Time Stamp Patents (Class 713/178)
-
Patent number: 7979713Abstract: Methods and arrangements are provided for handling, within a communications system comprising a distributed domain and a central domain, electronic records that contain predictions of the outcome of a certain incident. Within the distributed domain there is generated, before the outcome of the incident is known, a multitude of electronic records that contain predictions of the outcome of the incident. The electronic records are conveyed from the distributed domain to the central domain. After the outcome of the incident is known, the central domain finds out which of the electronic records, if any, contain correct predictions of the outcome of the incident. Each of the electronic records is furnished, within the distributed domain, with a cryptographically protected proof of a certain moment of time associated with the generation of the electronic record.Type: GrantFiled: June 1, 2009Date of Patent: July 12, 2011Assignee: Innoka OyInventors: Timo Hämäläinen, Risto Rautee, Marko Hännikäinen, Janne Rekonius
-
Patent number: 7979533Abstract: A system, method and computer program product for auditing a message in a message stream are disclosed. Messages in a message stream are captured including at least one message in an extensible markup language (XML) format. Each message in the XML format is then extracted from the captured messages and has a timestamp applied thereto. Each timestamped message in the XML format is then stored in a memory.Type: GrantFiled: October 16, 2006Date of Patent: July 12, 2011Assignee: Network Resonance, Inc.Inventors: Kevin Stewart Dick, Eric Kenneth Rescorla
-
Patent number: 7979709Abstract: An information processing apparatus is provided. The information processing apparatus includes content verification means for executing a verification processing of a recording content recorded on an information recording medium, and content play means for executing a content play processing on a condition that validity of the recording content is checked on the basis of the verification processing. The content verification means acquires from the information recording medium a content hash table having registered therein hash values generated on the basis of legal recording content data and executes a processing for verifying a presence or absence of an illegal recording content whose hash value is not registered in the content hash table.Type: GrantFiled: September 13, 2006Date of Patent: July 12, 2011Assignee: Sony CorporationInventors: Yoshikazu Takashima, Kenjiro Ueda
-
Patent number: 7979731Abstract: A time authentication device identifies clocks that show a time falling within the predetermined permissible range as compared with a time shown by the time authentication device. In a time authentication device embodied as a distribution device, a time-relation information storage unit stores a playback-device-time measured by a clock unit of a playback device, and also stores a distribution-device-time measured by a clock unit when the playback-device-time is acquired. The time authentication unit acquires from the playback device a target time measured by the clock unit, and also acquires an authentication time measured by the clock unit when the target time is received. The time authentication unit then calculates a first difference, a second difference, an authentication difference. If the authentication difference is smaller than or equal to a predetermined threshold, the time authentication unit judges that the clock unit of the playback device is valid.Type: GrantFiled: July 13, 2005Date of Patent: July 12, 2011Assignee: Panasonic CorporationInventors: Yuichi Futa, Natsume Matsuzaki, Hiroki Yamauchi, Toshihisa Nakano
-
Patent number: 7975145Abstract: A time stamp updating apparatus includes: a time stamp obtaining unit configured to transmit hash value calculated from certification target data to an apparatus for time stamp authority when certification target data is input, to receive time stamp data from the apparatus for time stamp authority, to relate the received time stamp data to certification target data, and stored them in an evidence data storage unit; and a time stamp verification unit configured to calculate logical OR of a validity period of the time stamp data related to certification target data, and to output a period that can go back from time of verification as a period when the certification target data can be certified.Type: GrantFiled: October 26, 2006Date of Patent: July 5, 2011Assignees: Kabushiki Kaisha Toshiba, Toshiba Solutions CorporationInventor: Tomonari Tanaka
-
Patent number: 7973607Abstract: A technique involves the use of an electronic device having a real-time clock (RTC) circuit. In particular, the technique involves obtaining an RTC value from the RTC circuit. The RTC value is based on a previous time value and being arranged to represent current time. The technique further involves generating an adjustment factor arranged to adjust for imperfection in an oscillator of the RTC circuit, and providing a new time value based on the RTC value and the adjustment factor. The new time value represents current time at least as accurately as the RTC value.Type: GrantFiled: April 22, 2008Date of Patent: July 5, 2011Assignee: EMC CorporationInventors: Marco Ciaffi, Daniel Wilder
-
