IP Library Granted Patent US 7,228,430
Granted Patent B2
US 7,228,430 · App. 10/250,722 · Granted Jun 5, 2007

Security system for preventing a personal computer from being used by an unauthorized people

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,228,430
App. No.
10/250,722
Granted
Jun 5, 2007
Kind
B2
Abstract

A security system for preventing unauthorized use of a computer device. An extractable security piece includes an extractable main private key and a main PC public key. A PC security area which is a non-extractable part of the computer device includes a PC private key and an extractable main public key, which, together with the keys of the extractable security piece, constitute a Public Key Infrastructure. The extractable security piece and the PC security area include processing means for mutual authentication of the extractable security piece and the PC security area after the extractable security piece, which had been previously removed, has been reinserted in the computer device, thereby enabling the authorized user to access data stored in the computer device.

Claims (13)

1. A Security system for preventing unauthorized use of a main computer device having an authorized user, comprising:

an extractable security piece which can be removed from the main computer device by the authorized user, wherein the extractable security piece includes an extractable main private key and a main PC public key;

a PC security area, which is a non-extractable part of said main computer device, wherein said PC security area includes a PC private key and an extractable main public key that constitute a Public Key Infrastructure (PKI) with, respectively, the extractable main private key and the main PC public key; and

processing means in said extractable security piece and in said PC security area for mutual authentication of said extractable security piece and said PC security area, wherein said extractable main private key identifies said extractable security piece to said PC security area and said PC private key authenticates said PC security area to said extractable security piece after said extractable security piece, which had been previously removed from said PC security area, is reinserted in said PC security area to enable the authorized user to access data stored in said main computer device, wherein said extractable security piece and said PC security area each comprise a PKI checker for encrypting and authenticating data exchanged between said PC security area and said extractable security piece when said extractable security piece is reinserted in said main computer device, said extractable security piece PKI checker encrypting extractable security piece data with said main PC public key and said PC security area PKI decrypting the encrypted extractable security piece data with said PC private key, and said PC security area PKI checker encrypting PC security area data with said extractable main public key and said extractable security piece PKI checker decrypting the PC security area data with said extractable main private key.

2. The security system according to claim 1 , wherein said extractable security piece includes a password that is used by said computer device and that is exchanged with a password included in said PC security area.

3. The security system according to claim 1 , wherein said extractable security piece is a keyboard key of said main computer device.

4. The security system according to claim 1 , wherein said extractable security piece is an integrated mouse button.

5. The security system according to claim 1 , wherein said extractable security piece includes a PCMCIA card.

6. A method for authorizing a main computer device having an authorized user to be used by a guest user, wherein said main computer device includes a main extractable security piece that includes an extractable main private key, a main PC public key, and a first processor, and a PC security area that includes an extractable main public key and a PC private key that constitute a Public Key Infrastructure (PKI) with said keys of a said extractable security piece and a second processor for exchanging authentication data with said first processor, said method comprising the steps of:

inserting said main extractable security piece into a location of said main computer device, wherein said main extractable security piece includes a shared private key which is transferred into a temporary key area of said PC security area when said main extractable security piece is inserted into said main computer device;

removing said main extractable security piece from said main computer device after said first and second processors have exchanged said authentication data comprising the extractable main private key and the main PC public key; and

inserting into the location a guest extractable security piece of a guest computer of said guest user, wherein said guest extractable security piece includes the same functions and areas as said main extractable security piece, said shared private key is transferred from said PC security area of said main computer device into said guest extractable security piece and the PC public key is transferred from said PC security area as a local PC public key into said guest extractable security piece when said main extractable security piece has been replaced by said guest extractable security piece in said computer device, said extractable main private key identifies said guest extractable security piece to said PC security area, and said PC private key authenticates said PC security area to said guest extractable security piece, wherein said guest extractable security piece and said PC security area each comprise a PKI checker for encrypting and authenticating data exchanged between said PC security area and said guest extractable security piece when said guest extractable security piece is reinserted in said main computer device, said guest extractable security piece PKI checker encrypting guest extractable security piece data with said main PC public key and said PC security area PKI decrypting the encrypted guest extractable security piece data with said PC private key, and said PC security area PKI checker encrypting PC security area data with said extractable main public key and said guest extractable security piece PKI checker decrypting the PC security area data with said extractable main private key.

7. A security method for authorizing a main computer device having an authorized user to be used remotely from a remote computer device by said authorized user wherein said main computer device includes a main extractable security piece that includes an extractable main private key and a main PC Public key and a first processor, and a PC security area that includes an extractable main public key and a PC Private key that constitute a Public Key Infrastructure (PKI) with said keys of said extractable security piece and a second processor for exchanging authentication data with said first processor, said method comprising the step of inserting said main extractable security piece into said remote computer device so that an extractable main public key is transferred from said main extractable security piece into a temporary key area within a remote PC security area of said remote computer device in order for said remote computer device to verify that said extractable main public key corresponds to said authorized user, wherein said extractable main private key identifies said main extractable security piece to said remote PC security area, said PC private key authenticates said remote PC security area to said main extractable security pieces, a PC public key included in said remote PC security area of said remote computer device is transferred as a local PC public key into said main extractable security piece of said main computer device so that security communications may be established between said main extractable security piece and said remote PC security area, wherein said main extractable security piece and said remote PC security area each comprise a PKI checker for encrypting and authenticating data exchanged between said remote PC security area and said main extractable security piece when said main extractable security piece is reinserted in said remote computer device, said main extractable security piece PKI checker encrypting main extractable security piece data with said main PC public key and said remote PC security area PKI decrypting the main encrypted extractable security piece data with said PC private key, and said remote PC security area PKI checker encrypting remote PC security area data with said extractable main public key and said main extractable security piece PKI checker decrypting the remote PC security area data with said extractable main private key.

Assignments (3)
NUNC PRO TUNC ASSIGNMENT Recorded Nov 25, 2015
From: LENOVO (SINGAPORE) PTE LTD.
To: LENOVO PC INTERNATIONAL
Reel/Frame 037160/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2005
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: LENOVO (SINGAPORE) PTE LTD.
Reel/Frame 016891/0507 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2003
From: BENAYOUN, ALAIN; FIESCHI, JACQUES; LE PENNEC, JEAN-FRANCOIS; ROY, PASCOL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014642/0849 →