Patents by Inventor Aviel D. Rubin

Aviel D. Rubin has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 7461254
    Abstract: The present invention provides a system and method for providing certified voice and/or multimedia mail messages in a broadband signed communication system which uses packetized digital information. Cryptography is used to authenticate a message that has been compiled from streaming voice or multimedia packets. A certificate of the originator's identity and electronic signature authenticates the message. A broadband communication system user may be provisioned for certified voice and/or multimedia mail by registering with a certified mail service provider and thereby receiving certification. The called system user's CPE electronically signs the bits in received communication packets and returns the message with an electronic signature of the called system user to the calling party, along with the system user's certificate obtained from the service provider/certifying authority during registration. The electronic signature is a cryptographic key of the called party.
    Type: Grant
    Filed: September 28, 2005
    Date of Patent: December 2, 2008
    Assignee: AT&T Corp.
    Inventor: Aviel D. Rubin
  • Patent number: 7334126
    Abstract: The present invention provides authorized users access to sensitive information on internal servers inside a firewall while protecting the information from others. A strong client authentication mechanism is layered on top of a secure communication protocol to allow legitimate users access to an internal server from outside the firewall. A proxy is provided with an external component outside the firewall and an internal component inside the firewall, with a control communication channel established between the two. The external component forwards messages through the firewall to the internal component which handles user authentication and acts as a proxy between the user and the internal servers. Where the returned resource contains document hyperlinks, the links are translated into references to the proxy, permitting the user a seamless experience that is almost exactly the same whether the user is inside or outside the firewall.
    Type: Grant
    Filed: February 1, 2000
    Date of Patent: February 19, 2008
    Assignee: AT&T Corp.
    Inventors: Christian A. Gilmore, David P. Kormann, Aviel D. Rubin
  • Patent number: 7222233
    Abstract: The present invention is directed to an architecture and mechanism for securely backing up files and directories on a local machine onto untrusted servers over an insecure network.
    Type: Grant
    Filed: September 14, 2001
    Date of Patent: May 22, 2007
    Assignee: AT&T Corp.
    Inventor: Aviel D. Rubin
  • Patent number: 7149803
    Abstract: The present invention is directed to a method of providing content distribution services while minimizing the processing time required for security protocols such as the Secure Sockets Layer.
    Type: Grant
    Filed: June 8, 2001
    Date of Patent: December 12, 2006
    Assignee: AT&T Corp.
    Inventors: Frederick Douglis, Michael Rabinovich, Aviel D. Rubin, Oliver Spatscheck
  • Patent number: 7035410
    Abstract: The broadband telephony interface is provisioned by receiving information authenticating a provisioning server, establishing a communication channel between the user and the provisioning server over which is transmitted authorization information from the user to the provisioning server, and encrypting and transmitting a cryptographic key associated with the user to the provisioning server. The cryptographic key can be a symmetric key or a public key corresponding to a private key stored in the broadband telephony interface. The cryptographic key can be utilized to generate other keys which are utilized to secure communication channels for the telephony service. The broadband telephony interface advantageously can be implemented as untrusted hardware or software that is installed by a customer.
    Type: Grant
    Filed: March 1, 2000
    Date of Patent: April 25, 2006
    Assignee: AT&T Corp.
    Inventors: William A. Aiello, Steven Michael Bellovin, Charles Robert Kalmanek, Jr., William Todd Marshall, Aviel D. Rubin
  • Patent number: 6990581
    Abstract: The present invention provides a system and method for providing certified voice and/or multimedia mail messages in a broadband signed communication system which uses packetized digital information. Cryptography is used to authenticate a message that has been compiled from streaming voice or multimedia packets. A certificate of the originator's identity and electronic signature authenticates the message. A broadband communication system user may be provisioned for certified voice and/or multimedia mail by registering with a certified mail service provider and thereby receiving certification. The called system user's CPE electronically signs the bits in received communication packets and returns the message with an electronic signature of the called system user to the calling party, along with the system user's certificate obtained from the service provider/certifying authority during registration. The electronic signature is a cryptographic key of the called party.
    Type: Grant
    Filed: April 7, 2000
    Date of Patent: January 24, 2006
    Assignee: AT&T Corp.
    Inventor: Aviel D. Rubin
  • Patent number: 6850909
    Abstract: The present invention permits a user to conduct remote transactions without a network while using an untrusted computing device, such as a hand-held personal digital assistant or a laptop computer. The computing device is augmented with a smartcard reader, and the user obtains a smartcard and connects it to the device. This design can be used by an untrusted user to perform financial transactions, such as placing bets on the outcome of a probabilistic computation. Protocols are presented for adding (purchasing) or removing (selling) value on the smartcard, again without requiring a network connection. Using the instant protocols, neither the user nor the entity issuing the smartcards can benefit from cheating.
