Patents by Inventor Lane W. Lee

Lane W. Lee has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9672333
    Abstract: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and dec
    Type: Grant
    Filed: November 5, 2012
    Date of Patent: June 6, 2017
    Assignee: Adobe Systems Incorporated
    Inventors: Lane W. Lee, Mark J. Gurkowski, Randal Hines
  • Publication number: 20170070345
    Abstract: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and dec
    Type: Application
    Filed: November 5, 2012
    Publication date: March 9, 2017
    Inventors: Lane W. Lee, Mark J. Gurkowski, Randal Hines
  • Publication number: 20140129847
    Abstract: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and dec
    Type: Application
    Filed: November 5, 2012
    Publication date: May 8, 2014
    Applicant: Divan Industries, LLC
    Inventors: Lane W. Lee, Mark J. Gurkowski, Randal Hines
  • Patent number: 8307217
    Abstract: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and dec
    Type: Grant
    Filed: February 5, 2008
    Date of Patent: November 6, 2012
    Inventors: Lane W. Lee, Mark J. Gurkowski, Randal Hines
  • Patent number: 8010790
    Abstract: A block-level storage device is provided that implements a digital rights management (DRM) system. In response to receiving a public key from an associated host system, the storage device challenges the host system to prove it has the corresponding private key to establish trust. This trust is established by encrypting a secure session key using the public key. The host system uses its private key to recover the secure session key. The storage device may store content that has been encrypted according to a content key. In addition, the storage device may encrypt the content key using the secure session key.
    Type: Grant
    Filed: September 10, 2008
    Date of Patent: August 30, 2011
    Assignee: DPHI, Inc.
    Inventors: Lane W. Lee, Randal C. Hines, Mark J. Gurkowski, David L. Blankenbeckler
  • Patent number: 8001387
    Abstract: In one embodiment, a storage device with biometric access includes: a biometric scanner adapted to scan a biological feature of a user to provide a corresponding extracted biometric template; and a storage engine adapted to retrieve an encrypted biometric template from a storage medium and to retrieve a corresponding encrypted content key from the storage medium. The storage engine generates a first key and combines the first key with a media identifier from the storage medium to provide a content key. Using the content key, the storage engine decrypts the retrieved encrypted biometric template. If the extracted biometric template matches the retrieved biometric template, the storage engine grants a user access to content on the storage medium.
    Type: Grant
    Filed: April 19, 2006
    Date of Patent: August 16, 2011
    Assignee: DPHI, Inc.
    Inventors: Lane W. Lee, Mark J. Gurkowski, David H. Davies
  • Patent number: 8001391
    Abstract: A method of encrypting data is provided that uses a medium key retrieved from a storage medium. The medium key is combined with another key to generate a combination key. Content is encrypted according to the combination key and written to the storage medium.
    Type: Grant
    Filed: April 17, 2008
    Date of Patent: August 16, 2011
    Assignee: DPHI, Inc.
    Inventors: Daniel R. Zaharris, Lane W. Lee
  • Patent number: 7958377
    Abstract: In one embodiment, a storage device is provided that includes: a storage medium; and a storage engine, the storage engine being configured to generate a secure session key and to receive encrypted content and a corresponding encrypted content key from a host system, wherein the content key has been encrypted by the host system using the secure session key, the storage engine being further configured to decrypt the encrypted content key using the secure session key and to encrypt the decrypted content key with a first storage engine encryption key and to write the storage-engine-encrypted content key to the storage medium.
    Type: Grant
    Filed: July 24, 2008
    Date of Patent: June 7, 2011
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Lane W. Lee, Timothy R. Feldman
  • Patent number: 7729495
    Abstract: A system and method is provided for detecting unauthorized actions with respect to encrypted data on a media disk, the media disk including a first portion for prerecorded content and a second portion for written content. The method includes reading an identifier on the media disk, wherein the identifier includes one or more sections located in one of the first portion for pre-recorded content, the second portion for written content, and both the first portion for pre-recorded content and the second portion for written content, determining whether the identifier includes a section located in the second portion written content, comparing the identifier with one or more predetermined types of identifiers for which a section is located in the second portion for written content, and if the identifier is of a type that is one of the one or more predetermined types of identifiers, detecting an unauthorized action.