Patent number: 7962752Abstract: Providing trusted time in a computing platform, while still supporting privacy, may be accomplished by having a trusted time device provide the trusted time to an application executing on the computing platform. The trusted time device may be reset by determining if a value in a trusted time random number register has been set, and if not, waiting a period of time, generating a new random number, and storing the new random number in the trusted time random number register. The trusted time random number register is set to zero whenever electrical power is first applied to the trusted time device upon power up of the computing platform, and whenever a battery powering the trusted time device is removed and reconnected. By keeping the size of the trusted time random number register relatively small, and waiting the specified period of time, attacks on the computing platform to determine the trusted time may be minimized, while deterring the computing platform from being uniquely identified.Type: GrantFiled: September 23, 2005Date of Patent: June 14, 2011Assignee: Intel CorporationInventors: Ernest F. Brickell, Clifford D. Hall
-
Patent number: 7959073Abstract: A method for securely handling processing of information in a chip may include randomly selecting one of a plurality of data processes based on a random process index. A time interval may be randomly allocated on the chip, for processing the randomly selected one of the plurality of data processes. When the randomly allocated time interval has elapsed, the randomly selected one of the plurality of data processes may be initiated. The randomly selected one of the plurality of data processes may include one or both of accessing data and acquiring the data. Data may be verified by the randomly selected one of the plurality of data processes prior to the processing of the data. The data may be verified utilizing at least one digital signature verification algorithm, such as a Rivest-Shamir-Adelman (RSA) algorithm and/or a secure hash algorithm (SHA-1).Type: GrantFiled: June 29, 2010Date of Patent: June 14, 2011Inventors: Xuemin Chen, Iue-Shuenn I. Chen, Francis Chi-Wai Cheung, Longyin Wei
-
Patent number: 7958366Abstract: A system is provided for preventing recorded data from being illicitly read out and analyzed. An Internet connection interface transmits a program executed by an adapter to an authentication station, while receiving the program in an encrypted form from the authentication station. A hard disc records the encrypted program, received from the authentication station. An interface transmits the program recorded on the horizontal direction on the adapter.Type: GrantFiled: April 18, 2007Date of Patent: June 7, 2011Assignee: Sony CorporationInventors: Ryuji Ishiguro, Itaru Kawakami, Mitsuru Tanabe, Yuichi Ezura, Hirokazu Kawahara
-
Patent number: 7958364Abstract: A system for digitally signing electronic documents is disclosed. The system includes a mobile device, an application server and a database, the mobile device includes a requesting module and a digest encrypting module, the application server includes an obtaining module, a digest generating module and a merging module. The requesting module is configured for sending a request for a digital signature of an electronic document to the application server; the obtaining module is configured for obtaining the electronic document from the database; the digest generating module is configured for generating a digest of the electronic document, and sending the digest to the mobile device; the digest encrypting module is configured for encrypting the digest, generating an encrypted value, and sending the encrypted value to the application server; the merging module is configured for merging the encrypted value and the electronic document. A related computer-based method is also disclosed.Type: GrantFiled: November 15, 2007Date of Patent: June 7, 2011Assignees: Hong Fu Jin Precision Industry (ShenZhen) Co., Ltd., Hon Hai Precision Industry Co., Ltd.Inventors: Chung-I Lee, Chien-Fa Yeh, Chiu-Hua Lu, Xiao-Di Fan, Guo-Ling Ou-Yang
-
Patent number: 7958367Abstract: When a document creation unit 1 is started, it calculates a hash value of each software piece therein and stores the hash value in a hash value holder 71 and a measurement log document holder 44. The document creation unit 1 accesses a time distribution unit plural times to receive time information therefrom, and records the time information in a log document and a measurement log document. The document creation unit 1 transmits the log document, the measurement log document, and digital signature-embedded hash value information (measurement auxiliary document) in a tamper-resistant device 63 to a document reception device. The document reception device verifies matching of the hash values or digital signature in the document group, confirms software operating environments in the document creation unit 1 from the hash values, and determines whether the time information is correctly managed within the unit 1.Type: GrantFiled: April 25, 2008Date of Patent: June 7, 2011Assignee: Hitachi, Ltd.Inventors: Tadaoki Uesugi, Takahiro Fujishiro, Takeshi Akutsu, Hisanori Mishima
-
Patent number: 7953981Abstract: Disclosed herein are methods and systems for encoding digital watermarks into content signals. Also disclosed are systems and methods for detecting and/or verifying digital watermarks in content signals. According to one embodiment, a system for encoding of digital watermark information includes: a window identifier for identifying a sample window in the signal; an interval calculator for determining a quantization interval of the sample window; and a sampler for normalizing the sample window to provide normalized samples. According to another embodiment, a system for pre-analyzing a digital signal for encoding at least one digital watermark using a digital filter is disclosed.Type: GrantFiled: August 10, 2009Date of Patent: May 31, 2011Assignee: Wistaria Trading, Inc.Inventor: Scott A. Moskowitz
