Patents by Inventor Bertrand Marquet

Bertrand Marquet has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8102838
    Abstract: A method and apparatus are provided for authenticating a user attempting to establish a service which uses SIP. The user registers with the SIP server by providing the digital otoacoustic signature of the user. Thereafter, when the user attempts to initiate a session through the SIP server, the SIP server sends an Authorization Request message to the SIP client of the user. The SIP client reads the user's digital otoacoustic signature, generates a response based on the digital otoacoustic signature, and embeds the response in a second Invite message sent back to the SIP server. Meanwhile, the SIP server determines an expected response, based on the digital otoacoustic signature registered by the user. If the response provided by the SIP client matches the response expected by the SIP server, the SIP server allows establishment of the server.
    Type: Grant
    Filed: January 17, 2007
    Date of Patent: January 24, 2012
    Assignee: Alcatel Lucent
    Inventors: Vinod Kumar Choyi, Bertrand Marquet
  • Patent number: 8031596
    Abstract: The invention concerns a router associated to a secure device (DC) and included in a communication network (RC), comprising an interface (IRT) to communicate with the secure device following an authentication of the router by the secure device, and comprising a protocol interpreter (INT) to command the execution of the critical operations of one or more routing protocols by the secure device. The sensitive or critical portions of a routing protocol are executed in a secure and reliable manner in the secured device, for example of a chip card type.
    Type: Grant
    Filed: June 5, 2009
    Date of Patent: October 4, 2011
    Assignee: Alcatel Lucent
    Inventors: Emmanuel Onfroy, Evren Bulut, Bertrand Marquet, José Araujo, Arnaud Ansiaux
  • Patent number: 7783756
    Abstract: Mechanisms and methods for providing a mobile/wireless device with protection against false access-point/base-station attacks using MAC address protection are presented. The mobile/wireless device known as mobile client (MC) gains access to wireless network by discovering and selectively associating with an access point (AP). The MAC addresses of both the AP and the MC are protected during all communications between the AP and MC during the discovery phase. This protection mitigates MAC address spoofing type attacks on both the AP and the MC.
    Type: Grant
    Filed: June 3, 2005
    Date of Patent: August 24, 2010
    Assignee: Alcatel Lucent
    Inventors: Vinod Kumar Choyi, Bertrand Marquet, Frederic Gariador
  • Patent number: 7743421
    Abstract: Communication network security risk exposure management systems and methods are disclosed. Risks to a communication network are determined by analyzing assets of the communication network and vulnerabilities affecting the assets. Assets may include physical assets such as equipment or logical assets such as software or data. Risk analysis may be adapted to assess risks to a particular feature of a communication network by analyzing assets of the communication network which are associated with that feature and one or more of vulnerabilities which affect the feature and vulnerabilities which affect the assets associated with the feature. A feature may be an asset itself or a function or service offered in the network and supported by particular assets, for example.
    Type: Grant
    Filed: May 18, 2005
    Date of Patent: June 22, 2010
    Assignee: Alcatel Lucent
    Inventors: Francois J. N. Cosquer, Bertrand Marquet, Robert W. MacIntosh, Yvon Leclerc, Scott David D'Souza
  • Publication number: 20100014515
    Abstract: The invention concerns a router associated to a secure device (DC) and included in a communication network (RC), comprising an interface (IRT) to communicate with the secure device following an authentication of the router by the secure device, and comprising a protocol interpreter (INT) to command the execution of the critical operations of one or more routing protocols by the secure device. The sensitive or critical portions of a routing protocol are executed in a secure and reliable manner in the secured device, for example of a chip card type.
    Type: Application
    Filed: June 5, 2009
    Publication date: January 21, 2010
    Inventors: Emmanuel Onfroy, Evren Bulut, Bertrand Marquet, José Araujo, Arnaud Ansiaux
  • Patent number: 7631344
    Abstract: A distributed authentication framework is presented. The framework includes an authentication stack that is created by an authentication server. The server receives an authentication request from an end-user, the request including an authentication domain ID that distinguishes the end-user. The authentication stack has entries that trigger local or remote specific authentication actions providing respective results. When the results are consolidated the authentication status of the end-user is determined.
    Type: Grant
    Filed: November 4, 2003
    Date of Patent: December 8, 2009
    Assignee: Alcatel Lucent
    Inventors: Christophe Gustave, Bertrand Marquet, Olivier Le Moigne
  • Patent number: 7536716
    Abstract: The present invention provides adequate service virtualization and compartmentalization in Network Management Systems for heterogeneous Network Elements to provide interoperability. It introduces a generic mediation layer that can be added to each Network Element that does not provide a network compartmentalization model that is compatible with the one used by the Network Management System. The mediation layer acts as a reverse proxy for the Network Management System to provide an operator with transparent access to an appropriate Management Service. The present invention is also instrumental in providing a high level of security in such hybrid networks.
