Patents by Inventor David Grawrock

David Grawrock has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 6360322
    Abstract: In accordance with the invention a method of securely and automatically authenticating a user is disclosed. Bona fides are entered for a user, hashed, and stored at an authenticating entity, remote from the user's computer. When a user forgets his/her password, the user enters his/her bona fides, which are again hashed on the user's system, and then securely transmitted to the authenticating entity. The authenticating entity compares the received, hashed bona fides to those previously stored at the authenticating entity. If the comparison shows that the values match or otherwise appropriately correlate, the user will be authenticated. The user will then be provided with the means to access his/her encrypted data. In other words, once authenticated the authenticating entity will automatically provide the user and/or the user's computer with an access key, in one embodiment, allowing the user to access his/her encrypted data.
    Type: Grant
    Filed: September 28, 1998
    Date of Patent: March 19, 2002
    Assignee: Symantec Corporation
    Inventor: David Grawrock
  • Patent number: 6339828
    Abstract: A system is disclosed for controlling intelligible access to secured files by means of a user-memorized password in combination with a user-associated passport record. The passport record takes on two forms, one when it is physically secured within the workstation and a different second form when the passport record is in-transit. Log-in privileges are granted after a presented passport record passes a number of tests including digital signature authentication, and the ability to extract two different encrypted keys from the passport record. The in-transit record does not carry one of those two keys.
    Type: Grant
    Filed: May 3, 2000
    Date of Patent: January 15, 2002
    Assignee: Symantec Corporation
    Inventors: David Grawrock, Shawn R. Lohstroh
  • Publication number: 20010044901
    Abstract: A machine system includes bubble protection for protecting the information of certain classes of files from unauthorized access by way of unauthorized classes of programs at unauthorized periods of time. The machine system additionally may have OTF mechanisms for automatic decryption of confidential file data on a per-use basis and automatic later elimination of the decrypted data by scorching and/or re-encrypting is disclosed. The system can operate within a multi-threaded environment. The machine system additionally may have a digital signature mechanism for protecting file data from unauthorized tampering. The machine system additionally may have a volume-encryption mechanism for protecting plaintext versions of file data from exposure in events of power outages.
    Type: Application
    Filed: March 24, 1998
    Publication date: November 22, 2001
    Applicant: Symantec Corporation
    Inventor: DAVID GRAWROCK
  • Publication number: 20010002487
    Abstract: A system is disclosed for controlling intelligible access to secured files by means of a user-memorized password in combination with a user-associated passport record. The passport record takes on two forms, one when it is physically secured within the workstation and a different second form when the passport record is in-transit. Log-in privileges are granted after a presented passport record passes a number of tests including digital signature authentication, and the ability to extract two different encrypted keys from the passport record. The in-transit record does not carry one of those two keys.
    Type: Application
    Filed: December 5, 2000
    Publication date: May 31, 2001
    Applicant: Symantec Corporation
    Inventors: David Grawrock, Shawn R. Lohstroh
  • Patent number: 6081893
    Abstract: A system is disclosed for controlling intelligible access to secured files by means of a user-memorized password in combination with a user-associated passport record. The passport record takes on two forms, one when it is physically secured within the workstation and a different second form when the passport record is in-transit. Log-in privileges are granted after a presented passport record passes a number of tests including digital signature authentication, and the ability to extract two different encrypted keys from the passport record. The in-transit record does not carry one of those two keys.
    Type: Grant
    Filed: May 28, 1997
    Date of Patent: June 27, 2000
    Assignee: Symantec Corporation
    Inventors: David Grawrock, Shawn R. Lohstroh
  • Patent number: 5953419
    Abstract: A system is disclosed for automatically distributing secured versions (*Sys.sub.-- D.sub.-- key*) of a file decryption key (Sys.sub.-- D.sub.-- key) to a plurality of file users by way of the file's security label. The label is defined to contain a plurality of Access-Control-Entries Records (ACER's) where each ACER includes a respective secured version (*Sys.sub.-- D.sub.-- key*) of the file decryption key. Each such secured version (*Sys.sub.-- D.sub.-- key*) is decipherable by a respective ACER private key. Each ACER may include respective other data such as:(a) ACER-unique identifying data for uniquely identifying the ACER or an associated user;(b) decryption algorithm identifying data for identifying the decryption process to be used to decrypt the encrypted *DATA* portion of the file; and(c) special handling code for specifying special handling for the code-containing ACER.
    Type: Grant
    Filed: May 6, 1996
    Date of Patent: September 14, 1999
    Assignee: Symantec Corporation
    Inventors: Shawn R. Lohstroh, William D. McDonnal, David Grawrock
  • Patent number: 5796825
    Abstract: A machine system for automatic decryption of confidential file data on a per-use basis and automatic later elimination of the decrypted data by scorching and/or re-encrypting is disclosed. The system can operate within a multi-threaded environment. The following features are provided for secure and automatic recryption: (1) use of file-exclusion lists; (2) use of application-program exclusion lists; (3) decrypting as needed in response to intercepted file-OPEN requests; (4) encrypting as needed in response to intercepted file-CLOSE requests; (5) delaying post-CLOSE encryption in special cases; (6) delaying retry of failed encryption; (7) keeping track of the number of application programs that are using each piece of decrypted plaintext; (8) identifying non-confidential files according to the directories they are contained within; (9) including encryption and decryption rules within directories that contain confidential files; and (10) avoiding unnecessary encryption of non-modified plaintext.
    Type: Grant
    Filed: October 6, 1997
    Date of Patent: August 18, 1998
    Assignee: Symantec Corporation
    Inventors: William D. McDonnal, Shawn Lohstroh, David Grawrock
  • Patent number: 5768373
    Abstract: The present invention is directed toward providing a secure method to access data when the user has lost or forgotten the user password. In accordance with the invention and in a system where decryption of an access key will give access to data, two encrypted versions of the access key are created. A first version is formed using a key formed with the user password. A second version is formed using a public key from a public-private key pair. Generally, data access can be had by decrypting the first encrypted version of the access key with the password key. However, if the password is forgotten, access to data can be accomplished by decrypting the second encrypted version of the access key with the private key from the public-private key pair. One embodiment of the invention requires the private key to be stored at a remote site and for decryption using the private key to take place at the remote site. In this manner the user can gain access to data without significantly compromising the data security.
    Type: Grant
    Filed: May 6, 1996
    Date of Patent: June 16, 1998
    Assignee: Symantec Corporation
    Inventors: Shawn R. Lohstroh, David Grawrock
  • Patent number: 5699428
    Abstract: A machine system for automatic decryption of confidential file data on a per-use basis and automatic later elimination of the decrypted data by scorching and/or re-encrypting is disclosed. The system can operate within a multi-threaded environment. The following features are provided for secure and automatic recryption: (1) use of file-exclusion lists; (2) use of application-program exclusion lists; (3) decrypting as needed in response to intercepted file-OPEN requests; (4) encrypting as needed in response to intercepted file-CLOSE requests; (5) delaying post-CLOSE encryption in special cases; (6) delaying retry of failed encryption; (7) keeping track of the number of application programs that are using each piece of decrypted plaintext; (8) identifying non-confidential files according to the directories they are contained within; (9) including encryption and decryption rules within directories that contain confidential files; and (10) avoiding unnecessary encryption of non-modified plaintext.
    Type: Grant
    Filed: January 16, 1996
    Date of Patent: December 16, 1997
    Assignee: Symantec Corporation
    Inventors: William D. McDonnal, Shawn Lohstroh, David Grawrock