-
Patent number: 7949875Abstract: For the authentication of messages communicated in a distributed system from an originator to a destination a keyed-hashing technique is used according to which data to be authenticated is concatenated with a private (secret) key and then processed to the cryptographic hash function. The data are transmitted together with the digest of the hash function from the originator to the destination. The data comprises temporal validity information representing the temporal validity of the data. For example the setup key of a communication is therefore only valid within a given time interval that is dynamically defined by the communication originator. After the time interval is exceeded the setup key is invalid and cannot be reused again.Type: GrantFiled: March 8, 2007Date of Patent: May 24, 2011Assignee: Sony Deutschland GmbHInventor: Niels Mache
-
Patent number: 7949878Abstract: A method for providing a time stamp by using a tamper-proof time signal via a telecommunications network includes the steps of: receiving, at a central system, a request from a network user for a time signal. The time signal is encrypted by the central system with at least one key. The encrypted time signal is transmitted to the network user via the telecommunications network. The network user is provided with the same at least one key. At the central system and the network user, the at least one key is synchronously generated.Type: GrantFiled: December 19, 2003Date of Patent: May 24, 2011Assignee: Deutsche Telekom AGInventor: Marian Trinkel
-
Patent number: 7941667Abstract: A need exists for a technology for guaranteeing the authenticity of an electronic document, and an information disclosure system, which can guarantee the authenticity of a disclosed document and delete information regarded as inappropriate for disclosure. An electronic document is divided into components, and a random number generated from a seed value is concatenated to each of the components. A hash value is calculated for each of the components with which the random numbers have been concatenated. The calculated hash values are further concatenated using a hash function to generate data to which an digital signature is applied.Type: GrantFiled: July 7, 2006Date of Patent: May 10, 2011Assignee: Hitachi, Ltd.Inventors: Kunihiko Miyazaki, Yasuo Hatano
-
Patent number: 7941668Abstract: A method and system for secure managing transactions between application devices over a network. The present invention provides a method and system for receiving data from an application device, such as computer workstation, ATM, credit card point-of-sale terminal, or application software, and transferring that data securely over a network to a recipient application device. The method and system provide secure cryptographic key and enterprise management of embedded, standalone and tightly coupled information assurance components.Type: GrantFiled: July 10, 2006Date of Patent: May 10, 2011Inventors: Jeff J. Stapleton, Bradley L. Morrison, Arnold G. Werschky
-
Patent number: 7941121Abstract: The invention disclose a method for verifying the validity of a user, making full use of a TID as the bridge for establishing confidence between a NAF and a user equipment, and the BSF assigning a term of validity for the TID, thereby extending the function of the TID, enabling the NAF to verify the term of validity for using the TID, and accordingly, achieving a further verification of the validity to the user. By using the method of the invention, it is possible to avoid the situation in which one TID is permanently valid for one or more NAFs, enhance the system security, decrease the risks caused by the theft of users' TID and corresponding secret keys, and at the same time, implement TID management by the NAF. In addition, a combination of the method with billing system makes it easy to implement the function of charging a user.Type: GrantFiled: April 28, 2006Date of Patent: May 10, 2011Assignee: Huawei Technologies Co., Ltd.Inventor: Yingxin Huang
-
Patent number: 7934100Abstract: An information processing system includes a unit that selects a time stamp authority to which a request for generation of a time stamp, the time stamp authority to be selected is different from a time stamp authority selected in a last selection process which has been performed; a unit that acquires the time stamp from the selected time stamp authority; a unit that generates link information specifying an order in which time stamps; a controller that causes verification information including the time stamp, identification information of the time stamp authority, the link information, that are associated with each other; a unit that receives a time stamp verification request with regard to digital data; and a unit that compares an invalidated time stamp applied to digital data to be verified with a time stamp to thereby specify a time range in which the invalidated time stamp is applied.Type: GrantFiled: March 19, 2007Date of Patent: April 26, 2011Assignee: Fuji Xerox Co., Ltd.Inventor: Yoshihiro Fujimaki
-