    Type: Grant
    Filed: April 17, 2003
    Date of Patent: May 19, 2009
    Assignee: Alcatel Lucent
    Inventors: Frederic Gariador, Olivier Le Moigne, Bertrand Marquet
  • Publication number: 20080172728
    Abstract: A method and apparatus are provided for authenticating a user attempting to establish a service which uses SIP. The user registers with the SIP server by providing the digital otoacoustic signature of the user. Thereafter, when the user attempts to initiate a session through the SIP server, the SIP server sends an Authorization Request message to the SIP client of the user. The SIP client reads the user's digital otoacoustic signature, generates a response based on the digital otoacoustic signature, and embeds the response in a second Invite message sent back to the SIP server. Meanwhile, the SIP server determines an expected response, based on the digital otoacoustic signature registered by the user. If the response provided by the SIP client matches the response expected by the SIP server, the SIP server allows establishment of the server.
    Type: Application
    Filed: January 17, 2007
    Publication date: July 17, 2008
    Applicant: ALCATEL LUCENT
    Inventors: Vinod Kumar Choyi, Bertrand Marquet
  • Publication number: 20080005575
    Abstract: A method and apparatus are provided for authenticating a user of a mobile phone. While the user holds the phone to his or her ear, a microphone near the earpiece emits clicks into the user's ear. The speaker of the phone measures the response from the ear as an otoacoustic signal. A processor digitizes the measured otoacoustic signal to produce a received digital otoacoustic signature, and compares this with a stored digital otoacoustic signature of a legitimate user. If the signatures match, the phone is enabled. The invention allows secure authentication of mobile phones in a manner very natural and convenient to users.
    Type: Application
    Filed: June 30, 2006
    Publication date: January 3, 2008
    Applicant: ALCATEL
    Inventors: Vinod Kumar Choyi, Bertrand Marquet
  • Patent number: 7305554
    Abstract: Systems and methods of dynamically introducing security features into a client-server application program are described. A security server between an application server and a database has multiple security components with a shared dependency. This shared dependency enables the introduction of a new security component providing a new security function without compromising the security of the application program. The new security component acquires state information from other security components in the security server thereby dynamically reconfiguring the component-based security system.
    Type: Grant
    Filed: December 16, 2002
    Date of Patent: December 4, 2007
    Assignee: Alcatel Canada Inc.
    Inventors: Bertrand Marquet, Adrian Mario Rossi, Francois J. N. Cosquer
  • Patent number: 7284269
    Abstract: A communications security system has been described. The security system in the form of a firewall is made up of a plurality of communicatively coupled sets of modules in a matrix configuration. The modules may be implemented in hardware and software in order to rely on the advantages of each technology. Data packets are typically coupled to an ingress side of the firewall where policy rules having the highest importance are checked first. The result is a high speed system having carrier class availability.
    Type: Grant
    Filed: May 29, 2002
    Date of Patent: October 16, 2007
    Assignee: Alcatel Canada Inc.
    Inventors: Bertrand Marquet, Scott David D'Souza, Paul Kierstead
  • Patent number: 7171684
    Abstract: A virtual security server enabling a set of applications to access a plurality of security services. In response to a service request from a software application, the virtual security server receive service determines which of the security servers is able to provide the requested service. The virtual security server sends to a selected security server data enabling the selected security server to provide the security service corresponding to the service request. Accordingly, communication between the applications and the security servers is simplified because the application are not required to manage negotiation protocols associated with the security servers and choose the security server(s) appropriate for the required service.
    Type: Grant
    Filed: May 4, 2000
    Date of Patent: January 30, 2007
    Assignee: Alcatel
    Inventors: Bertrand Marquet, Guy Fouquet, Laurent Ballester
  • Publication number: 20070011452
    Abstract: A secured execution device (SED) maintains security credentials for a certain user that requests access to the network for performing specified operations or for obtaining specified information. The NE from where the user requests access to the network is authenticated using SED credentials against a multi-level and multi-factor credentials table maintained by a NE authentication controller provided in the EMS/NM/OSS controlling the respective NE. The NE authentication controller issues a challenge and transmits it to the NE. The SED receives the challenge and both the SED and the NE authentication controller process the random number in the same way. The SED then returns a one time usage cryptographic message with the response to the challenge. The NE authentication controller checks the SED response against the expected response calculated locally; the user gains access to the network over the NE if the two responses coincide.
