Patents by Inventor Eric Sprunk

Eric Sprunk has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8973025
    Abstract: Two or more set-top boxes are installed in a household. A communications link, preferably a physical link, is provided between or among the set-top boxes. One of the boxes is designated as a “master” box while the other box or boxes are “slaves.” The slave box will use the communications link to communicate in a secured and encrypted manner with the master box. If that communication is severed, e.g., if an attempt is made to move the slave box to another household to provide unauthorized service in that household, the slave box will stop working when it can no longer communicate with the master box.
    Type: Grant
    Filed: November 2, 2011
    Date of Patent: March 3, 2015
    Assignee: General Instrument Corporation
    Inventors: Paul Moroney, Scott Contini, Eric Sprunk, Allen James Anderson
  • Patent number: 8479020
    Abstract: A process may be utilized by a device to implement public key asymmetric encryption. The process encrypts a data set with a symmetric encryption key to form an encrypted data set. Further, the process encrypts the symmetric encryption key with a public key component of an asymmetric encryption key to form an asymmetric encrypted cookie. Finally, the process stores the encrypted data set and the asymmetric encrypted cookie in a non-secure area of a storage medium.
    Type: Grant
    Filed: July 25, 2007
    Date of Patent: July 2, 2013
    Assignee: Motorola Mobility LLC
    Inventor: Eric Sprunk
  • Patent number: 8392702
    Abstract: A system for token-based management of a PKI (public key infrastructure) personalization process includes a token request and management system (TRMS) configured to gather request information from a requestor; and a token personalization system (TPS) configured to personalize a hardware token such that usage of the hardware token is constrained by the request information. A method for token-based management of a PKI personalization process includes: requesting a hardware token; personalizing a hardware token such that the hardware token is confined to operation within limiting parameters; binding the hardware token to a workstation which is configured receive the hardware token and use credentials within the hardware token to request and download PKI data from a PKI server, the workstation being further configured to personalize an end user product by loading the PKI data into internal memory contained within the end user product; and monitoring usage of the hardware token and the PKI data.
    Type: Grant
    Filed: July 17, 2008
    Date of Patent: March 5, 2013
    Assignee: General Instrument Corporation
    Inventors: Xin Qiu, Eric Sprunk, Liqiang Chen, Jason Pasion
  • Publication number: 20120110612
    Abstract: Two or more set-top boxes are installed in a household. A communications link, preferably a physical link, is provided between or among the set-top boxes. One of the boxes is designated as a “master” box while the other box or boxes are “slaves.” The slave box will use the communications link to communicate in a secured and encrypted manner with the master box. If that communication is severed, e.g., if an attempt is made to move the slave box to another household to provide unauthorized service in that household, the slave box will stop working when it can no longer communicate with the master box.
    Type: Application
    Filed: November 2, 2011
    Publication date: May 3, 2012
    Applicant: GENERAL INSTRUMENT CORPORATION
    Inventors: Paul Moroney, Scott Contini, Eric Sprunk, Allen James Anderson
  • Patent number: 8156560
    Abstract: The present invention discloses an apparatus and method for defining and enforcing rules of transition between two security domains, e.g., a transport domain and a persistent security domain. In turn, a border guard, e.g., a security device, is provided between these two domains that enforce rules for transition between the two security domains. This novel approach of defining a transport domain and a persistent security domain simplifies the classification of the digital content and its movement through the system. Namely, the border guard once established between the two systems can enforce DRM rules associated with how contents are moved between the two domains.
    Type: Grant
    Filed: December 30, 2004
    Date of Patent: April 10, 2012
    Assignee: General Instrument Corporation
    Inventors: John I. Okimoto, Bridget D. Kimball, Annie O. Chen, Michael T. Habrat, Douglas M. Petty, Eric Sprunk, Lawrence W. Tang
  • Patent number: 8068610
    Abstract: Two or more set-top boxes are installed in a household. A communications link, preferably a physical link, is provided between or among the set-top boxes. One of the boxes is designated as a “master” box while the other box or boxes are “slaves.” The slave box will use the communications link to communicate in a secured and encrypted manner with the master box. If that communication is severed, e.g., if an attempt is made to move the slave box to another household to provide unauthorized service in that household, the slave box will stop working when it can no longer communicate with the master box.
