IP Library Granted Patent US 7,299,364
Granted Patent B2
US 7,299,364 · App. 10/608,459 · Granted Nov 20, 2007

Method and system to maintain application data secure and authentication token for use therein

Assignee: The Regents of the University of Michigan
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,299,364
App. No.
10/608,459
Granted
Nov 20, 2007
Kind
B2
Abstract

Two embodiments of a method and system to maintain application data secure and authentication token for use therein are provided. The present invention uses transient authentication, in which a small hardware token continuously authenticates the user's presence over a short-range, wireless link. Four principles underlying transient authentication are described as well as the two embodiments for securing applications. In the first embodiment, applications are protected transparently by encrypting in-memory state when the user departs and decrypting this state when the user returns. This technique is effective, requiring just seconds to protect and restore an entire machine. In the second embodiment, applications utilize an API for transient authentication, protecting only sensitive state. Ports of three applications, PGP, SSH, and Mozilla are described with respect to this API.

Claims (28)

1. A system to maintain application data stored on a portable computer secure, the system comprising:

an authorization client for use on the portable computer for making requests, the portable computer being capable of providing in-memory portions of address space for an application program;

a security device to be associated with an authorized user of the portable computer and including an authorization server for supplying responses to the requests;

a communication subsystem for wirelessly communicating the requests and the responses to the server and the client, respectively, within a range; and

a cryptographic subsystem for encrypting data located in the in-memory portions of the address space to obtain corresponding encrypted data when the security device is outside the range of the communication subsystem and for decrypting the encrypted data when the security device is back within the range;

wherein the requests include cryptographic requests for cryptographic information and wherein the server supplies the cryptographic information in response to the cryptographic requests and wherein the cryptographic subsystem utilizes the cryptographic information to either encrypt or decrypt the data.

2. The system as claimed in claim 1 further comprising means for suspending substantially all authorized user processes on the computer when the security device is outside the range and means for restarting the suspended authorized user processes on the computer when the security device is back within the range.

3. The system as claimed in claim 1 wherein the cryptographic information includes keys.

4. The system as claimed in claim 3 wherein the keys are encrypted.

5. The system as claimed in claim 3 wherein the keys include at least one master key.

6. The system as claimed in claim 5 wherein the at least one master key is a key-encrypting key.

7. The system as claimed in claim 1 further comprising means for suspending selected authorized user processes on the computer when the security device is outside the range and means for restarting the selected authorized user processes on the computer when the security device is back within the range.

8. The system as claimed in claim 1 further comprising a mechanism for establishing a binding between the portable computer and the security device to ensure that the security device only responds to a portable computer with a valid binding.

9. The system as claimed in claim 1 wherein the security device is an authorization token.

10. The system as claimed in claim 1 wherein the cryptographic subsystem includes encrypted keys and wherein the cryptographic information includes keys for decrypting the encrypted keys.

11. A method to maintain application data stored on a portable computer secure, the method comprising:

providing an authorization client for use on the portable computer for making requests, the portable computer being capable of providing in-memory portions of address space for an application program;

providing a security device to be associated with an authorized user of the portable computer and including an authorization server for supplying responses to the requests;

wirelessly communicating the requests and the responses to the server and the client, respectively, within a range;

encrypting data located in the in-memory portions of the address space to obtain corresponding encrypted data when the security device is outside the range; and

decrypting the encrypted data when the security device is back within the range;

wherein the requests include cryptographic requests for cryptographic information and wherein the server supplies the cryptographic information in response to the cryptographic requests and wherein the cryptographic information is used to either encrypt or decrypt the data.

12. The method as claimed in claim 11 further comprising suspending substantially all authorized user processes on the computer when the security device is outside the range and restarting the suspended authorized user processes on the computer when the security device is back within the range.

13. The method as claimed in claim 11 further comprising establishing a binding between the portable computer and the security device to ensure that the security device only responds to a portable computer with a valid binding.

14. The method as claimed in claim 11 further comprising suspending selected authorized user processes on the computer when the security device is outside the range and restarting the selected authorized user processes on the computer when the security device is back within the range.

15. The method as claimed in claim 11 wherein the cryptographic information includes keys.

16. The method as claimed in claim 15 wherein the keys include at least one master key.

17. The method as claimed in claim 16 wherein the at least one master key is a key-encrypting key.

Assignments (3)
CONFIRMATORY LICENSE Recorded May 21, 2020
From: UNIVERSITY OF MICHIGAN
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 052720/0916 →
CONFIRMATORY LICENSE Recorded Aug 7, 2013
From: UNIVERSITY OF MICHIGAN
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 030984/0669 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2003
From: NOBLE, BRIAN D.; CORNER, MARK D.
To: MICHIGAN, THE REGENTS OF THE UNIVERSITY OF
Reel/Frame 014732/0388 →
Continuity (2)
Continuation In Part 1011920400 · Apr 9, 2002
Related Publication 20040073792A1 · Apr 15, 2004