By Generation Of Certificate Patents (Class 713/175)
  • Patent number: 7260836
    Abstract: A system and method for distributed authentication service is disclosed, which prevents any single participant from monitoring the logon rates of other participants is disclosed. In particular, there is no single central list that is consulted to identify where the authentication should be performed. Rather, the systems keys on the domain portion of the global user ID. The client portion parses the entered ID and re-directs the submission to the appropriate authentication service. Rather than consulting a global look-up table, the domain name is pre-pended to a central host domain and DNS is consulted to find the location of the underlying authentication servers. The DNS look-up is distributed and cached and, as a result, the look-up cannot be centrally monitored.
    Type: Grant
    Filed: February 26, 2002
    Date of Patent: August 21, 2007
    Assignee: AOL LLC
    Inventors: Jim Roskind, Chris Toomey
  • Patent number: 7257836
    Abstract: A method for setting up and managing secure data/audio/video links with secure key exchanges, authentication and authorization is described. An embodiment of the invention enables establishment of a secure link with limited privileges using the machine identifier of a trusted machine. This is particularly useful if the user of the machine does not have a user identifying information suitable for authentication. Furthermore, the presentation of a default user identifying information by a user advantageously initiates intervention by a system administrator instead of a blanket denial. This decentralized procedure allows new users access to the network without having to physically access a centralized facility to present their credentials. Another embodiment of the invention enables a remote user to connect to a secure network with limited privileges.
    Type: Grant
    Filed: October 23, 2000
    Date of Patent: August 14, 2007
    Assignee: Microsoft Corporation
    Inventors: Timothy M. Moore, Arun Ayyagari, Sachin C. Sheth, Pradeep Bahl
  • Publication number: 20070186110
    Abstract: An information processing apparatus includes: a data processing unit that acquires content codes including a data processing program recorded in an information recording medium and executes data processing according to the content codes; and a memory that stores an apparatus certificate including an apparatus identifier of the information processing apparatus. The data processing unit is configured to execute an apparatus checking process applying the apparatus certificate stored in the memory on the basis of a code for apparatus checking process included in the content codes, acquire the apparatus identifier recorded in the apparatus certificate after the apparatus checking process, and execute data processing applying content codes corresponding to the acquired apparatus identifier.
    Type: Application
    Filed: January 25, 2007
    Publication date: August 9, 2007
    Applicant: Sony Corporation
    Inventor: Yoshikazu Takashima
  • Patent number: 7254711
    Abstract: A certificate authority for certifying the validity of the collation result from a user terminal is placed on a communication network. The user terminal identifies a user himself or herself by collation by using biometrical information of the user. In response to notification of the collation result from the user terminal across the communication network, a service providing apparatus requests across the communication network the certificate authority to certify the validity of the collation result. When a certificate which certifies the validity of the collation result is notified from the certificate authority across the communication network, the service providing apparatus provides a predetermined service to the user.
    Type: Grant
    Filed: April 4, 2002
    Date of Patent: August 7, 2007
    Assignee: Nippon Telegraph and Telephone Corporation
    Inventors: Satoshi Shigematsu, Mamoru Nakanishi, Hiroki Suto
  • Patent number: 7249380
    Abstract: A W3 Trust Model is described for evaluating trust and transitivity of trust of online services. By introducing a set of trust attributes for each web document, the W3 Trust Model combines a vertically trusted public key infrastructure with a horizontal referral web classification. It provides a mechanism to assess both the trust and the transitivity of trust of web contents in a heterogeneous environment. The trust attributes are categorized in three categories: a first category which relates to contents of the web document, a second category which relates to owner of the web document, and a third category which relates to relationships of the web document and certificate authorities.
    Type: Grant
    Filed: September 5, 2003
    Date of Patent: July 24, 2007
    Inventor: Yinan Yang
  • Patent number: 7246238
    Abstract: A network system providing integration. The network system includes a client computer, a server, a server-side cryptographic function, a PKI-Bridge, a remote access switch, a client-side cryptographic function, a dial-up client, and a custom script dynamically linked library. The server-side cryptographic function is located on the server and provides cryptographic services. The PKI-Bridge provides an interface between the server and the server-side cryptographic function. The remote access switch provides an interface between the client computer and the server. The client-side cryptographic function is located on the client computer and provides cryptographic services. The dial-up client provides dial-up services to access the remote access switch. The custom script dynamically linked library provides an interface between the dial-up client and the client-side cryptographic function.
    Type: Grant
    Filed: October 18, 2001
    Date of Patent: July 17, 2007
    Assignee: Schlumberger Omnes, Inc.
