IP Library Granted Patent US 7,660,994
Granted Patent B2
US 7,660,994 · App. 10/876,275 · Granted Feb 9, 2010

Access control

Assignee: CoreStreet, Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,660,994
App. No.
10/876,275
Granted
Feb 9, 2010
Kind
B2
Abstract

An administration entity controls access to an electronic device by generating credentials and a plurality of corresponding proofs, wherein no valid proofs are determinable given only the credentials and values for expired proofs. The electronic device receives the credentials and, if access is authorized at a particular time, the electronic device receives a proof corresponding to the particular time and confirms the proof using the credentials. A single administration entity may generate the credentials and generate the proofs and/or there may be a first administration entity that generates the credentials and other administration entities that generate proofs. The credentials may be a digital certificate that includes a final value that is a result of applying a one way function to a first one of the proofs.

Claims (69)

1. A method for at least one administration entity to control access to an electronic device, comprising:

the at least one administration entity generating credentials and a plurality of proofs for the electronic device, wherein the proofs are not determinable as valid given only the credentials and values for expired proofs, the expired proofs being no longer valid;

the electronic device receiving the credentials;

if access is authorized at a particular time, the electronic device receiving a corresponding proof corresponding to the particular time; and

the electronic device confirming the corresponding proof using the credentials, wherein the corresponding proof is a result of applying a one way function to a subsequent one of the plurality of proofs received at the electronic device, wherein the credentials are a digital certificate that includes a final value that is a result of applying the one way function to a first one of the plurality of proofs, and wherein said access is access to data on the electronic device.

2. The method, according to claim 1 , wherein the at least one administration entity generates the plurality of proofs after generating the credentials.

3. The method, according to claim 1 , wherein a single administration entity generates the credentials and generates the plurality of proofs.

4. The method, according to claim 1 , wherein there is a first administration entity that generates the credentials and other administration entities that generate the plurality of proofs.

5. The method, according to claim 4 , wherein the first administration entity also generates the plurality of proofs.

6. The method, according to claim 4 , wherein only the other administration entities generate the plurality of proofs.

7. The method, according to claim 1 , wherein the digital certificate includes an identifier for the electronic device.

8. The method, according to claim 1 , wherein the credentials include an identifier for the electronic device.

9. The method, according to claim 1 , wherein the electronic device is a computer.

10. The method, according to claim 9 , further comprising:

the computer booting up only if access is authorized.

11. The method, according to claim 1 , wherein the electronic device is a disk drive.

12. The method, according to claim 1 , further comprising:

providing the plurality of proofs using at least one proof distribution entity separate from the at least one administration entity.

13. The method, according to claim 12 , wherein there is a single proof distribution entity.

14. The method, according to claim 12 , wherein there are a plurality of proof distribution entities.

15. The method, according to claim 1 , further comprising:

providing the plurality of proofs using a connection to the electronic device.

16. The method, according to claim 15 , wherein the connection is the Internet.

17. The method, according to claim 1 , wherein at least one of the proofs is stored locally on the electronic device.

18. The method, according to claim 17 , further comprising:

if the corresponding proof corresponding to the particular time is not available locally on the electronic device, the electronic device requests the plurality of proofs via an external connection.

19. The method, according to claim 1 , wherein each of the plurality of proofs is associated with a particular time interval.

20. The method, according to claim 19 , wherein, after the particular time interval associated with a particular one of the plurality of proofs has passed, the electronic device receives a new proof.

21. The method, according to claim 20 , wherein the particular time interval is one day.

22. A method for an electronic device to control access thereto, comprising:

receiving credentials and at least one of a plurality of proofs for the electronic device, wherein the at least one of the plurality of proofs is not determinable as valid given only the credentials and values for expired proofs, the expired proofs being no longer valid; and

testing, using at least one processor, the at least one of the plurality of proofs using the credentials, wherein, if access is authorized at a particular time, the at least one the plurality of proofs corresponds to the particular time, and wherein the at least one of the plurality of proofs is a result of applying a one way function to a subsequent one of the plurality of proofs, wherein the credentials are a digital certificate that includes a final value that is a result of applying the one way function to a first one of the plurality of proofs, and wherein said access is access to data on the electronic device.

23. The method, according to claim 22 , wherein the digital certificate includes an identifier for the electronic device.