    Type: Grant
    Filed: November 20, 2002
    Date of Patent: November 29, 2011
    Assignee: General Instrument Corporation
    Inventors: Paul Moroney, Scott Contini, Eric Sprunk, Allen James Anderson
  • Patent number: 7787622
    Abstract: A system and method for digital data distribution is disclosed. The system and method provides a set of one or more source streams encoded by an encoder to form a common data stream for distribution to a plurality of destination systems, each authorized to access at least a portion of the common data stream. Encryption comprises obtaining the source stream, identifying some blocks of the source stream as secure blocks, identifying some other blocks of the source stream as unsecured blocks, encrypting the secure blocks for each of a plurality of destination system classes wherein each of the plurality of destination systems is a member of one or more destination system classes, and each of the blocks of an encrypted secure block set is decryptable by destination systems in the class associated with that encrypted secure block set.
    Type: Grant
    Filed: November 13, 2003
    Date of Patent: August 31, 2010
    Assignee: General Instrument Corporation
    Inventor: Eric Sprunk
  • Publication number: 20090031131
    Abstract: A system for token-based management of a PKI personalization process includes a token request and management system (TRMS) configured to gather request information from a requestor; and a token personalization system (TPS) configured to personalize a hardware token such that usage of the hardware token is constrained by the request information. A method for token-based management of a PKI personalization process includes: requesting a hardware token; personalizing a hardware token such that the hardware token is confined to operation within limiting parameters; binding the hardware token to a workstation which is configured receive the hardware token and use credentials within the hardware token to request and download PKI data from a PKI server, the workstation being further configured to personalize an end user product by loading the PKI data into internal memory contained within the end user product; and monitoring usage of the hardware token and the PKI data.
    Type: Application
    Filed: July 17, 2008
    Publication date: January 29, 2009
    Applicant: GENERAL INSTRUMENT CORPORATION
    Inventors: Xin Qiu, Eric Sprunk, Liqiang Chen, Jason Pasion
  • Publication number: 20090028343
    Abstract: A process may be utilized by a device to implement public key asymmetric encryption. The process encrypts a data set with a symmetric encryption key to form an encrypted data set. Further, the process encrypts the symmetric encryption key with a public key component of an asymmetric encryption key to form an asymmetric encrypted cookie. Finally, the process stores the encrypted data set and the asymmetric encrypted cookie in a non-secure area of a storage medium.
    Type: Application
    Filed: July 25, 2007
    Publication date: January 29, 2009
    Applicant: GENERAL INSTRUMENT CORPORATION
    Inventor: Eric Sprunk
  • Patent number: 7404082
    Abstract: Described herein are embodiments that provide an approach to cryptographic key management for a digital rights management (DRM) architecture that includes multiple levels of key management for minimizing bandwidth usage while maximizing security for the DRM architecture. In one embodiment, there is provided a data structure for cryptographic key management that includes a public/private key pair and three additional layers of symmetric keys for authorizing access to a plurality of contents.
    Type: Grant
    Filed: September 16, 2005
    Date of Patent: July 22, 2008
    Assignee: General Instrument Corporation
    Inventors: Alexander Medvinsky, Paul Moroney, Eric Sprunk, Petr Peterka
  • Publication number: 20080049942
    Abstract: A system and method for securely distributing PKI data, such as one or more private keys or other confidential digital information, from a PKI data generation facility to a product in a product personalization facility that is not connected to the PKI data generation facility and is assumed to be a non-secure product personalization facility. The system includes a PKI data loader for securely transmitting the encrypted PKI data transferred from the PKI data generator to a PKI server at the product personalization facility. The PKI server then transfers the PKI data to the product of interest, typically via a PKI station acting as a proxy between the PKI server and the product. In each communication step, PKI data being transferred is encrypted multiple times and the system is designed such that if any intermediate node is compromised with all of its keys, the overall system has not yet been compromised.
    Type: Application
    Filed: August 28, 2007
    Publication date: February 28, 2008
    Applicant: General Instrument Corporation
    Inventors: Eric Sprunk, Alexander Medvinsky, Xin Qiu, Stuart Moskovics, Liqiang Chen
  • Publication number: 20070294171
    Abstract: A method and apparatus of providing a virtual universe associated with a product is disclosed. A virtual universe of amenities is established. The virtual universe of amenities is sponsored by the vendor of a product. A security code is provided as part of the sale of the product. The security code provides access to a portion of the virtual universe of amenities. A user is permitted to access the portion of the virtual universe of amenities when the security code is authenticated at a virtual universe server.
    Type: Application
    Filed: June 6, 2006
    Publication date: December 20, 2007
    Inventor: Eric Sprunk
  • Publication number: 20070179898
    Abstract: User-to-user (“superdistribution”) of digital content allows for management and control of the distribution by a content owner, content distributor or other owner or licensee of the content. Provisions are also available for identifying senders and receivers of content for purposes of compensating or encouraging distribution. A sending user generates a referral key that is used to encrypt all, or a portion of, the content, or to encrypt other mechanisms (e.g., another key, ticket, etc.) that will ultimately be used to allow access to the content. The sending user creates a content referral object that includes the restricted referral key, an identification of the license server and an identification of the content. A receiving user receives the content referral object and contacts the license server to identify the transaction (e.g., content being referred, access rights desired, etc.) and to receive information (e.g., a key or ticket) to use the referral key to access the content.