    Inventors: Glen H. Mullen, Matthew T. Novi, Shaun E. Neumann, Abdullah Zahur, Alexander J. C. Gaulene, Sacha Dawes, Johann Bazzali
  • Patent number: 7243238
    Abstract: Disclosed are a person authentication system, a person authentication method, and an information processing apparatus which allow person authentication to be performed in an easy fashion in various devices by comparing a template serving as person identification data with sampling information input by a user. A service provider (SP) or user device (UD) executes person authentication by acquiring a template from a person identification certificate (IDC) generated by a third-party agency serving as a person identification certificate authority (IDA). The IDA acquires a template serving as identification data after verifying a person requesting an IDC to be issued, and generates the IDC storing template information. The IDA distributes the IDC having a digital signature of the IDA added thereto to the SP and the UD.
    Type: Grant
    Filed: August 30, 2001
    Date of Patent: July 10, 2007
    Assignee: Sony Corporation
    Inventors: Hideaki Watanabe, Yoshihito Ishibashi, Shinako Matsuyama, Ichiro Futamura, Masashi Kon
  • Patent number: 7228439
    Abstract: A method for storing an event encrypted by control words guarantees access to this event at any moment, even if identities of these events are modified between storage and the moment of viewing. The method is performed in a reception and decryption unit connected to a security unit, the control words and the necessary rights being contained in control messages the method comprising the steps of storing the encrypted event and associated control messages in the storage unit; transmitting the control messages to the security unit; verifying if the access rights to this event are contained in the security unit and, if so, calculating a receipt of all or part of the control message using a secret unique key contained in the security unit; and storing the receipt in the storage unit.
    Type: Grant
    Filed: December 17, 2002
    Date of Patent: June 5, 2007
    Assignee: Nagravision S.A.
    Inventor: Marco Sasselli
  • Patent number: 7225337
    Abstract: A portable electronic security module including an electronic data storage device, a secret private customer key and a public customer key stored in the electronic data storage device as a first digital key pair, a signature module configured to generate a digital customer signature from object data to be signed using the secret private customer key, a secret private key of a security provider and a public key of the security provider stored in the electronic data storage device as a second digital key pair, and a certification module, installed in the signature module, and configured to generate a digital signature certificate from the digital customer signature using the secret private key of the security provider.
    Type: Grant
    Filed: May 23, 2003
    Date of Patent: May 29, 2007
    Assignee: Swisscom Mobile AG
    Inventor: Felix Baessler
  • Patent number: 7222119
    Abstract: A system may perform a first operation within a file system in which directories and files are organized as nodes in a namespace tree. The system may associate a read-write lock with each of the nodes in the namespace tree. The system may acquire a first lock on a name of one or more directories involved in the first operation, acquire a second lock on an entire pathname involved in the first operation, determine whether the first lock or the second lock conflicts with third locks acquired by a second operation, and perform the first operation when the first lock or the second lock does not conflict with the third locks. The first, second, and third locks may include read-write locks.
    Type: Grant
    Filed: June 30, 2003
    Date of Patent: May 22, 2007
    Assignee: Google Inc.
    Inventors: Sanjay Ghemawat, Howard Gobioff, Shun-Tak Leung
  • Patent number: 7213262
    Abstract: In accordance with the invention, a presenter of credentials presents to a recipient of credentials one or more chains of group credentials to prove entity membership or non-membership in a nested group in a computer network. The ability to present a chain of credentials is particularly important when a client is attempting the prove membership or non-membership in a nested group and one or more of the group servers in the family tree are off-line. A chain of group credentials includes two or more proofs of group membership and/or proofs of group non-membership Furthermore, the proofs of group membership may include one or more group membership certificates and/or one or more group membership lists; and proofs of group non-membership may include one or more group non-membership certificates and/or one or more group membership lists.
    Type: Grant
    Filed: May 10, 1999
    Date of Patent: May 1, 2007
    Assignee: Sun Microsystems, Inc.
    Inventors: Yassir K. Elley, Anne H. Anderson, Stephen R. Hanna, Sean J. Mullan, Radia J. Perlman
  • Patent number: 7209889
    Abstract: A transaction network contains a networked certificate authority, by which one or more virtual certificates may be remotely defined and stored, such as by an issuer user through a issuer web portal interface. An acquirer user, through an acquirer web portal interface, may acquire one or more virtual certificates, which contain a public key portion, as well as a corresponding private key, which is established at the time of acquisition, and is stored at the certificate authority. At a redemption location associated with an acquired certificate, the acquirer (or an alternate recipient of an acquired certificate to whom the acquirer has communicated the established private key), submits the certificate information, along with the established private key, to redeem the certificate.