Publication number: 20110093713Abstract: A method for signing a document to be transmitted between two correspondents, i.e. a sender and an addressee, including recording the sender and the addressee of the document for the allocation of a digital identity thereto; authorizing by the addressee a correspondence with the sender; ciphering the document; indicating to the addressee that the document is available; detecting an access to the document by the addressee; generating an electronic report indicating the delivery of the document, the document-delivery electronic report including a set of data associated with the transmission of the document to the addressee, the set including identification of elements concerning the addressee authentication, the sealing of the document, the access to the document by the addressee and the time-stamping of the access to the document by the addressee; and electronically signing, by a reliable third-party using the private key thereof, the document-delivery electronic report.Type: ApplicationFiled: January 5, 2009Publication date: April 21, 2011Applicant: TRUSTSEED SASInventor: Eric Blot-Lefevre
-
Publication number: 20110087887Abstract: Methods and apparatus for providing proof of multiple entities being co-located at a specific time and location. An attestor transmits an attestation message via short range communication; the attestation message includes a time stamp, a location stamp, and a verifiable digital signature. An attestee that stores the attestation message can produce the attestation message at a later time to any interested party, as proof of co-location with the attestor at the specified time and location. In one exemplary embodiment, the methods and apparatus are substantially “open” for public implementation. Such public implementation enables attestors and attestees without prior affiliation, to provide attestation. Furthermore, the device-agnostic methods and apparatus can provide attestation capabilities even in previously deployed systems and devices.Type: ApplicationFiled: October 9, 2009Publication date: April 14, 2011Inventors: Achim Luft, Maik Bienas, Andreas Schmidt
-
Patent number: 7925884Abstract: A method of verifying a carved seal includes detecting a pressure on a carved seal stamp is detected through pins extending from a face of the carved stamp steal. It is determined if the pressure indicates that the seal is being pressed. A fingerprint of a user of the seal is read when it is determined that the seal is being pressed. An image of an object being stamped by the seal is photographed if the pressure indicates that the seal is being pressed. A time that the seal is being pressed is determined if the pressure indicates that the seal is being pressed. A location of the seal is determined if the pressure indicates that the seal is being pressed. An audio note is recorded if the pressure indicates that the seal is being pressed. The fingerprint, time, and location is associated with the photograph of the image of the object being stamped by the seal. The information is encoded into a face of the seal to indicate that the fingerprint was determined to belong to an authorized user.Type: GrantFiled: June 30, 2008Date of Patent: April 12, 2011Assignee: International Business Machines CorporationInventors: Ori Pomerantz, Louis Thomas Fuka
-
Patent number: 7923830Abstract: A package-on-package (POP) secure module includes a first ball grid array (BGA) package and a second BGA package. The first BGA includes an array of bond balls that is disposed on a side of a substrate member, and an array of lands that is disposed on the opposite side of the substrate member. Bond balls of the second BGA are fixed to the lands of the first BGA such that the second BGA is piggy-back mounted to the first BGA. Embedded in the substrate member of the second BGA is an anti-tamper security mesh. An integrated circuit in the first BGA is coupled to, drives and monitors the security mesh. When the module is disposed on a printed circuit board within a point of sale (POS) terminal, the integrated circuit is coupled to, also drives and monitors a second security mesh embedded in the printed circuit board underneath the module.Type: GrantFiled: April 13, 2007Date of Patent: April 12, 2011Assignee: Maxim Integrated Products, Inc.Inventors: Steven M. Pope, Ruben C. Zeta
-
Patent number: 7926096Abstract: A system and a method for operating a device that is not capable of independently maintaining a local time clock to enforce a time-based transaction policy that requires a reliable time reference. The device establishes a secure communications channel to one or more network-attached time sources and inquires of each of the network-attached time-sources as to the current time using the secure communications channel. The device receives the current time from the network-attached time-sources and uses the received current times to estimate a current calendar time and to compute a reliability index associated with the estimated current calendar time. The device uses the estimated current calendar time and reliability index to enforce the time-based transaction policy.Type: GrantFiled: August 31, 2005Date of Patent: April 12, 2011Assignee: Gemalto SAInventors: Asad Mahboob Ali, Bertrand du Castel, Apostol Vassilev, Sylvain Prevost, Kapil Sachdeva
-
Patent number: 7925883Abstract: A phishing detection server component and method is provided. The component can be employed as part of a system to detect/phishing attacks. The phishing detection server component can receive password reuse event report(s), for example, from a protection component of client component(s). Due to the malicious nature of phishing in general, the phishing detection server component can be susceptible to attacks by phishers (e.g., by reverse engineering of the client component). For example, false report(s) of PREs can be received from phisher(s) in an attempt to overwhelm the server component, induce false positives and/or induce false negatives. Upon receipt of a PRE report, the phishing detection server component can first verify that the timestamp(s) are genuine (e.g., previously generated by the phishing detection server component). The report verification component can employ the timestamp(s) to verify veracity of the report (e.g., to minimize attacks by phishers).Type: GrantFiled: February 23, 2006Date of Patent: April 12, 2011Assignee: Microsoft CorporationInventors: Dinei A. Florencio, Cormac E. Herley
