IP Library Patent Application 13105173
Patent Application
App. No. 13/105,173

METHODS AND SYSTEMS FOR IMPLEMENTING A SECURE BOOT DEVICE USING CRYPTOGRAPHICALLY SECURE COMMUNICATIONS ACROSS UNSECURED NETWORKS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/105,173
Abstract

A secure boot device, method, and system for securely connecting a client computer having a secure boot device to a remote server over a communications network are disclosed. The secure boot device includes a housing having an integrated communication interface, a controller located within the housing and operatively connected to the communication interface, and a memory communicatively connected to the programmable circuit and the communication interface. The memory securely stores program instructions including a boot module, a client terminal process module, an operating system module, and a secure communications interface module. The secure communications interface module includes program instructions for communicating split and encrypted data communicated between a computing system to which the communication interface is connected and a remote computing system.

Claims (48)

1 . A secure boot device comprising:

a housing having an integrated communication interface;

a controller located within the housing and operatively connected to the communication interface;

a memory communicatively connected to the programmable circuit and the communication interface, the memory securely storing program instructions comprising:

a boot module;

a client terminal process module;

an operating system module; and

a secure communications interface module, the secure communications interface module including program instructions for communicating split and encrypted data communicated between a computing system to which the communication interface is connected and a remote computing system.

2 . The secure boot device of claim 1 , wherein the housing is sized to fit in a hand of a user.

3 . The secure boot device of claim 1 , wherein the communication interface comprises a USB interface.

4 . The secure boot device of claim 1 , wherein the boot module enables a computing system to which the secure boot device is connected to boot from the secure boot device into the operating system module.

5 . The secure boot device of claim 4 , wherein the client terminal process module is configured to, when executed, authenticate a user at an authorization server remote from the computing system when booting from the secure boot device.

6 . The secure boot device of claim 4 , wherein the client terminal process module is configured to, when executed, provide a client terminal at the computing system for communication with the remote computing system, the client terminal configured to generate a user interface useable in connection with the secure communication interface module to communicate with the remote computing system.

7 . The secure boot device of claim 4 , wherein the operating system module is configured to deactivate one or more hardware devices of the computing system when the computing system is booted from the boot module.

8 . The secure boot device of claim 4 , wherein the boot module, client terminal process module, operating system module, and secure communications interface module are stored in a secured area of the memory, the secured area of the memory configured to be written to only by authorized computing systems remote from the computing system.

9 . The secure boot device of claim 8 , wherein the authorized computing systems include the remote computing system and an authorization server remote from the computing system and the remote computing system.

10 . The secure boot device of claim 1 , wherein the secure communications interface module includes one or more encryption keys configured for use to encrypt and split data transmitted to the remote computing system.

11 . The secure boot device of claim 1 , wherein the secure communications interface module is configured to generate a security code useable to authenticate the secure boot device at an authentication server or a remote computing system.

12 . A method of establishing a secure connection between a local computing system and a remote computing system, the method comprising:

booting a local computing system from a boot module of a secure boot device, the secure boot device including a memory storing the boot module, a client terminal process module, an operating system module, and a secure communications interface module;

authenticating the secure boot device;

upon authenticating the user, establishing a secure connection between the local computing system and the remote computing system, the secure connection configured for communication of cryptographically split data.

13 . The method of claim 12 , wherein authenticating the secure boot device includes:

receiving user credentials from a user at the local computing system;

transmitting user credentials from the local computing system to an authentication system;

selecting one or more encryption keys for use by the local computing system, each of the one or more encryption keys associated with a community of interest that includes the user.

14 . The method of claim 12 , wherein selecting one or more encryption keys for use by the local computing system includes receiving the one or more encryption keys from the authentication system.

15 . The method of claim 12 , wherein selecting one or more encryption keys for use by the local computing system include selecting keys from among a set of keys stored in the memory of the secure boot device.

16 . The method of claim 12 , further comprising, prior to booting the local computing system, configuring the local computing system based on data stored on the secure boot device.

17 . The method of claim 16 , wherein configuring the local computing system comprises:

collecting data for USB configuration; and

modifying a BIOS configuration setting of the local computing system to allow the local computing system to boot from the secure boot device.

18 . The method of claim 12 , wherein the remote computing system comprises a financial institution.

19 . The method of claim 12 , further comprising, upon booting a local computing system from a boot module of a secure boot device, disabling one or more hardware devices of the local computing system, thereby preventing modification of the operating system module.

20 . A system for securely connecting a client computer having a secure boot device to a remote server over a communications network, the system comprising:

a general purpose computing device having a peripheral interface and a network interface connected to a communications network;

a secure boot device connected to the general purpose computing device via the peripheral interface; and

a set of processing modules loaded onto the general purpose computing device from the secure boot device that, when executed, provide a secure communications connection over the communications network to a remote server;

wherein the set of processing modules comprise:

a boot module;

a client terminal process module;

a small operating system shell; and

a secure communications interface module.

21 . The secure communication system of claim 20 , further comprising an authorization system configured to authorize communication between the general purpose computing device and the remote server based on credentials received from the client terminal process module.

22 . The secure communication system of claim 21 , wherein the authorization system is located within a service enclave at a managed service provider.

23 . The secure communication system of claim 22 , wherein the remote server is located within a customer enclave at a managed service provider.

24 . The secure communication system of claim 23 , wherein the remote server is associated with a financial institution.

25 . The secure communication system of claim 20 , wherein the remote server is a web services server.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Nov 9, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION (SUCCESSOR TO GENERAL ELECTRIC CAPITAL CORPORATION)
To: UNISYS CORPORATION
Reel/Frame 044416/0358 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2013
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL TRUSTEE
To: UNISYS CORPORATION
Reel/Frame 030082/0545 →
RELEASE OF SECURITY INTEREST Recorded Mar 15, 2013
From: DEUTSCHE BANK TRUST COMPANY
To: UNISYS CORPORATION
Reel/Frame 030004/0619 →
SECURITY AGREEMENT Recorded Aug 2, 2011
From: UNISYS CORPORATION
To: DEUTSCHE BANK NATIONAL TRUST COMPANY
Reel/Frame 026688/0081 →
SECURITY AGREEMENT Recorded Jun 27, 2011
From: UNISYS CORPORATION
To: GENERAL ELECTRIC CAPITAL CORPORATION, AS AGENT
Reel/Frame 026509/0001 →