    Type: Grant
    Filed: December 20, 1999
    Date of Patent: April 24, 2007
    Inventor: Henry Whitfield
  • Patent number: 7210037
    Abstract: One embodiment of the present invention provides a system that facilitates delegating operations involved in providing digital signatures to a signature server. The system operates by receiving a request for a digital signature from a user at the signature server, wherein the request includes an item to be signed on behalf of the user by the signature server. In response to the request, the system looks up a private key for the user at the signature server, and signs the item with the private key. Next, the system returns the signed item to the user, so that the user can send the signed item to the recipient. In one embodiment of the present invention, the system authenticates the user prior to signing the item. In one embodiment of the present invention, the system determines whether the user is authorized to sign the item prior to signing the item.
    Type: Grant
    Filed: December 15, 2000
    Date of Patent: April 24, 2007
    Assignee: Oracle International Corp.
    Inventor: Vipin Samar
  • Patent number: 7203657
    Abstract: A method and system to enable data packets to engage in two-way transactions with various facilities, electronic equipment, and data sources, performing various services. This is accomplished by the loading of data packets with access tokens, denominated at certain values and issued by certain institutions. These tokens are then transferred, according to the instructions of a packet controller that is part of a packet, and according to the interaction of packet controller and facility gateway access controller, from packets to facilities (or vice versa) that provide services, and are redeemed by the facility or the source of the packet. This system enables information, communication, and general commercial activities by establishing a generalized mechanism for payment, transactions, negotiation, and differentiation on the packet level.
    Type: Grant
    Filed: September 5, 2000
    Date of Patent: April 10, 2007
    Inventor: Eli M. Noam
  • Patent number: 7194628
    Abstract: A method for group authentication using a public key cryptosystem that includes a public key and a private key, comprising the steps of providing a Private Key Share to a Tool of each Entity of each Group encompassed by a Boolean Expression of a prescribed Rule based upon the private key, encrypting a random number using the public key of the public key cryptosystem to generate a ciphertext challenge at a Verification Device, conveying the ciphertext challenge to the Tool of each Entity in communication with the Verification Device, generating a response to the ciphertext challenge using the Private Key Share of the Tool of each Entity in communication with the Verification Device, transmitting the response generated by each Entity in communication with the Verification Device to the Verification Device, combining the responses received from the Entities in communication with the Verification Device, determining whether any combination of the responses equals the random number wherein any combination that equ
    Type: Grant
    Filed: April 29, 2003
    Date of Patent: March 20, 2007
    Assignee: Mobile-Mind, Inc.
    Inventor: Scott B. Guthery
  • Patent number: 7188361
    Abstract: A method and/or system for transmitting sequences of signals/data from a transmitter to a receiver and for authenticating the sequences of signals/data may consist of a precalculation phase and of a communication phase in which the signals are transmitted together with the checking sums. In the precalculation phase, a pseudo-random sequence may be first generated by means of a cryptographic algorithm from a time-variable parameter and other initialization data. Non-overlapping sections (z(1) of a sequence (z) having each m bits may be associated to signals (s(i)), wherein i=1, 2, . . . n, of a signal storage. Further non-overlapping m bit sections (t(i)) of the remaining sequence may be selected for coding numbers (1, 2, . . . MAX). The transmitter may transmit the initialization information and the time-variable parameters to the receiver and the receiver may calculate the pseudo-random sequence (z) and checks the receiver authentication token (T).
    Type: Grant
    Filed: September 17, 1997
    Date of Patent: March 6, 2007
    Assignee: Deutsche Telekom AG
    Inventors: Alfred Scheerhorn, Klaus Huber
  • Patent number: 7185194
    Abstract: A system of distributed group management for generating authentication information relating to a group to which users belong at a high speed on a client side and, at the same time, wherein a server side can verify this at a high speed. This system provides a group certificate issuing apparatus for issuing a group certificate on a client side based on original group information including the name of the group to which the users belong and a group certificate verification unit for verifying a legitimacy of the certificate transmitted from the client side in a server.
    Type: Grant
    Filed: May 16, 2001
    Date of Patent: February 27, 2007
    Assignee: Fujitsu Limited
    Inventors: Ikuya Morikawa, Makoto Minoura, Kenichi Fukuda
  • Patent number: 7185195
    Abstract: In accordance with one embodiment of the present invention, a digital certificate is used to link an arbitrary provisioned right with an associated arbitrary digital action to be performed by a client device on or with respect to a protected digital content object. In one embodiment, the certificate is associated with one or more secure components, which are utilized by the client device in association with performance of the digital action.
    Type: Grant
    Filed: December 14, 2003
    Date of Patent: February 27, 2007
    Assignee: Realnetworks, Inc.