    Type: Grant
    Filed: August 27, 2001
    Date of Patent: June 1, 2010
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Lane W. Lee, Timothy R. Feldman, Douglas M. Rayburn, Gary G. Kiwimagi
  • Patent number: 7672903
    Abstract: A system and method is provided for revoking a device. A method includes receiving a certificate from the device, the certificate including one or more of fields, at least one of the fields holding a signature, attempting to verify the signature, receiving a revocation list from a source, the revocation list identifying one or more data on the certificate as valid or invalid, the data including at least one of the fields of the certificate; and if one of one or more signatures identified unsuccessfully verified and one or more data is identified as invalid, preventing the transmission of a session key to the device, the session key being required to establish a secure communication channel.
    Type: Grant
    Filed: August 27, 2001
    Date of Patent: March 2, 2010
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Lane W. Lee, Timothy R. Feldman, Douglas M. Rayburn, Gary G. Kiwimagi
  • Patent number: 7549044
    Abstract: A block-level storage device is provided that implements a digital rights management (DRM) system. In response to receiving a public key from an associated host system, the storage device challenges the host system to prove it has the corresponding private key to establish trust. This trust is established by encrypting a secure session key using the public key. The host system uses its private key to recover the secure session key. The storage device may store content that has been encrypted according to a content key. In addition, the storage device may encrypt the content key using the secure session key.
    Type: Grant
    Filed: October 28, 2003
    Date of Patent: June 16, 2009
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Lane W. Lee, Randal C. Hines, Mark J. Gurkowski, David L. Blankenbeckler
  • Publication number: 20090041244
    Abstract: In one embodiment, a storage device is provided that includes: a storage medium; and a storage engine, the storage engine being configured to generate a secure session key and to receive encrypted content and a corresponding encrypted content key from a host system, wherein the content key has been encrypted by the host system using the secure session key, the storage engine being further configured to decrypt the encrypted content key using the secure session key and to encrypt the decrypted content key with a first storage engine encryption key and to write the storage-engine-encrypted content key to the storage medium.
    Type: Application
    Filed: July 24, 2008
    Publication date: February 12, 2009
    Inventors: Lane W. Lee, Timothy R. Feldman
  • Publication number: 20090034722
    Abstract: A method of encrypting data is provided that uses a medium key retrieved from a storage medium. The medium key is combined with another key to generate a combination key. Content is encrypted according to the combination key and written to the storage medium.
    Type: Application
    Filed: April 17, 2008
    Publication date: February 5, 2009
    Inventors: Daniel R. Zaharris, Lane W. Lee
  • Publication number: 20090003608
    Abstract: A block-level storage device is provided that implements a digital rights management (DRM) system. In response to receiving a public key from an associated host system, the storage device challenges the host system to prove it has the corresponding private key to establish trust. This trust is established by encrypting a secure session key using the public key. The host system uses its private key to recover the secure session key. The storage device may store content that has been encrypted according to a content key. In addition, the storage device may encrypt the content key using the secure session key.
    Type: Application
    Filed: September 10, 2008
    Publication date: January 1, 2009
    Inventors: Lane W. Lee, Randal C. Hines, Mark J. Gurkowski, David L. Blankenbeckler
  • Publication number: 20080294914
    Abstract: In one embodiment, a method for authenticating access to encrypted content on a storage medium, wherein the encrypted content is encrypted according to a full disk encryption (FDE) key, the storage medium including an encrypted version of the FDE key and an encrypted version of a protected storage area (PSA) key, and wherein the encrypted version of the FDE key is encrypted according to the PSA key, the method comprising: providing an authenticated communication channel between a host and a storage engine associated with the storage medium; at the storage engine, receiving a pass code from the host over the authenticated communication channel; hashing the pass code to form a derived key, wherein the encrypted version of the PSA key is encrypted according to the derived key; verifying an authenticity of the pass code; if the pass code is authentic, decrypting the encrypted version of the PSA key to recover the PSA key; decrypting the encrypted FDE key using the recovered PSA key to recover the FDE key; and dec
    Type: Application
    Filed: February 5, 2008
    Publication date: November 27, 2008
    Inventors: Lane W. Lee, Mark J. Gurkowski, Randal Hines
  • Patent number: 7310821
    Abstract: A system and method is provided for authenticating a device. A method includes receiving a certificate from the device, the certificate including a plurality of fields, including a field holding a digital signature from a certifying authority, verifying the digital signatures in the certificate, the verifying including at least one of verifying the certifying authority digital signature using the certifying authority public key; and verifying a device digital signature using a device public key, and receiving validation data from a source, the validation data identifying one or more data in the certificate as valid or invalid according to predetermined criteria, and if the digital signatures are verified and validated, transmitting a session key to the device to establish a secure communication channel.
