Patents by Inventor Gary L. Luckenbaugh

Gary L. Luckenbaugh has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 6311269
    Abstract: Arbitrarily fine-grained limitation of access to information stored in a resource of a data processor network is provided in a manner compatible with existing network browsers by mapping user identity and credentials with randomly assigned security cookie information which thus serves as a surrogate credential accompanying each user request during a session. Labels are imbedded within HTML files/text which may embody any desired security policy, including mandatory access control (MAC) arrangements which are not available through native browser functions. Data is retrieved in response to a user request which includes a security cookie from a location in the resource which is not directly accessible through use of a URL; the location being stored in a configuration file which is hidden from users.
    Type: Grant
    Filed: June 15, 1998
    Date of Patent: October 30, 2001
    Assignee: Lockheed Martin Corporation
    Inventors: Gary L. Luckenbaugh, Forrest E. Stoakes
  • Publication number: 20010013096
    Abstract: Arbitrarily fine-grained limitation of access to information stored in a resource of a data processor network is provided in a manner compatible with existing network browsers by mapping user identity and credentials with randomly assigned security cookie information which thus serves as a surrogate credential accompanying each user request during a session. Labels are imbedded within HTML files/text which may embody any desired security policy, including mandatory access control (MAC) arrangements which are not available through native browser functions. Data is retrieved in response to a user request which includes a security cookie from a location in the resource which is not directly accessible through use of a URL; the location being stored in a configuration file which is hidden from users.
    Type: Application
    Filed: June 15, 1998
    Publication date: August 9, 2001
    Inventors: GARY L. LUCKENBAUGH, FORREST E. STOAKES
  • Patent number: 5991877
    Abstract: An object-oriented framework provides ease of development and alteration of access control systems for arbitrary applications and accomodates arbitrary security policies while providing fine-grained security by providing for creation of labels for portions of a resource such as an application or portions of files, credentials corresponding to users and any other objects of the access control system by providing templates for such objects within at least one policy manager class of objects and which can be selected or modified at will. Provision for creation of label and credential objects which are later compared or correlated for granting or denying access to portions of a resource effectively decouples security policy from security enforcement and allows reconciliation of security policies having inconsistent requirements as well as development of hybrid and customized security policies.
    Type: Grant
    Filed: April 3, 1997
    Date of Patent: November 23, 1999
    Assignee: Lockheed Martin Corporation
    Inventor: Gary L. Luckenbaugh
  • Patent number: 5684950
    Abstract: A method for authenticating an authorized user to multiple computer servers within a distributed computing environment after a single network sign-on is disclosed. In accordance with the method and system of the present invention, an authentication broker is provided within the distributed computing network. The authentication broker first receives an authentication request from a workstation. After a determination that the authentication request is valid, the authentication broker then issues a Kerberos Ticket Granting Ticket to the workstation. At this point, if there is a request by the workstation for accessing a Kerberos Ticket-based server within the distributed computing network, the authentication broker will issue a Kerberos Service Ticket to the workstation. Similarly, if there is a request by the workstation for accessing a passticket-based server within the distributed computing network, the authentication broker will issue a passticket to the workstation.
    Type: Grant
    Filed: September 23, 1996
    Date of Patent: November 4, 1997
    Assignee: Lockheed Martin Corporation
    Inventors: Timothy S. Dare, Eric B. Ek, Gary L. Luckenbaugh
  • Patent number: 4918653
    Abstract: The trusted path mechanism invention guarantees that data typed by a user on a terminal keyboard is protected from any intrusion by unauthorized programs. It allows a user to create a non-forgeable and non-penetrable communication path between the user's terminal and the trusted operating system software. The user can create a trusted path by simply pressing a key, called the Secure Attention Key (SAK), on the terminal keyboard. This operation can be called when the user logs into the system in order to be sure that the user is communicating with the real login program and not a Trojan horse program masquerading as a login program, which could steal the user's password. After the user establishes the trusted path, he can enter his critical data, such as a password, and can be sure that his critical data is not being stolen by an intruder's program.
    Type: Grant
    Filed: January 28, 1988
    Date of Patent: April 17, 1990
    Assignee: International Business Machines Corporation
    Inventors: Abhai Johri, Gary L. Luckenbaugh