    Inventors: Joshua D. Hug, Xiaodong Fu
  • Patent number: 7181603
    Abstract: Redirecting function calls through a protected environment to effect secure linkage of program modules. In one embodiment, a program module, such as a player application for example, may make function calls to secure functions instead of to insecure operating system (OS) services, thereby deterring attacks on the player's calls to OS services. In one embodiment, the new secure functions provide similar functionality to the replaced OS services. Providing a securely loaded function for calling by a program module in place of calling an insecure OS function includes obtaining object code for the securely loaded function from a signed binary description file, performing signature and integrity verification of the program module using the signed binary description file, loading the object code for the securely loaded function into memory, and updating an address for calling the securely loaded function by the program module.
    Type: Grant
    Filed: March 12, 2002
    Date of Patent: February 20, 2007
    Assignee: Intel Corporation
    Inventors: Lewis V. Rothrock, Richard L. Maliszewski
  • Patent number: 7178029
    Abstract: Method and system are described for validating a digital signature. More particularly, a signed message and a corresponding certificate are received. The certificate is checked for validation. A validation statement is generated, and the certificate validation and the signed message provide a status. This status represents a request for validation, and is provided along with a set of validations among which such status is an element. A digest is generated using a Merkle authentication tree corresponding to the set of validations, and this digest is signed with a private key. Accordingly, a notary may provide the signed digest, status and the set of validations for subsequent confirmation of the digital signature.
    Type: Grant
    Filed: February 9, 2001
    Date of Patent: February 13, 2007
    Assignee: Privador, Ltd
    Inventors: Arne Ansper, Ahto Buidas, Meelis Roos, Jan Villemson
  • Patent number: 7174563
    Abstract: A computer network security system and method utilizes digitally signed and centrally assigned policy data, such as password length rules, that is unilaterally enforced at network nodes by node policy enforcement engines. The policy data may be variable on a per client or network node basis through a centralized authority, such as a certification authority. The computer network security system provides variable security policy rule data for distribution to at least one network node through a central security policy rule data distribution source, such as the certification authority. The central security policy rule data distribution source associates a digital signature to the variable security policy rule data to ensure the integrity of the policies in the system. Each network node uses a policy rule data engine and policy rule table to decode policy rule data and enforce the policy rules as selectively determined through the central authority.
    Type: Grant
    Filed: November 1, 2000
    Date of Patent: February 6, 2007
    Assignee: Entrust, Limited
    Inventors: Michael Brownlie, Stephen Hillier, Paul C. Van Oorschot
  • Patent number: 7174021
    Abstract: A key management interface that allows for different key protection schemes to be plugged into a digital rights management system is disclosed. The interface exposes the functionality of signing data, decrypting data encrypted using a public key, and re-encrypting data encrypted using the public key exported by the interface to a different authenticated principal (i.e., a different public key). Thus, a secure interface can be provided such that the data does not enter or leave the interface in the clear. Such an interface exports private key operations of signing and decryption, and provides security and authentication for the digital asset server in licensing and publishing. During publishing, a client can encrypt asset keys such that only a specified entity can decrypt it, using a plug-in, for example, that implements the aforementioned interface.
    Type: Grant
    Filed: June 28, 2002
    Date of Patent: February 6, 2007
    Assignee: Microsoft Corporation
    Inventors: Vinay Krishnaswamy, Attila Narin, Gregory Kostal, Vladimir Yarmolenko, Scott C. Cottrille
  • Patent number: 7174456
    Abstract: A fast authentication and access control method of authenticating a network access device to a communications network having an access point communicating with a remote authentication (home AAA) server for the network access device. The method includes the step of receiving an access request having an authentication credential from the network access device at the access point. The authentication credential includes a security certificate having a public key for the network access device and an expiration time. The security certificate is signed with a private key for the remote authentication server. The access point locally validates the authentication credential by accessing the public key of the remote authentication server from a local database, and checking the signature and expiration time of the security certificate.
    Type: Grant
    Filed: May 14, 2002
    Date of Patent: February 6, 2007
    Assignee: AT&T Corp.
    Inventors: Paul Shala Henry, Zhimei Jiang, Hui Luo
  • Patent number: 7171000
    Abstract: A system for securely transmitting an information package (10) to an addressee via a network (108) includes a directory interface (110) adapted to check a directory (112) to determine whether the addressee has a public key; an escrow key manager (116), coupled to the directory interface (110), adapted to provide an escrow encryption key for encrypting the package (10); a encryption module (114), coupled to the escrow key manager (116), adapted to encrypt the package (10) with the escrow encryption key; a computer-readable medium (118), coupled to the encryption module (114), adapted to store the package (10) in escrow for the addressee; a notification module (120), coupled to the computer-readable medium (118), adapted to send a notification to the addressee via the network (108); a key registration module (124), coupled to the notification module (120), adapted to issue, in response to the addressee acknowledging the notification, new public and private keys to the addressee; and a transmission module (122),
    Type: Grant
    Filed: June 10, 1999
    Date of Patent: January 30, 2007
    Assignee: Message Secure Corp.