24. The method, according to claim 22 , wherein the credentials include an identifier for the electronic device.

25. The method, according to claim 22 , wherein the electronic device is a computer.

26. The method, according to claim 25 , further comprising:

the computer booting up only if access is authorized.

27. The method, according to claim 22 , wherein the electronic device is a disk drive.

28. The method, according to claim 22 , further comprising:

obtaining the at least one of the plurality of proofs using a connection to the electronic device.

29. The method, according to claim 28 , wherein the connection is the Internet.

30. The method, according to claim 22 , wherein at least one of the plurality of proofs is stored locally on the electronic device.

31. The method, according to claim 30 , further comprising:

if the at least one of the plurality of proofs corresponding to the particular time is not available locally, the electronic device requests the at least one of the plurality of proofs via an external connection.

32. The method, according to claim 22 , wherein each of the plurality of proofs is associated with a particular time interval.

33. The method, according to claim 32 , wherein, after the particular time interval associated with a particular one of the plurality of proofs has passed, the electronic device receives a new proof.

34. The method, according to claim 33 , wherein the particular time interval is one day.

35. A method of controlling access to an electronic device, comprising:

providing credentials to the electronic device; and

if access is allowed at a particular time, providing a proof from a plurality of proofs to the electronic device corresponding to the particular time, wherein the proof is not determinable as valid given only the credentials and values for expired proofs, the expired proofs being no longer valid, and wherein the proof provided to the electronic device is a result of applying, using at least one processor, a one way function to a subsequent proof provided to the electronic device, wherein the credentials are a digital certificate that includes a final value that is a result of applying the one way function to a first one of the plurality of proofs, and wherein said access is access to data on the electronic device.

36. The method, according to claim 35 , wherein the digital certificate includes an identifier for the electronic device.

37. The method, according to claim 35 , wherein the credentials include an identifier for the electronic device.

38. The method, according to claim 35 , wherein the electronic device is a computer.

39. The method, according to claim 38 , further comprising:

the computer booting up only if access is authorized.

40. The method, according to claim 35 , wherein the electronic device is a disk drive.

41. The method, according to claim 35 , further comprising:

providing the proof using at least one proof distribution entity separate from at least one administration entity that generates the proof.

42. The method, according to claim 41 , wherein there is a single proof distribution entity.

43. The method, according to claim 41 , wherein there are a plurality of proof distribution entities.

44. The method, according to claim 35 , further comprising:

providing the proof using a connection to the electronic device.

45. The method, according to claim 44 , wherein the connection is the Internet.

46. The method, according to claim 35 , wherein the proof is stored locally on the electronic device.

47. The method, according to claim 46 , further comprising:

if the proof not available locally, the electronic device requests the proof via an external connection.

48. The method, according to claim 35 , wherein the proof is associated with a particular time interval.

49. The method, according to claim 48 , wherein, after the particular time interval associated with the proof has passed, the electronic device receives a new proof.

50. The method, according to claim 49 , wherein the particular time interval is one day.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2014
From: CORESTREET LTD
To: ASSA ABLOY AB
Reel/Frame 032404/0759 →
RELEASE OF SECURITY INTEREST Recorded Oct 8, 2013
From: ASSA ABLOY AB
To: CORESTREET, LTD.
Reel/Frame 031361/0975 →
ASSIGNMENT OF SECURITY AGREEMENT Recorded Jan 26, 2007
From: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
To: ASSA ABLOY AB
Reel/Frame 018806/0814 →
SECURITY AGREEMENT Recorded Dec 16, 2005
From: CORESTREET, LTD.
To: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
Reel/Frame 016902/0444 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2004
From: LIBIN, PHIL; MICALI, SILVIO
To: CORESTREET, LTD.
Reel/Frame 015790/0111 →
Continuity (8)
Continuation In Part 0991518000 · Jul 25, 2001
Continuation 0948312500 · Jan 14, 2000
Continuation 0935674500 · Jul 19, 1999
Continuation 0882335400 · Mar 24, 1997
Continuation 0855953300 · Nov 16, 1995
Provisional Application 6048217900 · Jun 24, 2003
Provisional Application 6000603800 · Oct 24, 1995
Related Publication 20050010783A1 · Jan 13, 2005