-
Patent number: 7917763Abstract: The present invention relates to a device for detecting a manipulation of an information signal, having an extractor for extracting an information signal component characteristic for the information signal from the information signal, an encryptor for encrypting the information signal component to obtain an encrypted signal, and a comparator for comparing the encrypted signal to a reference signal, wherein the reference signal is an encrypted representation of a non-manipulated reference signal component of a reference information signal to detect the manipulation.Type: GrantFiled: May 10, 2007Date of Patent: March 29, 2011Assignee: Fraunhofer-Gesellschaft zur Foerderung der Angewandten Forschung E.V.Inventors: Ralph Kulessa, Jörg Pickel, Stefan Krägeloh, Patrick Aichroth, Frank Siebenhaar, Christian Neubauer, Wolfgang Spinnler
-
Patent number: 7904725Abstract: A system verifies an electronic signature. The electronic signature may be associated with timestamps, each including a time value. A timestamp verification module detects invalid certificates in a certificate chain of the electronic signature and records an earliest invalidity time value of the invalid certificates. The verification module also verifies the timestamps associated with the electronic signature and records the time value of the earliest valid timestamp. A declaration module declares the electronic signature as valid if the time value of the earliest valid timestamp is earlier than the earliest invalidity time value of the one or more invalid certificates. The electronic signature may alternatively or additionally be associated with countersignatures. A countersignature verification module verifies the countersignatures associated with the electronic signature, and the declaration module declares the electronic signature as valid if all of the countersignatures are determined to be valid.Type: GrantFiled: March 2, 2006Date of Patent: March 8, 2011Assignee: Microsoft CorporationInventor: Miladin Pavlicic
-
Patent number: 7899205Abstract: A method of detecting a version of input data content, there being a plurality of different versions of said data content, in which: said data content is arranged as two or more segments according to a segmentation pattern; and said versions of said data content are identifiable by corresponding identification data patterns by which at least some of said segments have respective identification data; said method comprising the steps of: (i) detecting said identification data in respect of said segments of said input data content; (ii) comparing said detected identification data with said identification data patterns corresponding to said different versions of said data content; and (iii) detecting that said input data content comprises at least a contribution from a certain version of said data content if a sum of matches obtained between said detected identification data and said identification data pattern for said certain version exceeds a threshold number.Type: GrantFiled: July 21, 2004Date of Patent: March 1, 2011Assignee: Sony United Kingdom LimitedInventors: Jason Charles Pelly, Daniel Warren Tapson, Mark Julian Russell
-
Patent number: 7895445Abstract: Data transfer between remote and home locations over a network is effected using an electronic token to facilitate access to the data. According to an example embodiment of the present invention, a network-based server facilitates the generation of a token specifying conditions upon which data access to a registered user's data can be made. When a request for data transfer is received in connection with a token, information in the token is used together with the request to selectively authenticate and serve the request.Type: GrantFiled: March 13, 2006Date of Patent: February 22, 2011Assignee: Nokia CorporationInventors: Michael J. Albanese, James Roland Henderson, Keith Barraclough, David Irvine, Rodrigo Philander
-
Publication number: 20110040976Abstract: A method and memory device for generating a time estimate are provided. In one embodiment, a memory device generates a time estimate from time stamps in file system metadata for a plurality of files stored in the memory device and uses the time estimate to perform a time-based activity in the memory device. In another embodiment, a memory device generates a time estimate from time stamps stored in a plurality of files stored in the memory device and uses the time estimate to perform a time-based activity in the memory device. In yet another embodiment, a memory device obtains a plurality of time stamps, selects one or more of the plurality of time stamps based on validity rankings, generates a time estimate from the selected time stamp(s), and uses the time estimate to perform a time-based activity in the memory device.Type: ApplicationFiled: August 17, 2009Publication date: February 17, 2011Inventors: Rahav Yairi, Itzhak Pomerantz, Itai Dror, Ori Stern
-
