IP Library Granted Patent US 7,624,440
Granted Patent B2
US 7,624,440 · App. 11/830,891 · Granted Nov 24, 2009

Systems and methods for securely providing and/or accessing information

Assignee: EMT LLC
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,624,440
App. No.
11/830,891
Granted
Nov 24, 2009
Kind
B2
Abstract

The invention is directed to a secure data communication system and method for use in connection with a potentially untrusted host computer. The system includes a storage medium that is connectable with the potentially untrusted host computer. The system also includes a hardened, stand alone, browser stored on the storage medium. The system can also include client authentication data and/or add-on program data. The browser can use the client authentication data to facilitate secure communications. The system can include has a loader that performs an integrity check of the browser and/or data files and launches the browser only if the browser and associated data files pass the integrity check. The client authentication data can be stored on the storage medium. The storage medium can be read-only, read-write or a combination thereof.

Claims (51)

1. A secure data communication system for use in connection with a potentially untrusted host computer comprising:

a storage medium that is connectable with the potentially untrusted host computer;

a hardened, stand alone, web browser stored on the storage medium; and

client authentication data, wherein the browser uses the client authentication data to facilitate secure communications.

2. The system of claim 1 comprising a loader that performs a cryptographic integrity check of at least one file associated with the browser and launches the browser only if the file passes the integrity check.

3. The system of claim 1 wherein the client authentication data is stored on the storage medium.

4. The system of claim 3 comprising a loader that performs a cryptographic integrity check of at least a portion of the client authentication data and launches the browser only if the client authentication data passes the integrity check.

5. The system of claim 1 comprising add-on program data stored on the storage medium.

6. The system of claim 5 comprising a loader that performs a cryptographic integrity check of at least a portion of the add-on program data and launches the browser only if the add-on program data passes the integrity check.

7. The system of claim 1 comprising an input for receiving client authentication data.

8. The system of claim 1 wherein the storage medium comprises at least one of a USB Flash Drive and a CD.

9. The system of claim 1 wherein storage medium has at least a read only portion.

10. The system of claim 1 wherein storage medium has at least a read/write portion.

11. The system of claim 1 wherein storage medium comprises a read only portion and a read/write portion.

12. The system of claim 9 comprising a loader stored on the read only portion, wherein the loaded performs an integrity check of at least one file associated with the browser and launches the browser only if the file passes the integrity check.

13. The system of claim 9 wherein the browser is stored on the read only portion.

14. The system of claim 2 wherein the loader launches the web browser in debug mode.

15. The system of claim 1 wherein the client authentication data includes at least one digital certificate.

16. The system of claim 15 wherein the digital certificate is cryptographically signed.

17. The system of claim 1 wherein the web browser is hardened by limiting communication to a list of browsable addresses.

18. The system of claim 1 wherein the browser is hardened by forcing encrypted communication.

19. The system of claim 1 wherein the web browser is hardened by forcing mutual authentication.

20. The system of claim 1 wherein the web browser is hardened by preventing access to security related browser options.

21. A secure data communication method for use in connection with a potentially untrusted host computer comprising:

providing a storage medium that is connectable with the potentially untrusted host computer;

providing a hardened, stand alone, web browser stored on the storage medium; and

providing client authentication data, wherein the web browser uses the client authentication data to facilitate secure communications.

22. The method of claim 21 comprising performing a cryptographic integrity check of at least one file associated with the web browser and launches the web browser only if the file passes the integrity check.

23. The method of claim 21 wherein the client authentication data is stored on the storage medium.

24. The method of claim 23 comprising performing a cryptographic integrity check of at least a portion of the client authentication data and launches the web browser only if the client authentication data passes the integrity check.

25. The method of claim 21 comprising add-on program data stored on the storage medium.

26. The method of claim 25 comprising performing a cryptographic integrity check of at least a portion of the add-on program data and launching the web browser only if the add-on program data passes the integrity check.

27. The method of claim 21 receiving client authentication data via the host computer.

28. The method of claim 21 wherein the storage medium comprises at least one of a USB Flash Drive and a CD.

29. The method of claim 21 wherein storage medium has at least a read only portion.

30. The method of claim 21 wherein storage medium has at least a read/write portion.

31. The method of claim 21 wherein storage medium comprises a read only portion and a read/write portion.

32. The method of claim 29 comprising a loader stored on the read only portion, wherein the loaded performs a cryptographic integrity check of at least one file associated with the web browser and launches the web browser only if the file passes the integrity check.

33. The method of claim 29 wherein the a cryptographic browser is stored on the read only portion.

34. The method of claim 22 comprising launching the web browser in debug mode.

35. The method of claim 21 wherein the client authentication data includes at least one digital certificate.

36. The method of claim 35 wherein the digital certificate is cryptographically signed.

37. The method of claim 21 wherein the web browser is hardened by limiting communication to a list of browsable addresses.

38. The method of claim 21 wherein the web browser is hardened by forcing encrypted communication.

39. The method of claim 21 wherein the web browser is hardened by forcing mutual authentication.

40. The method of claim 21 wherein the web browser is hardened by preventing access to security related browser options.

41. A secure data communication system for use in connection with a potentially untrusted host computer comprising:

a storage medium that is connectable with the potentially untrusted host computer, wherein the storage medium has at least a read only portion;

a hardened, stand alone, web browser stored on the storage medium;

a loader that performs an cryptographic integrity check of at least one file associated with the web browser and launches the web browser only if the file passes the integrity check, wherein the loader is stored on the read only portion of the storage medium; and

client authentication data, wherein the web browser uses the client authentication data to facilitate secure communications.

Assignments (4)
SECURITY INTEREST Recorded May 5, 2016
From: TRUSTATE INTERNATIONAL INC.
To: TANGIBLE IP, LLC
Reel/Frame 038477/0301 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2013
From: TRUSTATE LLC
To: TRUSTATE INTERNATIONAL INC.
Reel/Frame 030379/0017 →
CHANGE OF NAME Recorded Jan 21, 2008
From: EMT LLC
To: TRUSTATE LLC
Reel/Frame 020426/0777 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2007
From: JALLAD, RAMSEY; STACH, PATRICK; TERRILL, JOHN
To: EMT LLC
Reel/Frame 019623/0310 →
Continuity (2)
Provisional Application 6082106500 · Aug 1, 2006
Related Publication 20080034210A1 · Feb 7, 2008