    Type: Application
    Filed: February 2, 2006
    Publication date: August 2, 2007
    Applicant: General Instrument Corporation
    Inventors: Alexander Medvinsky, Eric Sprunk
  • Patent number: 7243366
    Abstract: A digital rights management architecture for securely delivering content to authorized consumers. The architecture includes a content provider and a consumer system for requesting content from the content provider. The content provider generates a session rights object having purchase options selected by the consumer. A KDC thereafter provides authorization data to the consumer system. Also, a caching server is provided for comparing the purchase options with the authorization data. The caching server forwards the requested content to the consumer system if the purchase options match the authorization data. Note that the caching server employs real time streaming for securely forwarding the encrypted content, and the requested content is encrypted for forwarding to the consumer system. Further, the caching server and the consumer system exchange encrypted control messages (and authenticated) for supporting transfer of the requested content.
    Type: Grant
    Filed: March 4, 2002
    Date of Patent: July 10, 2007
    Assignee: General Instrument Corporation
    Inventors: Alexander Medvinsky, Petr Peterka, Paul Moroney, Eric Sprunk
  • Publication number: 20070091345
    Abstract: According to one embodiment of the invention a system is utilized to leverage the security arrangement between a first and second device to establish a secure link between the first device and a third device. One embodiment of the invention is particularly suitable for loading security data on a set top box, such as that utilized in the cable television industry.
    Type: Application
    Filed: October 20, 2005
    Publication date: April 26, 2007
    Applicant: General Instrument Corporation
    Inventors: Xin Qiu, Bridget Kimball, Eric Sprunk, Lawrence Tang
  • Patent number: 7150035
    Abstract: A method of securing information. The method comprises: obtaining a path to the information; and performing a security check regarding the path.
    Type: Grant
    Filed: March 20, 2001
    Date of Patent: December 12, 2006
    Assignee: General Instrument Corporation
    Inventors: Douglas Makofka, Eric Sprunk
  • Publication number: 20060146885
    Abstract: The present invention discloses a system and method for providing a secured system time reference to a subscriber device, e.g., a set top box or a receiver. In one embodiment, the system time reference is provided in a secure system time message that is broadcasted to a plurality of subscriber devices. Each subscriber device has a security device or software application that is capable of determining whether the received system time reference is legitimate. If the system time reference is determined to be legitimate, a local time reference is synchronized with said received system time reference.
    Type: Application
    Filed: December 30, 2004
    Publication date: July 6, 2006
    Inventors: Bridget Kimball, Michael Habrat, John Okimoto, Douglas Petty, Eric Sprunk, Lawrence Tang
  • Publication number: 20060149676
    Abstract: The present invention discloses an apparatus and method for providing a secure move of a content decryption key within or between domains. Namely, the present invention addresses the single copy usage rule by restricting the movement of the decryption key instead of restricting the movement of the encrypted content itself.
    Type: Application
    Filed: December 30, 2004
    Publication date: July 6, 2006
    Inventors: Eric Sprunk, Alexander Medvinsky
  • Publication number: 20060150252
    Abstract: The present invention discloses an apparatus and method for defining and enforcing rules of transition between two security domains, e.g., a transport domain and a persistent security domain. In turn, a border guard, e.g., a security device, is provided between these two domains that enforce rules for transition between the two security domains. This novel approach of defining a transport domain and a persistent security domain simplifies the classification of the digital content and its movement through the system. Namely, the border guard once established between the two systems can enforce DRM rules associated with how contents are moved between the two domains.
    Type: Application
    Filed: December 30, 2004
    Publication date: July 6, 2006
    Inventors: John Okimoto, Bridget Kimball, Annie Chen, Michael Habrat, Douglas Petty, Eric Sprunk, Lawrence Tang
  • Publication number: 20060059342
    Abstract: Described herein are embodiments that provide an approach to cryptographic key management for a digital rights management (DRM) architecture that includes multiple levels of key management for minimizing bandwidth usage while maximizing security for the DRM architecture. In one embodiment, there is provided a data structure for cryptographic key management that includes a public/private key pair and three additional layers of symmetric keys for authorizing access to a plurality of contents.
    Type: Application
    Filed: September 16, 2005
    Publication date: March 16, 2006
    Inventors: Alexander Medvinsky, Paul Moroney, Eric Sprunk, Petr Peterka