Patent number: 7890761Abstract: A token value is generated for a user to submit to an authentication service of an electronic system. The token value represents that the user is in possession of an electronic item known to the authentication service, where the electronic item is capable of two-way communications with the authentication service and has thereon an authenticator application transmitted from the authentication service to the electronic item. The authenticator application obtains a current time value from a clock of the electronic item or an authentication value from the authentication service, retrieves predetermined indicia of the electronic item from a location thereon, and combines the obtained value and the retrieved indicia of the electronic item to generate the token value. The authentication service essentially performs the same steps based on information already available at such authentication service to generate a verification token value, and compares the submitted token value to the verification token value.Type: GrantFiled: September 25, 2007Date of Patent: February 15, 2011Assignee: United Services Automobile Association (USAA)Inventor: Michael Frank Morris
-
Patent number: 7890764Abstract: A time stamp obtaining apparatus for maintaining the certificate of the existence of electronic filing document including: a receiving unit 12 receiving hash value of the document data; a transmitting section 15c transmitting the hash value to time stamp providing apparatus 30a; a storing processing section 15d inserting the time stamp encoded with private key in unupdated data 16b concerning time stamp received since point to which private key is updated and storing; an update detecting section 11 detecting the update of private key; a calculation section 13b calculating hash value for all time stamps included in the unupdated data 16b; a transmitting section 13c transmitting the hash value; a storing processing section 13d moving the unupdated data 16b to past data 16c concerning time stamp received before point to which private key is updated last time when time stamp is received, storing it, and storing the time stamp newly received as new unupdated data 16b; is provided.Type: GrantFiled: September 22, 2006Date of Patent: February 15, 2011Assignees: Kabushiki Kaisha Toshiba, Toshiba Solutions CorporationInventor: Tomonari Tanaka
-
Patent number: 7891009Abstract: A first time indication which can be changed by a user and stored in a first memory. Furthermore, in the case of a change in the first time indication which is performed externally to the checking device, the difference between the stored first time indication and the changed first time indication is determined. Furthermore, it is checked whether a predetermined criterion is met by using a trustworthy second time indication, the first time indication and the difference.Type: GrantFiled: October 20, 2006Date of Patent: February 15, 2011Assignee: Infineon Technologies AGInventors: Gerard David Jennings, Eckhard Delfs, Uma Ranjan, Andreas Siggelkow
-
Patent number: 7890765Abstract: Methods, apparatus and systems for generating a trusted digital time stamp as well as a public time source. It includes, an apparatus for receiving and recording public time information and a method for verifying a digital time stamp. A method for generating a trusted digital time stamp includes: obtaining a first time information and a corresponding random code from a public time source; and generating a digital time stamp using a first time information and random code. A method for verifying a digital time stamp includes: recording time information and corresponding random codes transmitted by a public time source; retrieving time information and a random code contained in the time stamp; and comparing a retrieved random code from the time stamp with one of the recorded random codes that corresponds to a time information in the time stamp, if they are consistent, the time stamp is determined to be trusted, otherwise the time stamp is determined to be not trusted.Type: GrantFiled: May 20, 2008Date of Patent: February 15, 2011Assignee: International Business Machines CorporationInventors: Jian Zhang, Ling Shao, Dong Xie
-
Patent number: 7882363Abstract: There is described an authentication system in which during an enrolment process a distinctive characteristic of a subject being enrolled is measured to generate a reference number representative of the subject. Authentication data is then generated using the reference number, and the authentication data is stored for use in a subsequent verification process. During verification, the representative characteristic of the subject being verified is re-measured to generate a test number representative of the subject being verified and the authentication data during enrolment is retrieved. The authentication system then checks for equality between the test number and the reference number using the retrieved authentication data. If the test number and the reference number are equal, then the authenticity of the subject is verified, otherwise the authenticity is denied.Type: GrantFiled: June 2, 2003Date of Patent: February 1, 2011Assignee: Fountain Venture ASInventors: Dominic Gavan Duffy, Aled Wynne Jones
-
Patent number: 7882349Abstract: Method for detecting an attack on a broadcast key shared between an access point and its wireless clients. Upon detection of the attack, actions are implemented to react to the attack as defined in one or more security policies. Detection of the attack is achieved by examining both a link message integrity check and an infrastructure management frame protection (IMFP) message integrity check contained in a broadcast management frame.Type: GrantFiled: December 6, 2005Date of Patent: February 1, 2011Assignee: Cisco Technology, Inc.Inventors: Nancy Cam-Winget, Mark Krischer, Robert B. O'Hara, Jr.
