, Michael F. Braitberg, Axel Fuchs, Nate Klingenstein, Lane Lee
-
Patent number: 7366895Abstract: A method for permitting encrypted communications between two stations which are operable with encryption algorithms that accept encryption keys having work factors with different values, by: in a first determining step, determining the lower one of the different values; providing an initial encryption key having a first work factor value; comparing the first work factor value with the lower one of the work factors determined in the determining step; when, in the comparing step, the first work factor value is greater than the lower one of the work factor values determined in the determining step, performing the following steps: performing a first hash function on the initial encryption key to produce a first output, and deriving from the first output a first intermediate key having a work factor value not greater than the lower one of the different work factor values determined in the determining step; performing the first hash function on the first intermediate key to produce a second output, and deriving froType: GrantFiled: January 21, 2004Date of Patent: April 29, 2008Assignee: QUALCOMM IncorporatedInventor: Gregory G. Rose
-
Patent number: 7363489Abstract: A method and related system obtains consent from a user for electronic delivery of sensitive information. The user operating a first computer accesses a web page on a server system to input the consent. The web page prompts for the consent from the user. Once the consent is received at the server system, the consent is stored and sensitive information is delivered electronically to an e-mail address specified by the user. Once consent is indicated, it is communicated from the individual's computer to another computer such as a server over, for example, a modem connection. Having secured the individual's consent, the additional sensitive information may be delivered to the individual's computer as, for example, a URL attachment to an email message.Type: GrantFiled: December 28, 2005Date of Patent: April 22, 2008Assignee: New River, Inc.Inventors: Stephen V. Burakoff, Sergiu S. Simmel, Robert A. Fein, Leonard Driscoll, Alex Magary, Garett Wiley
-
Patent number: 7363513Abstract: A method, apparatus, and computer instructions for responding to a denial of service attack. The method comprising from a remote data processing system detects an occurrence of the denial of service attack in which invalid credentials are presented to the data processing system. Connections from the remote data processing system to the data processing system are blocked in response to detecting the occurrence of the denial of service attack. A command is selectively sent to a server data processing system to block connections from the remote data processing system, in response to detecting the occurrence the denial of service attack.Type: GrantFiled: April 15, 2004Date of Patent: April 22, 2008Assignee: International Business Machines CorporationInventors: Susann Marie Keohane, Gerald Francis McBrearty, Shawn Patrick Mullen, Jessica Kelley Murillo, Johnny Meng-Han Shieh