Patents by Inventor Ravi Sandhu

Ravi Sandhu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8019881
    Abstract: The present invention relates to methods and systems for creating secure cookies. The methods can be used to create, receive, and transmit secure cookies, confidential cookies, and authentication cookies.
    Type: Grant
    Filed: September 28, 2007
    Date of Patent: September 13, 2011
    Assignee: George Mason Intellectual Properties, Inc.
    Inventors: Ravi Sandhu, Joon S. Park
  • Patent number: 7447903
    Abstract: A user has two asymmetric crypto-keys, the first having a first private key and the second having a second private key, both of which are split into a first private key portion corresponding to a password of the user and to a computation. However, the computation of the first private key portion of the first and the second private keys have different levels of complexity. First and second messages from the user encrypted with the first private key portion of, respectively, the first private key and the second private key, are received centrally. A second private key portion of, respectively, the first private key and the second private key is applied to the received first and the received second messages, as applicable, to authenticate the user at, respectively, a first level of authentication security and a second level of authentication security which is greater than the first level.
    Type: Grant
    Filed: June 22, 2006
    Date of Patent: November 4, 2008
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Publication number: 20080052775
    Abstract: The present invention relates to methods and systems for creating secure cookies. The methods can be used to create, receive, and transmit secure cookies, confidential cookies, and authentication cookies.
    Type: Application
    Filed: September 28, 2007
    Publication date: February 28, 2008
    Inventors: Ravi Sandhu, Joon Park
  • Patent number: 7293098
    Abstract: The present invention relates to methods and systems for creating secure cookies. The methods can be used to create, receive, and transmit secure cookies, confidential cookies, and authentication cookies.
    Type: Grant
    Filed: December 19, 2005
    Date of Patent: November 6, 2007
    Assignee: George Mason Unversity
    Inventors: Ravi Sandhu, Joon S. Park
  • Publication number: 20070199053
    Abstract: To authenticate a user of a communications network, credentials from the user are centrally receiving. An authentication sequence is retrieved from a plurality of retrievable authentication sequences, and the retrieved authentication sequence is performed to authenticate the user based on the received credentials.
    Type: Application
    Filed: February 12, 2007
    Publication date: August 23, 2007
    Applicant: TRICIPHER, INC.
    Inventors: Ravi Sandhu, Ravi Ganesan, Andrew Cottrell, Timothy Renshaw, Brett Schoppert, Kyle Austin
  • Patent number: 7149310
    Abstract: A method and system for generating asymmetric crypto-keys usable by network users to transform messages is provided. The system includes a first network station associated with a user, a second network station associated with a trusted entity, and a third network station associated with a sponsor. The trusted entity authorizes the sponsor to generate the asymmetric crypto-key. The sponsor generates a symmetric crypto-key and associated user identification. The sponsor both stores the generated symmetric crypto-key and the associated user identification and transmits the symmetric crypto-key and the associated user identification to the trusted entity. The trusted entity then distributes the symmetric crypto-key and user identification to the user. The user then presents the user identification to the sponsor. The sponsor then generates a challenge and transforms the challenge with the stored symmetric crypto-key. The sponsor transmits the transformed challenge to the user.
    Type: Grant
    Filed: December 19, 2000
    Date of Patent: December 12, 2006
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Publication number: 20060248333
    Abstract: A user has two asymmetric crypto-keys, the first having a first private key and the second having a second private key, both of which are split into a first private key portion corresponding to a password of the user and to a computation. However, the computation of the first private key portion of the first and the second private keys have different levels of complexity. First and second messages from the user encrypted with the first private key portion of, respectively, the first private key and the second private key, are received centrally. A second private key portion of, respectively, the first private key and the second private key is applied to the received first and the received second messages, as applicable, to authenticate the user at, respectively, a first level of authentication security and a second level of authentication security which is greater than the first level.