-
Patent number: 7877787Abstract: An apparatus and method for sharing data in a communications system include a bootstrapping server function (BSF) configured to transmit a first message. The first message includes a timestamp parameter corresponding to a generic bootstrapping architecture user security settings (GUSS) stored in the BSF. A home subscriber server (HSS) is configured to receive the first message, to compare the timestamp parameter corresponding to the GUSS stored in the BSF with a timestamp parameter corresponding to a GUSS stored in the HSS, and to transmit a second message back to the BSF excluding the GUSS when the timestamp parameters of the GUSS of the BSF and the HSS are equal.Type: GrantFiled: December 16, 2005Date of Patent: January 25, 2011Assignee: Nokia CorporationInventors: Pekka Laitinen, Philip Ginzboorg
-
Patent number: 7873834Abstract: An image forming apparatus having a network communication function, includes a data input unit which inputs digital data; a data transmission unit which transmits the input digital data to a data management server for management of data; a digest generation unit which generates a digest of the input digital data; a digest storage unit which stores the digest generated by the digest generation unit; a time stamp acquisition unit which acquires a time stamp for authentication of an input time of the digital data from a time stamp station by issuing a time stamp request including the stored digest at a scheduled time; and a data management directive unit which transmits the acquired time stamp to the data management server for management of the time stamp and the transmitted digital data, associated with each other.Type: GrantFiled: February 17, 2006Date of Patent: January 18, 2011Assignee: Fuji Xerox Co., Ltd.Inventor: Shunichi Kojima
-
Patent number: 7873835Abstract: Restricting access to a device includes obtaining a passphrase for a user, obtaining access credentials for the user, obtaining a PIN value for the user, one-way encrypting at least the access credentials and the PIN using a secret key provided with the device. The user is allowed access to the device if the result of one-way encrypting equals the passphrase. The user is denied access to the device if the result of one-way encrypting does not equal the passphrase. The device may be a storage device. The access credentials may include a username that identifies the user and may include a role for the user. The access credentials may include a time period for which access is allowed. Access may be subsequently revoked in response to the current date and time being greater than the time period for which access is allowed.Type: GrantFiled: March 31, 2006Date of Patent: January 18, 2011Assignee: EMC CorporationInventors: Yedidia Atzmony, David J. Allen, Dennis Flanagan, Hagit Brit-Artzi, Ron Arnan
-
Publication number: 20110004767Abstract: A bidirectional entity authentication method based on the credible third party includes the steps that: entity A receives message 1 sent from entity B including the authentication parameters of said entity B, and sends message 2 to the credible third party TP, said message 2 including the authentication parameters of entity B and the authentication parameters of entity A; entity A receives message 3 sent from said credible third party TP, said message 3 including the checking result after checking that whether said entity A and entity B are legal based on said message 2 by said credible third party TP; entity A gets the authentication result of entity B after authenticating said message 3, and sends message 4 to said entity B to make entity B authenticating based on said message 4 and getting the authentication result of entity A.Type: ApplicationFiled: March 4, 2009Publication date: January 6, 2011Inventors: Manxia Tie, Jun Cao, Xiaolong Lai, Zhenhai Huang
-
Patent number: 7861088Abstract: A system and method can verifiably record a voice communication between participants of the voice communication by connecting a first participant to a verifying service provider, connecting between the verifying service and at least one additional participant, recording the voice communication between the first participant and the at least one additional participant to provide a recorded voice communication and secure time-stamping the recorded voice communication to provide a verifiable recorded voice communication. Switch data, such as telephone numbers for the participants and date and time information for the voice communication, can be appended to the recorded voice communication. The participants may input identification data, such as digital signatures, that can be associated with the recorded voice communication and the recorded voice communication can be digitally signed using the digital signatures input by the participants.Type: GrantFiled: December 10, 2002Date of Patent: December 28, 2010Assignee: Verizon Laboratories Inc.Inventor: Laurence Raphael Brothers
-
Patent number: 7861308Abstract: A method for monitoring time so that the use of protected content can be controlled includes receiving a trusted time value from a trusted authority external to a client device. When the client is no longer in communication with the trusted authority, the previously-received trusted time value is updated by use of the client's operating system counter so that a calculated trusted time value is derived for content license evaluation purposes.Type: GrantFiled: November 28, 2005Date of Patent: December 28, 2010Assignees: Sony Corporation, Sony Electronics Inc.Inventors: Marc E. Strohwig, Yoji Kawamoto, Motohiko Nagano, Pierre Chavanne, Norifumi Goto, Oscar H. Steele, III, Eric John Swenson
-
Patent number: 7853795Abstract: A system, method and computer program product for guaranteeing a data transaction over a network are disclosed. When a data transaction between at least a server and a client is detected on a network, data transmitted via the network between the server and client during the data transaction is captured. At least one identifier is associated with the captured data. A timestamp is also generated for the captured data. The timestamp includes information therein identifying at least a portion of the identifier(s). The captured data, the identifier(s) and the timestamp are stored in one or more data stores. The identifier(s) associated with the stored captured data is also mapped to an entry in an index to permit retrieval of the stored data from the data store via the index.Type: GrantFiled: October 28, 2004Date of Patent: December 14, 2010Assignee: Network Resonance, Inc.Inventors: Kevin Stewart Dick, Eric Kenneth Rescorla