    Inventors: Eng-Whatt Toh, Peng-Toh Sim
  • Patent number: 7171556
    Abstract: A virtual private network (VPN) enrollment protocol gateway is described herein. The protocol gateway is implemented as a registration authority that operates as an intermediary between routers and a certificate authority, allowing routers operating in accordance with one protocol to obtain and maintain certificates for a VPN from a certificate authority operating in accordance with another protocol. In accordance with one aspect, the gateway protocol supports various requests from the router, including router enrollment requests, get certificate revocation list request, get certificate requests, get certificate authority certificate requests, and password requests.
    Type: Grant
    Filed: May 20, 2005
    Date of Patent: January 30, 2007
    Assignee: Microsoft Corporation
    Inventors: Rudolph Balaz, Victor W. Heller, Xiaohong Su, Keith R. Vogel
  • Patent number: 7167985
    Abstract: A system and method for providing trusted browser verification services. In a preferred embodiment, these services are provided within the context of a four-corner trust model comprising a subscribing customer and a relying customer, engaged in an on-line transaction. The subscribing and relying customers are preferably customers of first and second financial institutions, respectively, that issue to them hardware tokens for their respective private keys and digital certificates. The buyer is preferably provided with a Web browser to conduct electronic transactions. A distinct-trusted verifier or other entity ensures in a verifiable manner that the browser used by the subscribing customer does not contain any code that is not trusted by verifying the digital signatures on each running browser component of the subscribing customer's browser and ensuring that the signature was applied by an entity that is authorized to certify the trustworthiness of the component.
    Type: Grant
    Filed: April 30, 2001
    Date of Patent: January 23, 2007
    Assignee: Identrus, LLC
    Inventor: Khaja Ahmed
  • Patent number: 7159114
    Abstract: An automated banking machine (12, 200, 302) is provided. The machine may be operative to install a terminal master key (TK) therein in response to at least one input from a single operator. The machine may include an EPP (204) that is operative to remotely receive an encrypted terminal master key from a host system (210, 304). The machine may authenticate and decrypt the terminal master key prior to accepting the terminal master key. The machine may further output through a display device (30) of the machine a one-way hash of at least one public key associated with the host system. The machine may continue with the installation of the terminal master key in response to an operator confirming that the one-way hash of the public key corresponds to a value independently known by the operator to correspond to the host system.
    Type: Grant
    Filed: April 19, 2002
    Date of Patent: January 2, 2007
    Assignee: Diebold, Incorporated
    Inventors: Timothy Zajkowski, Anne Doland, Mark D. Smith
  • Patent number: 7152158
    Abstract: The present invention provides a novel configuration which allows devices capable of processing different signature algorithms to mutually verify public key certificates. In this configuration, public key certificates storing plural signatures based on different signature algorithms such as RSA and ECC are issued and each device selects a signature which can be processed (namely, verified) by itself and verifies the selected signature.
    Type: Grant
    Filed: January 9, 2002
    Date of Patent: December 19, 2006
    Assignee: Sony Corporation
    Inventors: Hideaki Watanabe, Yoshihito Ishibashi, Shinako Matsuyama, Ichiro Futamura, Masashi Kon, Makoto Oka
  • Patent number: 7143286
    Abstract: The present invention provides a digital certificate (2, 32), the certificate comprising a credential attribute function (6, 38) associated with a credential attribute property (5, 36), which credential attribute function is embedded in the certificate as an executable file, in which the credential attribute function can determine the value (12, 44) of the credential attribute property at least partly by execution of the executable file. A corresponding method is also disclosed.
    Type: Grant
    Filed: February 15, 2002
    Date of Patent: November 28, 2006
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Richard Brown, Marco Casassa Mont
  • Patent number: 7143165
    Abstract: An update process is used to update root certificates in a root certificate store of a client computer, maintaining the integrity of the existing root certificates as well as any new root certificates. In accordance with certain aspects, the integrity of a certificate trust list identifying one or more root certificates is verified. The root certificate store of the client computer is modified in accordance with the certificate trust list if the integrity of the certificate trust list is verified.
    Type: Grant
    Filed: October 18, 2004
    Date of Patent: November 28, 2006
    Assignee: Microsoft Corporation
    Inventors: Keith R. Vogel, Charlie D. Chase, Kelvin S. Yiu, Philip J. Hallin, Louis K. Thomas
  • Patent number: 7143285
    Abstract: A method for creating a proof of possession confirmation for inclusion by a certification authority into a digital certificate, the digital certificate for use by an end user, is disclosed. In an exemplary embodiment of the invention, the method includes receiving from the certification authority, in response to a certificate request by the end user, a plurality of data fields corresponding to a target host system, the end user, and a form of proof of identity possession by the end user. The content of the plurality of data fields is analyzed and the accuracy thereof is verified. If the plurality of data fields is verified as accurate, then a signed object is sent to the certification authority, the signed object comprising the proof of possession confirmation.