    Type: Application
    Filed: June 22, 2006
    Publication date: November 2, 2006
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Patent number: 7069435
    Abstract: A system for authentication of a crypto-system user by the use of both symmetric and asymmetric crypto-keys is provided. A first network station, representing the user, transmits a first request for authentication to a second network station. The second station generates a shared symmetric crypto-key, encrypts it and forwards it to both the first station and a third network station. The third station encrypts the received shared symmetric crypto-key and forwards it to the first network station. The first network station combines the two instances of the received and encrypted shared symmetric crypto-key, decrypts the combined symmetric crypto-key to recover shared symmetric crypto-key, encrypts a second authentication request with the recovered shared symmetric crypto-key, and transmits the encrypted authentication request to authenticate the first station.
    Type: Grant
    Filed: December 19, 2000
    Date of Patent: June 27, 2006
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Patent number: 7065642
    Abstract: A system for authentication of network users which is operable in multiple modes, includes a plurality of user network stations and at least one sponsor network station representing a sponsor. Each network station represents a user associated with an asymmetric crypto-key having either a first or second number of private portions, the second number being greater than the first number. The one or more sponsor network stations receive authentication requests from the user network stations, determine the identity of a user associated with each of the received authentication requests, select from two or more available modes of operation based upon the determined identity. If operation in one mode is selected, the sponsor network station signs a particular received authentication request using one private portion of an asymmetric crypto-key having a first number of private portions.
    Type: Grant
    Filed: December 19, 2000
    Date of Patent: June 20, 2006
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Patent number: 7055032
    Abstract: A system for accessing multiple different network stations without entry of a password is provided. The password is obtainable by use of a portion of an asymmetric crypto-key. A first station, representing any network entity, transmits an authentication request of a user seeking access. A second station, representing the user, forwards the request and user identity information to a third station. The third station, representing a sponsor, matches the transmitted identity information with stored identity information, generates a certificate, and transmits the certificate. The second station further transmits the certificate to the first station.
    Type: Grant
    Filed: May 21, 2004
    Date of Patent: May 30, 2006
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Publication number: 20060101114
    Abstract: The present invention relates to methods and systems for creating secure cookies. The methods can be used to create, receive, and transmit secure cookies, confidential cookies, and authentication cookies.
    Type: Application
    Filed: December 19, 2005
    Publication date: May 11, 2006
    Inventors: Ravi Sandhu, Joon Park
  • Patent number: 7017041
    Abstract: A communications network is provided for securing communications and updating user identity information. A symmetric crypto-key, an asymmetric crypto-key having first and second private key portions and a public key portion, and a certificate are utilized. A first network station, representing any network entity, transmits a user authentication request. A second network station, representing the user, forwards, either jointly or separately, the request and user identity information to a third network station. The third network station, representing a sponsor, matches the transmitted identity information with stored identity information, modifies the stored identity information to correspond to the received identity information, generates a certificate including the modified identity information, and transmits the certificate and the request. The second station further transmits the certificate to the first station.
    Type: Grant
    Filed: December 19, 2000
    Date of Patent: March 21, 2006
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Patent number: 6985953
    Abstract: The present invention relates to methods and systems for creating secure cookies. The methods can be used to create, receive, and transmit secure cookies, confidential cookies, and authentication cookies.
    Type: Grant
    Filed: November 30, 1999
    Date of Patent: January 10, 2006
    Assignee: George Mason University
    Inventors: Ravi Sandhu, Joon S. Park
  • Patent number: 6970562
    Abstract: A first processor generates a private crypto-key and a public crypto-key. The first processor divides the private crypto-key into two portions, a first private key portion, based upon a user's password, and a second private key portion. The private crypto-key and the first private key portion are then destroyed. The remaining portion, second private key portion, and the public crypto-key are stored in a memory. A second processor generates the first private key portion based upon the user's password and responsive to receiving the user's password. The second processor then destroys the generated first private key portion with out storing the generated first private key portion.