    Type: Grant
    Filed: December 11, 2002
    Date of Patent: February 1, 2005
    Assignee: AT&T Corp.
    Inventors: William A. Aiello, Aviel D. Rubin, Martin J. Strauss
  • Publication number: 20040123139
    Abstract: Traffic over a secure link or tunnel is filtered to block packets that do not conform to specified requirements for the tunnel. In one embodiment, a private network, such as an ISP network, includes a filter for blocking packets not associated with an IPSec VPN tunnel. The ISP network and/or one or both of the tunnel endpoints can include monitoring modules for detecting the presence of packets that should have been blocked by the filter.
    Type: Application
    Filed: December 18, 2002
    Publication date: June 24, 2004
    Applicant: AT&T Corp.
    Inventors: William A. Aiello, Steven Michael Bellovin, Evan Stephen Crandall, Alan Edward Kaplan, David P. Kormann, Aviel D. Rubin, Norman Loren Schryer
  • Patent number: 6496808
    Abstract: The present method permits a user to conduct remote transactions without a network while using an untrusted computing device, such as a hand-held personal digital assistant or a laptop computer. The computing device is augmented with a smartcard reader, and the user obtains a smartcard and connects it to the device. This design can be used by an untrusted user to perform financial transactions, such as placing bets on the outcome of a probabilistic computation. Protocols are presented for adding (purchasing) or removing (selling) value on the smartcard, again without requiring a network connection. Using the instant protocols, neither the user nor the entity issuing the smartcards can benefit from cheating.
    Type: Grant
    Filed: October 5, 1999
    Date of Patent: December 17, 2002
    Assignee: AT&T Corp.
    Inventors: William A. Aiello, Aviel D. Rubin, Martin J. Strauss
  • Publication number: 20020099822
    Abstract: A method of distributing revocation state information includes receiving first update scheduling information from a first party, and sending digital certificate revocation state information to the first party according to a schedule that is based on the first update scheduling information.
    Type: Application
    Filed: January 25, 2001
    Publication date: July 25, 2002
    Inventors: Aviel D. Rubin, Patrick Drew McDaniel
  • Publication number: 20020073045
    Abstract: The present invention discloses a protocol that reduces the risk of misuse of a user's card number while avoiding having to securely contact and authenticate with a card issuer before each transaction in an “online” manner.
    Type: Application
    Filed: October 23, 2001
    Publication date: June 13, 2002
    Inventors: Aviel D. Rubin, Rebecca N. Wright
  • Publication number: 20020007415
    Abstract: The present invention is directed to a method of providing content distribution services while minimizing the processing time required for security protocols such as the Secure Sockets Layer.
    Type: Application
    Filed: June 8, 2001
    Publication date: January 17, 2002
    Inventors: Frederick Douglis, Michael Rabinovich, Aviel D. Rubin, Oliver Spatscheck
  • Patent number: 5809140
    Abstract: Methods and apparatus are disclosed for providing secure session key distribution using a smart circuit card or other intelligent device. First and second hosts communicate with each other and with a server over a communication network. The first host initiates the session key distribution process by transmitting a session identifier to the server. The first host uses a first smart card storing the first host secret key to generate a first message in the form of a random bit stream which is transmitted to the second host. The server generates a second message as a function of the server secret key and the session identifier, and transmits it to the first host. The second host uses a second smart card storing the second host secret key to generate a third message as a function of the second host secret key and the first message, and transmits the third message to the first host.
    Type: Grant
    Filed: October 15, 1996
    Date of Patent: September 15, 1998
    Assignee: Bell Communications Research, Inc.
    Inventors: Aviel D. Rubin, Victor J. Shoup
  • Patent number: 5638446
    Abstract: A process for using a trusted third party to create an electronic certificate for an electronic file that can be used to establish the file and verify the identity of the creator of the file. The process is composed of two phases, a registration phase and an electronic file distribution phase. In the registration phase, a trusted third party receives information about an author, including the author's public key and affirmatively verifies the accuracy of this information. In the file distribution phase, an author sends to the trusted third party a signed message containing the hash of the file the author wants to distribute. The trusted third party creates an electronic certificate, signed by the trusted third party, containing the hash of the file sent by the author.
    Type: Grant
    Filed: August 28, 1995
    Date of Patent: June 10, 1997
    Assignee: Bell Communications Research, Inc.
    Inventor: Aviel D. Rubin