    Type: Grant
    Filed: May 22, 2001
    Date of Patent: November 28, 2006
    Assignee: International Business Machines Corporation
    Inventors: Thomas L. Gindin, Messaoud Benantar, James W. Sweeny, John C. Dayka
  • Patent number: 7139911
    Abstract: A method of certifying a host-identification mapping extension included in a digital certificate, the digital certificate issued and signed by a specific certification authority. In an exemplary embodiment of the invention, the method includes assigning a trust value for each certification authority included in a set of certification authorities. A digital certificate containing the host-identification mapping extension therein is received, with the host-identification mapping extension further containing a plurality of identification attributes therein. The plurality of identification attributes are evaluated, along with the trust value assigned to the specific certification authority issuing the digital certificate. A determination is then made, based upon the plurality of identification attributes and the trust value, as to whether the host-mapping extension is to be certified.
    Type: Grant
    Filed: February 28, 2001
    Date of Patent: November 21, 2006
    Assignee: International Business Machines Corporation
    Inventors: James W. Sweeny, Messaoud Benantar, John J. Petreshock, Thomas L. Gindin, John C. Dayka
  • Patent number: 7139915
    Abstract: A secure communication channel between an open system and a portable IC device is established. An application running on the open system desiring access to the information on the portable IC device authenticates itself to the portable IC device, proving that it is trustworthy. Once such trustworthiness is proven, the portable IC device authenticates itself to the application. Once such two-way authentication has been completed, trusted communication between the open system and the portable IC device can proceed, and private information that is maintained on the portable IC device can be unlocked and made available to the application.
    Type: Grant
    Filed: October 19, 2005
    Date of Patent: November 21, 2006
    Assignee: Microsoft Corporation
    Inventor: John D. DeTreville
  • Patent number: 7133846
    Abstract: The present inventions provide an integrated, modular array of administrative and support services for electronic commerce and electronic rights and transaction management. These administrative and support services supply a secure foundation for conducting financial management, rights management, certificate authority, rules clearing, usage clearing, secure directory services, and other transaction related capabilities functioning over a vast electronic network such as the Internet and/or over organization internal Intranets. These administrative and support services can be adapted to the specific needs of electronic commerce value chains. Electronic commerce participants can use these administrative and support services to support their interests, and can shape and reuse these services in response to competitive business realities. A Distributed Commerce Utility having a secure, programmable, distributed architecture provides administrative and support services.
    Type: Grant
    Filed: September 17, 1999
    Date of Patent: November 7, 2006
    Assignee: Intertrust Technologies Corp.
    Inventors: Karl L. Ginter, Victor H. Shear, Francis J. Spahn, David M. Van Wie, Robert P. Weber
  • Patent number: 7127606
    Abstract: A method of authenticating an entity by a receiving party with respect to an electronic communication that is received by the receiving party and that includes both a unique identifier associated with an account maintained by the receiving party and a digital signature for a message regarding the account, consists of the steps of, before receipt of the electronic communication, first associating by the receiving party a public key of a public-private key pair with the unique identifier and, thereafter, only conducting message authentication using the digital signature received by the receiving party in the electronic communication and the public key associated with the account identifier.
    Type: Grant
    Filed: March 11, 2002
    Date of Patent: October 24, 2006
    Assignee: First Data Corporation
    Inventors: Lynn Henry Wheeler, Anne M. Wheeler
  • Patent number: 7127611
    Abstract: A vehicle authenticates a component class of a prospective component for use in the vehicle by obtaining from a certification authority a certification that an authentic component of the component class is associated with a second cryptographic key. The certification certifies that the second cryptographic key is bound to information identifying an authentic component of the component class. The vehicle utilizes the second cryptographic key obtained from the certification authority in cryptographic communication with the prospective component, and determines whether the prospective component is an authentic component of the component class based on whether the second cryptographic key is successfully utilized in the cryptographic communication.
    Type: Grant
    Filed: June 28, 2002
    Date of Patent: October 24, 2006
    Assignee: Motorola, Inc.
    Inventors: Ezzat A. Dabbish, Larry C. Puhl
  • Patent number: 7127741
    Abstract: An e-mail firewall applies policies to e-mail messages transmitted between a first site and a plurality of second sites. The e-mail firewall includes a plurality of mail transfer relay modules for transferring e-mail messages between the first site and one of the second sites. Policy managers are used to enforce and administer selectable policies. The policies are used to determine security procedures for the transmission and reception of e-mail messages. The e-mail firewall employs signature verification processes to verify signatures in received encrypted e-mail messages. The e-mail firewall is further adapted to employ external servers for verifying signatures. External servers are also used to retrieve data that is employed to encrypt and decrypt e-mail messages received and transmitted by the e-mail firewall, respectively.