    Type: Grant
    Filed: December 19, 2000
    Date of Patent: November 29, 2005
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Patent number: 6940980
    Abstract: A network device represents a user having a predefined associated password, a predefined associated symmetric crypto-key and a predefined associated asymmetric crypto-key, including a first private key portion, a second private key portion and a public key portion. The device includes a memory, input device and processor. The memory stores a function. The input device allows the inputting of the user password. The processor operates in either a first or second mode of operation. In the first mode of operation, the processor processes the input password in accordance with the stored function to generate the associated first private key portion, and encrypts and/or decrypts or signs a message with the generated first private key portion. In a second mode of operation, the processor processes the input password in accordance with the same stored function to generate the associated symmetric crypto-key, and encrypts and/or decrypts and/or authenticates a message with the generated symmetric crypto-key.
    Type: Grant
    Filed: December 19, 2000
    Date of Patent: September 6, 2005
    Assignee: TriCipher, Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Patent number: 6883095
    Abstract: A method for authenticating a user includes receiving a request for access from a user claiming to be a particular user. A first challenge having a first level of complexity is transmitted to the user. A response to the transmitted first challenge is transmitted. A determination is made as to whether or not the transmitted response authenticates the user as the particular user. The requested access by the user is allowed if the transmitted response authenticates the user. However, a second challenge having a second level of complexity, greater than the first level of complexity, is transmitted to the user if the transmitted response does not authenticate the user.
    Type: Grant
    Filed: December 19, 2000
    Date of Patent: April 19, 2005
    Assignee: SingleSigon. Net Inc.
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Publication number: 20050027989
    Abstract: A system for accessing multiple different network stations without entry of a password is provided. The password is obtainable by use of a portion of an asymmetric crypto-key. A first station, representing any network entity, transmits an authentication request of a user seeking access. A second station, representing the user, forwards the request and user identity information to a third station. The third station, representing a sponsor, matches the transmitted identity information with stored identity information, generates a certificate, and transmits the certificate. The second station further transmits the certificate to the first station.
    Type: Application
    Filed: May 21, 2004
    Publication date: February 3, 2005
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Publication number: 20030115452
    Abstract: A system for accessing multiple different network stations without entry of a password includes first, second and third network stations. The first network station represents a network entity and transmits a request for authentication of a user seeking access. The user has an associated password, identifier and asymmetric crypto-key, including a first private key portion obtainable with the password, a second private key portion and a public key portion. A second network station represents the user and has a user identifier, a combination symmetric crypto-key corresponding to a first symmetric crypto-key and a second symmetric crypto-key, and the first private key portion encrypted with the first symmetric crypto-key stored thereat. In response to the authentication request, this station (i) transmits the stored user identifier MAC'd with the stored combination symmetric key, and (ii) transmits the transmitted authentication request encrypted with the stored combination symmetric crypto-key.
    Type: Application
    Filed: December 19, 2000
    Publication date: June 19, 2003
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Publication number: 20020076042
    Abstract: A first processor generates a private crypto-key and a public crypto-key. The first processor divides the private crypto-key into two portions, a first private key portion, based upon a user's password, and a second private key portion. The private crypto-key and the first private key portion are then destroyed. The remaining portion, second private key portion, and the public crypto-key are stored in a memory. A second processor generates the first private key portion based upon the user's password and responsive to receiving the user's password. The second processor then destroys the generated first private key portion with out storing the generated first private key portion.
    Type: Application
    Filed: December 19, 2000
    Publication date: June 20, 2002
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan
  • Publication number: 20020078346
    Abstract: A communications network is provided for securing communications of a user having a password, an identifier, a symmetric crypto-key, and an asymmetric crypto-key, including a first private key portion, a second private key portion and a public key portion. The network includes a first network station, representing any network entity, a second network station, representing the user, and a third network station, representing a sponsor. The first network station transmits a request for authentication of the user. The second network station, which stores the user identifier and the symmetric crypto-key, transmits the identifier and also transmits, either jointly or separately the authentication request and information relating to the identity of the user, both encrypted with the symmetric crypto-key stored at the second network station.
    Type: Application
    Filed: December 19, 2000
    Publication date: June 20, 2002
    Inventors: Ravi Sandhu, Colin deSa, Karuna Ganesan