-
Patent number: 7848746Abstract: A first processing device, which may be, for example, a wireless authentication token or an RFID tag, comprises a memory, a processor coupled to the memory, and interface circuitry coupled to the processor. The processor is operative to control the output of authentication information via the interface circuitry, where the authentication information comprises a sequence of values corresponding to images of a hash chain. A given one of the values of the sequence is utilized by a second processing device to generate a modified value suitable for providing joint authentication of the first and second processing devices.Type: GrantFiled: June 26, 2007Date of Patent: December 7, 2010Assignee: EMC CorporationInventor: Ari Juels
-
Publication number: 20100306547Abstract: A gateway server interoperates with client and remote server systems to provide stateless security management for a distributed Web application. A Web client application on the client system initiates a WebSocket connection directed to a remote Web service by performing an authentication challenge directed to a user of the Web-browser client where a secure token is not present in a local store instance corresponding to the client application. The authentication challenge obtains the user credentials and then exchanges the user credentials with the gateway server for a secure token. The secure token is then sent in a protocol specific connect message to the gateway server.Type: ApplicationFiled: May 27, 2010Publication date: December 2, 2010Inventors: John R. Fallows, Frank J. Salim
-
Patent number: 7822690Abstract: According to the present invention, there is provided an electronic document processing system and method including an electronic document generation mechanism, an encrypted digital certificate generator, a tool for coordinating the processing of electronic documents, a packaging mechanism for finalizing and authenticating electronic documents, a tracking log for recording relevant electronic document information, and a transferring protocol for transferring the ownership of electronic documents. The present invention also provides an electronic authentication system including an electronic document authentication watermark seal or signature line for confirming a document's signing within the view.Type: GrantFiled: January 18, 2005Date of Patent: October 26, 2010Inventors: Paul Rakowicz, Robert Shanahan
-
Patent number: 7809131Abstract: Sensor device times can vary and may be set significantly wrong. In one embodiment, the present invention can adjust a sensor's time by receiving a raw security event from a sensor device, determining whether a timestamp included in the raw security event is within a timerange around a time known by the agent, determining whether a time offset is in a non-initialized state, and determining whether to adjust the timestamp by applying the time offset to the timestamp, the determination being based on whether the timestamp included in the security event is within the timerange around the time known by the agent and whether the time offset is in a non-initialized state.Type: GrantFiled: December 23, 2004Date of Patent: October 5, 2010Assignee: ArcSight, Inc.Inventors: Hugh S. Njemanze, Hector Aguilar-Macias
-
Patent number: 7809652Abstract: At each of a plurality of transit readers of a transit system, for each of a plurality of riders, where each rider seeks to conduct an access transaction with the transit system for access into the transit facility by using a payment device issued by an issuer in a payment system, data is read from the payment device. The data includes an encryption code that uniquely corresponds to the payment device and was created by the issuer using one or more encryption keys and a predetermined algorithm. A check will be performed, remotely and/or locally, of one or more lists of other encryption codes to determine if the encryption code is on the list. On the basis of whether the encryption code is on the list, the rider is permitted access to the facility of the transit system. The payment device need not be changed for the rider's fare. Decryption of the encryption code read from the payment device is not required to complete the access transaction.Type: GrantFiled: March 1, 2007Date of Patent: October 5, 2010Assignee: Visa U.S.A. Inc.Inventors: Phil Dixon, Ayman Hammad, William Alexander Thaw, Christian Aabye
-
Publication number: 20100250944Abstract: An information processing apparatus includes a first signing unit which digitally signs device information and environment information, a first generator which generates a first digital envelope as data including the signed device information and the signed environment information, a second signing unit which digitally signs biometric authentication information and the first digital envelope, a second generator which generates a second digital envelope as data including the signed biometric authentication information and the signed first digital envelope, a transmitter which transmits the second digital envelope, and a receiver which receives authentication results.Type: ApplicationFiled: February 17, 2010Publication date: September 30, 2010Applicant: FUJITSU LIMITEDInventor: Masato SUZUKI
-
Patent number: RE41960Abstract: According to one embodiment of the invention, a method is provided for receiving a timestamp from a caller via a telephone connection; receiving a device identifier from the caller, in which the device identifier identifies a device; determining a cryptographic key based on the device identifier; determining an indication of a time based on the timestamp and the cryptographic key; providing the indication of the time to the caller; determining an account; and charging a fee to the account.Type: GrantFiled: December 2, 2005Date of Patent: November 23, 2010Assignee: Walker Digital, LLCInventors: Jay S. Walker, Bruce Schneier, James A. Jorasch, Dean P. Alderucci
-
Patent number: RE42018Abstract: According to one embodiment of the invention, a method is provided for receiving a timestamp from a caller via a telephone connection; receiving a device identifier from the caller, in which the device identifier identifies a device; determining a cryptographic key based on the device identifier; determining an indication of a time based on the timestamp and the cryptographic key; providing the indication of the time to the caller; determining an account; and charging a fee to the account.Type: GrantFiled: September 29, 2006Date of Patent: December 28, 2010Assignee: Walker Digital, LLCInventors: Jay S. Walker, Bruce Schneier, James A. Jorasch, Dean P. Alderucci