    Type: Grant
    Filed: June 22, 2001
    Date of Patent: October 24, 2006
    Assignee: Tumbleweed Communications Corp.
    Inventors: Jean-Christophe Denis Bandini, Jeffrey C. Smith
  • Patent number: 7127607
    Abstract: A client/server authentication system is disclosed. The system includes a filter, a plug-in, and an extension. The filter monitors sessions between a client and a server for proper authentication. The plug-in is coupled to the client and the server. The plug-in generates public and private key pairs, and receives and stores certificates. The extension is coupled to the filter. The extension generates script commands to cause the client and the server to perform required steps indicated by the filter.
    Type: Grant
    Filed: May 28, 2004
    Date of Patent: October 24, 2006
    Assignee: LANDesk Software Limited
    Inventors: Jin Su, Paul Hillyard, Alan B. Butt
  • Patent number: 7127613
    Abstract: A system and method for providing secure exchange of messages between peers in peer groups. Embodiments may be used to provide secured sessions between peers in the peer-to-peer network. Embodiments may also be used to provide secured group sessions among a plurality of peers. A first peer may generate and send a public key to a second peer. The second peer may generate a session key from the public key. The second peer may send the session key to the first peer, or alternatively to two or more peers in a group session. The session key may be secured when sending. Messages and/or other data exchanged between the two peers may be encrypted and decrypted using the session key.
    Type: Grant
    Filed: February 25, 2002
    Date of Patent: October 24, 2006
    Assignee: Sun Microsystems, Inc.
    Inventors: Kuldip Singh Pabla, William J. Yeager
  • Patent number: 7127614
    Abstract: A justification/authentication personal certificate system stores in a remote database a counterpart of an identifier and a digital watermark contained in the personal certificate. The personal certificate includes the digital watermark embedded in an authentic image such as a facial photograph, a retinal scan, or a fingerprint. When the personal certificate is used, the authentic image is read from the personal certificate, and the digital watermark information is extracted. The digital watermark information and the identifier are compared with the counterparts stored in the database. If the extracted digital watermark information is identical to the information in the database, then the personal certificate is judged to be unjustifiable. In one embodiment, at least one of the identifier and digital watermark are changed each time the system justifies the personal certificate.
    Type: Grant
    Filed: June 20, 2001
    Date of Patent: October 24, 2006
    Assignee: Matsushita Electric Industrial Co., Ltd.
    Inventors: Yuichi Kawaguchi, Yuji Shimizu, Shinichi Tsumori, Takashi Katsura, Hisashi Inoue
  • Patent number: 7120802
    Abstract: Secure computation environments are protected from bogus or rogue load modules, executables and other data elements through use of digital signatures, seals and certificates issued by a verifying authority. A verifying authority—which may be a trusted independent third party—tests the load modules or other executables to verify that their corresponding specifications are accurate and complete, and then digitally signs the load module or other executable based on tamper resistance work factor classification. Secure computation environments with different tamper resistance work factors use different verification digital signature authentication techniques (e.g., different signature algorithms and/or signature verification keys)—allowing one tamper resistance work factor environment to protect itself against load modules from another, different tamper resistance work factor environment.
    Type: Grant
    Filed: August 6, 2001
    Date of Patent: October 10, 2006
    Assignee: Intertrust Technologies Corp.
    Inventors: Victor H. Shear, W. Olin Sibert, David M. Van Wie
  • Patent number: 7120798
    Abstract: A system generates and verifies signatures on hardcopy documents. A signor key is associated with a signor of a hardcopy document. A document signature is generated using the signor key to encode data selected from document data required to be on the hardcopy document. The document signature is then associated with the hardcopy document. A data indicator is also associated with the hardcopy document and indicates which of the document data is used to generate the document signature. A verification section receives the hardcopy document having the document data thereon, and also receives the document signature and the associated data indicator. The verification section performs a comparison to determine whether the document signature was generated using the signor key and the document data indicated by the data indicator.
