Patents by Inventor Shawn R. Lohstroh

Shawn R. Lohstroh has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 6408389
    Abstract: A system is disclosed for controlling intelligible access to secured files by means of a user-memorized password in combination with a user-associated passport record. The passport record takes on two forms, one when it is physically secured within the workstation and a different second form when the passport record is in-transit. Log-in privileges are granted after a presented passport record passes a number of tests including digital signature authentication, and the ability to extract two different encrypted keys from the passport record. The in-transit record does not carry one of those two keys.
    Type: Grant
    Filed: December 5, 2000
    Date of Patent: June 18, 2002
    Assignee: Symantec Corporation
    Inventors: David Grawrock, Shawn R. Lohstroh
  • Patent number: 6339828
    Abstract: A system is disclosed for controlling intelligible access to secured files by means of a user-memorized password in combination with a user-associated passport record. The passport record takes on two forms, one when it is physically secured within the workstation and a different second form when the passport record is in-transit. Log-in privileges are granted after a presented passport record passes a number of tests including digital signature authentication, and the ability to extract two different encrypted keys from the passport record. The in-transit record does not carry one of those two keys.
    Type: Grant
    Filed: May 3, 2000
    Date of Patent: January 15, 2002
    Assignee: Symantec Corporation
    Inventors: David Grawrock, Shawn R. Lohstroh
  • Publication number: 20010002487
    Abstract: A system is disclosed for controlling intelligible access to secured files by means of a user-memorized password in combination with a user-associated passport record. The passport record takes on two forms, one when it is physically secured within the workstation and a different second form when the passport record is in-transit. Log-in privileges are granted after a presented passport record passes a number of tests including digital signature authentication, and the ability to extract two different encrypted keys from the passport record. The in-transit record does not carry one of those two keys.
    Type: Application
    Filed: December 5, 2000
    Publication date: May 31, 2001
    Applicant: Symantec Corporation
    Inventors: David Grawrock, Shawn R. Lohstroh
  • Patent number: 6081893
    Abstract: A system is disclosed for controlling intelligible access to secured files by means of a user-memorized password in combination with a user-associated passport record. The passport record takes on two forms, one when it is physically secured within the workstation and a different second form when the passport record is in-transit. Log-in privileges are granted after a presented passport record passes a number of tests including digital signature authentication, and the ability to extract two different encrypted keys from the passport record. The in-transit record does not carry one of those two keys.
    Type: Grant
    Filed: May 28, 1997
    Date of Patent: June 27, 2000
    Assignee: Symantec Corporation
    Inventors: David Grawrock, Shawn R. Lohstroh
  • Patent number: 5953419
    Abstract: A system is disclosed for automatically distributing secured versions (*Sys.sub.-- D.sub.-- key*) of a file decryption key (Sys.sub.-- D.sub.-- key) to a plurality of file users by way of the file's security label. The label is defined to contain a plurality of Access-Control-Entries Records (ACER's) where each ACER includes a respective secured version (*Sys.sub.-- D.sub.-- key*) of the file decryption key. Each such secured version (*Sys.sub.-- D.sub.-- key*) is decipherable by a respective ACER private key. Each ACER may include respective other data such as:(a) ACER-unique identifying data for uniquely identifying the ACER or an associated user;(b) decryption algorithm identifying data for identifying the decryption process to be used to decrypt the encrypted *DATA* portion of the file; and(c) special handling code for specifying special handling for the code-containing ACER.
    Type: Grant
    Filed: May 6, 1996
    Date of Patent: September 14, 1999
    Assignee: Symantec Corporation
    Inventors: Shawn R. Lohstroh, William D. McDonnal, David Grawrock
  • Patent number: 5768373
    Abstract: The present invention is directed toward providing a secure method to access data when the user has lost or forgotten the user password. In accordance with the invention and in a system where decryption of an access key will give access to data, two encrypted versions of the access key are created. A first version is formed using a key formed with the user password. A second version is formed using a public key from a public-private key pair. Generally, data access can be had by decrypting the first encrypted version of the access key with the password key. However, if the password is forgotten, access to data can be accomplished by decrypting the second encrypted version of the access key with the private key from the public-private key pair. One embodiment of the invention requires the private key to be stored at a remote site and for decryption using the private key to take place at the remote site. In this manner the user can gain access to data without significantly compromising the data security.
    Type: Grant
    Filed: May 6, 1996
    Date of Patent: June 16, 1998
    Assignee: Symantec Corporation
    Inventors: Shawn R. Lohstroh, David Grawrock