    Type: Application
    Filed: July 8, 2005
    Publication date: January 11, 2007
    Applicant: ALCATEL
    Inventors: Bertrand Marquet, Francois Cosquer
  • Publication number: 20060274643
    Abstract: Mechanisms and methods for providing a mobile/wireless device with protection against false access-point/base-station attacks using MAC address protection are presented. The mobile/wireless device known as mobile client (MC) gains access to wireless network by discovering and selectively associating with an access point (AP). The MAC addresses of both the AP and the MC are protected during all communications between the AP and MC during the discovery phase. This protection mitigates MAC address spoofing type attacks on both the AP and the MC.
    Type: Application
    Filed: June 3, 2005
    Publication date: December 7, 2006
    Applicant: ALCATEL
    Inventors: Vinod Choyi, Bertrand Marquet, Frederic Gariador
  • Publication number: 20060265751
    Abstract: Communication network security risk exposure management systems and methods are disclosed. Risks to a communication network are determined by analyzing assets of the communication network and vulnerabilities affecting the assets. Assets may include physical assets such as equipment or logical assets such as software or data. Risk analysis may be adapted to assess risks to a particular feature of a communication network by analyzing assets of the communication network which are associated with that feature and one or more of vulnerabilities which affect the feature and vulnerabilities which affect the assets associated with the feature. A feature may be an asset itself or a function or service offered in the network and supported by particular assets, for example.
    Type: Application
    Filed: May 18, 2005
    Publication date: November 23, 2006
    Applicant: Alcatel
    Inventors: Francois Cosquer, Bertrand Marquet, Robert MacIntosh
  • Publication number: 20050257047
    Abstract: A system for improving security of management and control functions at a network element in a communications network is described. The control card of the network element is configured to function in association with an execution device such as a smartcard. The execution device has embedded thereon one or several processors each implementing specific security related operations. This limits access to the network element which, in turn, minimizes access to sensitive and confidential information.
    Type: Application
    Filed: May 17, 2004
    Publication date: November 17, 2005
    Applicant: Alcatel
    Inventors: Bertrand Marquet, Jean-Marc Robert, Francois Cosquer
  • Publication number: 20050097322
    Abstract: A distributed authentication framework is presented. The framework includes an authentication stack that is created by an authentication server. The server receives an authentication request from an end-user, the request including an authentication domain ID that distinguishes the end-user. The authentication stack has entries that trigger local or remote specific authentication actions providing respective results. When the results are consolidated the authentication status of the end-user is determined.
    Type: Application
    Filed: November 4, 2003
    Publication date: May 5, 2005
    Applicant: Alcatel
    Inventors: Christophe Gustave, Bertrand Marquet, Olivier Le Moigne
  • Publication number: 20040210768
    Abstract: The present invention provides adequate service virtualization and compartmentalization in Network Management Systems for heterogeneous Network Elements to provide interoperability. It introduces a generic mediation layer that can be added to each Network Element that does not provide a network compartmentalization model that is compatible with the one used by the Network Management System. The mediation layer acts as a reverse proxy for the Network Management System to provide an operator with transparent access to an appropriate Management Service. The present invention is also instrumental in providing a high level of security in such hybrid networks.
    Type: Application
    Filed: April 17, 2003
    Publication date: October 21, 2004
    Applicant: Alcatel
    Inventors: Frederic Gariador, Olivier Le Moigne, Bertrand Marquet
  • Publication number: 20040117622
    Abstract: Systems and methods of dynamically introducing security features into a client-server application program are described. A security server between an application server and a database has multiple security components with a shared dependency. This shared dependency enables the introduction of a new security component providing a new security function without compromising the security of the application program. The new security component acquires state information from other security components in the security server thereby dynamically reconfiguring the component-based security system.
    Type: Application
    Filed: December 16, 2002
    Publication date: June 17, 2004
    Inventors: Bertrand Marquet, Adrian Mario Rossi, Francois J.N Cosquer
  • Publication number: 20040083386
    Abstract: A system and method for providing distribution security measures in a distributed computer network environment. For consistency and ease of administration purposes, in a distributed computer network environment a security policy server can be used to maintain the global security policy of the environment. This server would need to distribute local security policies founded on the global policy to managed clients. The present invention provides a higher level of distribution security by utilizing robust cryptographic material in the distribution mechanism.
    Type: Application
    Filed: October 28, 2002
    Publication date: April 29, 2004
    Inventors: Bertrand Marquet, Frederic Gariador