    Type: Grant
    Filed: August 25, 2003
    Date of Patent: October 10, 2006
    Inventor: Daniel Suisa
  • Patent number: 7117363
    Abstract: A method, system, and apparatus for authenticating transactions and records is disclosed. A nonce stamp is a physical article that is relatively difficult to copy illicitly, and that bears a “nonce” number. The “nonce” is a relatively unique identifier, in that it is chosen from a distribution such that any given user/customer is extremely unlikely to obtain two nonce stamps bearing the same nonce. The method includes: presenting a nonce stamp having a nonce number; presenting a numbered digital certificate derived securely from the nonce number; and authenticating the transaction by comparing the number on the digital certificate and the nonce number. The digital certificate is typically obtained by users/customers in exchange for the purchase price of a desired transaction. The apparatus is an information-based indicium including a nonce stamp, and a digital certificate including a number derived securely from the nonce.
    Type: Grant
    Filed: September 9, 2002
    Date of Patent: October 3, 2006
    Assignee: SRI International
    Inventors: Patrick D. Lincoln, Natarajan Shankar
  • Patent number: 7117360
    Abstract: A method and apparatus for generating a CRL with a last_changed extension. When sequential CRLs are generated there is the potential that there will be no changes in the data associated with the CRL. In this case a recipient of the new CRL may needlessly perform processing on the new CRL. A CRL consistent with embodiments of the present invention provides an extension to specify the CRL number of the last_changed CRL. This provides the recipient with information to determine whether the new CRL should be processed or the existing data is up to date.
    Type: Grant
    Filed: July 9, 2001
    Date of Patent: October 3, 2006
    Assignee: Sun Microsystems, Inc.
    Inventor: Michelle Zhao
  • Patent number: 7114070
    Abstract: A system and methods for automatic digital certificate installation on network devices in a data-over-cable network are developed. One of the methods includes sending a digital certificate request from a cable modem to a predetermined network server upon determining on the cable modem that there is no digital certificate already installed on the cable modem. The method further includes generating at least one digital certificate on the network server and providing the at least one digital certificate to the cable modem.
    Type: Grant
    Filed: February 14, 2002
    Date of Patent: September 26, 2006
    Assignee: 3Com Corporation
    Inventors: David Willming, Paul Chan, William Necka, Ronald Lee
  • Patent number: 7113925
    Abstract: An electronic check that is created by a secure electronic transmission which can be printed as a paper check by the payee. The electronic check is created by a software program that makes a digital image of the check, securely encrypts the digital image and transmits the digital image to the payee. The payee then uses special software to decrypt the transmitted check image, which is then capable of being printed as a paper check by the payee. The payee can deposit the paper check to the bank. Optionally, the payee can electronically transmit the check image to the payee's bank.
    Type: Grant
    Filed: January 19, 2005
    Date of Patent: September 26, 2006
    Assignee: Echeck21, L.L.C.
    Inventors: Alan I. Waserstein, Atal Bansal
  • Patent number: 7111173
    Abstract: A method of encrypting an object includes generating a cryptographic key, using the cryptographic key to initialize a cryptographic algorithm, and applying the algorithm to the object. Accordingly, an encrypted object is formed. The key is generated by combining key splits derived from different sources. One of the key splits is a biometric value derived from and corresponding to a particular person.
    Type: Grant
    Filed: September 1, 1999
    Date of Patent: September 19, 2006
    Assignee: Tecsec, Inc.
    Inventor: Edward M. Scheidt
  • Patent number: 7107449
    Abstract: The present invention provides a digital certificate (2, 32) comprising a plurality of credential attribute properties (6, 36), and a trust function (8, 42) embedded within the certificate as an executable file, which trust function can determine as a function of data (12, 44) available to it a trust value (14, 46) attributable to at least a part of the certificate at least partly by execution of the executable file. A corresponding method of communication is also disclosed.
    Type: Grant
    Filed: February 15, 2002
    Date of Patent: September 12, 2006
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Marco Casassa Mont, Richard Brown, Brian Quentin Monahan
  • Patent number: 7107610
    Abstract: Resource authorization includes receiving a resource request from a first requester. The resource request includes credentials and identifies an operation to be performed with respect to a resource. The resource request is mapped to a resource identifier, and the resource data structure is searched for a resource node based on the resource identifier. A determination is made whether the first requester is authorized to perform the operation with respect to the resource based on whether the credentials in the resource request match a resource authorization level associated with the resource node.
    Type: Grant
    Filed: May 11, 2001
    Date of Patent: September 12, 2006
    Assignee: Intel Corporation
    Inventor: Victor B. Lortz
  • Patent number: 7107462
    Abstract: A method and system to store and distribute encryption keys commences when a service provider receives a product key from a content provider. The service provider encrypts content controlled by the content provider with a secure device public key of a secure device of the service provider. The secure device of the service provider decrypts the product key with the secure device public key and encrypts the product key with a storage key associated with the secure device. The product key is then stored at the service provider.
    Type: Grant
    Filed: December 16, 2002
    Date of Patent: September 12, 2006
    Assignee: Irdeto Access B.V.
    Inventor: Robert W. Fransdonk