    Type: Grant
    Filed: August 27, 2001
    Date of Patent: December 18, 2007
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Lane W. Lee, Timothy R. Feldman, Douglas M. Rayburn, Gary G. Kiwimagi
  • Patent number: 7110982
    Abstract: A secure electronic content system and method is provided. The system includes a controller including an interface component, a host system coupled to the controller, the host system configured to present content under predetermined conditions, the host system operable with a navigation protocol, the host system further including a system manager operable with an associations component configured to be at least partially run by the host system, a translator configured to provide meanings and generate commands within the host system at least a first digital rights management (DRM) component configured to provide encoding and access rules for the content; and a file system component including a file system application programming interface (API) configured to provide a logical interface between a plurality of components.
    Type: Grant
    Filed: August 27, 2001
    Date of Patent: September 19, 2006
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Timothy R. Feldman, Lane W. Lee, Michael F. Braitberg, Douglas M. Rayburn, Gary G. Kiwimagi
  • Patent number: 7051054
    Abstract: A method and apparatus for storing, updating, adding, deleting, and locating file system objects on a WORM storage medium, wherein information can be written to, but not erased from, the storage medium. The WORM storage medium has a writeable area that includes a system area and a data area. The system area includes system information regarding the file system objects on the storage medium. A system sector is written starting at one end of the system area, while the content of the file system objects is written in the data area starting at another end of the writeable area. When a change is made to the file system objects in the writeable area, an updated system sector is generated that replaces the previous file system information for those modified file system objects. Since the previous system sector is not erasable, the updated system sector is written in a location in the system area where it will be read before any previous system sectors.
    Type: Grant
    Filed: May 30, 2000
    Date of Patent: May 23, 2006
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Lane W. Lee, Michael B. Propps
  • Patent number: 6912189
    Abstract: A method and system for managing a plurality of defects that may cause an error during a write operation in a write-once data storage disk is provided. A host system sends a write command to a disk drive that contains the storage disk. The process detects any errors that may occur during the write operation. When an error is detected, a “skip list” containing the addresses of physical sectors on the disk that are to be skipped during a read operation is updated, the write operation is suspended, and the process attempts to rewrite the data in another sector. If the rewrite is performed successfully, the write operation continues. Otherwise, the write operation is terminated and the host device is notified. While the disk drive is operative, the skip list is preferably maintained in a buffer memory, but periodically the entries in the skip list are copied to the disk for permanent storage. Before a read operation begins, the skip list is copied from the disk to the memory.
    Type: Grant
    Filed: November 18, 2002
    Date of Patent: June 28, 2005
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Michael B. Propps, Lane W. Lee, Stanton M. Keeler
  • Patent number: 6823398
    Abstract: A file system for accessing information on digital storage media is provided by a storage device controller embedded within the storage device. The storage device controller includes an interface component to receive a packet having a file system command. A command decode component in the storage device controller decodes the file system command, and an interface response structure component creates a strategy for performing the file system command. The storage device controller generates an identifier for a file system object and accesses the file system object using the file system object's identifier. A host system coupled to the storage device receives a storage device access request from an application program and generates a command to perform on the file system object based on the storage device access request. The host system uses the identifier to indicate the file system object to be accessed.
    Type: Grant
    Filed: March 31, 2000
    Date of Patent: November 23, 2004
    Assignee: DPHI Acquisitions, Inc.
    Inventors: Lane W. Lee, Michael B. Propps, Daniel R. Zaharris