Notebook security system (NBS)

5 downloads 16829 Views 1MB Size Report
Jul 31, 1998... 12, 1999, International Filing. Date Jul. 29, 1999, applicant Durango Corporation. SecurityPak—Complete Computer Security Solution, found.
US006216230B1

(12) United States Patent

(10) Patent N0.: (45) Date of Patent:

Rallis et al.

(54) NOTEBOOK SECURITY SYSTEM (NBS)

US 6,216,230 B1 Apr. 10, 2001

M—Crypt—The Ideal in Laptop and Desktop Protection, found at (Jan. 13, 1998).

Yaacov Behar, Winchester, both of MA

(Us) (73) Assignee: Durango Corporation, Framingham, MA (US) (*)

Notice:

SafeHouse for Windows, found at (Jan. 13, 1998). Are Smartcards a Certi?cate Solution‘), found at (Feb. 4, 1998). Serial Cable With Security Key, found at (Feb. 4, 1998). EY—LOK II dongle security devices, found at (Feb. 4, 1998). SecuriKey for PCs, found at (Feb. 4, 1998).

(21) Appl. No.: 09/127,218

bluVenom Anti—Theft Devices Inc., found at (Feb. 2, 1998).

Jul. 31, 1998

(List continued on neXt page.)

Related US. Application Data (63)

Continuation-in-part of application No. 09/022,088, ?led on Feb. 11, 1998.

(51) (52) (58)

Int. Cl.7 ............................... .. H04L 9/10; H04L 9/32 US. Cl. ......................... .. 713/185; 713/172; 713/202 Field of Search ................................... .. 713/159, 169,

713/170, 172, 173, 185, 202; 705/72 (56)

(74) Attorney, Agent, or Firm—Cesari and McKenna, LLP

(57)

ABSTRACT

A multi-level security system prevents unauthorized use of a computer. Aprogram resident on the computer and imple ments a user-validation procedure. A key device carries a

References Cited

?rst serial number and an encryption key. A second serial number is stored in said computer, the second serial number being the serial number of a device internal to the computer.

U.S. PATENT DOCUMENTS 4,789,859 4,937,437

Primary Examiner—Tod R. SWann Assistant Examiner—Justin T. DarroW

12/1988 Clarkson et al. ............. .. 340/825.31 6/1990 Ferguson ............................ .. 235/382

A mass storage device installed in said computer stores a validation record. The validation record comprises an unen

crypted portion and an encrypted portion, the unencrypted

(List continued on neXt page.) OTHER PUBLICATIONS

Wiener, P. et al., “Meeting USB and IEEE 1394 Overcurrent

Protection Requirements Using PolySWitch Devices,” Wescon/97 Conf. Proc., Nov. 6, 1997, pp. 442—475.* International Search Report—International Application No. PCT/US 99/17315, dated Oct. 12, 1999, International Filing

Date Jul. 29, 1999, applicant Durango Corporation. SecurityPak—Complete Computer Security Solution, found at (Jan. 13,

portion including a copy of said ?rst serial number and said encrypted portion including a copy of said second serial number and a user personal identi?cation number. The key device is interfaced to the computer. The ?rst serial number and the encryption key are read from said key device in order to gain authorized use of said computer. The key device may be removed from the computer after authorized

use of the computer has been gained, and during operation of the computer.

30 Claims, 16 Drawing Sheets

1998). r PROMPT useR TO ATTACH Kev DEVICE

Kev DEWCE AVNLAELE v

NO

{me our) 2 new KEY DEVlCE seam NUMBER AND eNcnwnoN KEY a COMPARE seam NUMBER vwu seam. NUMBERS STORED m UDATlQN Reco '

(1 ) 9 VAUDATE USER

US 6,216,230 B1 Page 2

US. PATENT DOCUMENTS 4,975,550

12/1990 Panchisin ........................ .. ZOO/43.08

4,993,627

2/1991 Phelan 9t 91-

5,012,514

- 235/382

4/1991 Renton

5,072,101 5,077,991

12/1991 Ferguson 1/1992 Stickel er a1

5,142,269

8/1992

5,265,163

Mueller ----- --

2/1994

ima e

380/25

395/341 200/4308

380/25

70/58 - 340/568

5,655,020 * 5,657,470

8/1997 8/1997

Powers ................................. .. 380/25 Fisherman et a1. ................ .. 395/480

380/25

5,732,137

*

3/1998

AZiZ

~- 380/4

5,867,106

*

2/1999

Bi et a1. ........................ .. 340/82531

340/825.31 ~~~~ ~~ 380/25

al' s

.. 340/825.34

7/1997 Klemba et a1.

11/1994 Gokcebay et a1. . 3/1995 Goodman et a1~ u

4/1997 Jones et a1.

........... ..

7/1997 Tefft ........... ..

5,367,295 5,402,492 ,

5,623,637

Davies

5,642,805

8/1994 Ugon ...................................... .. 380/4 11/1994 Sanders .................................. .. 70/14

,

3/1997 Mooney et aL _

5,651,068

Samson ----- ~-

gag‘;

576107981

380/4

5,341,421 5,361,610

*

2/1997 Lapointe et a1. ..................... .. 380/45 3/1997

- 235/441

11/1993 Golding er a1

5,287,408

5,606,615 5,608,387

.............

. . . ..

380/25

OTHER PUBLICATIONS

EliaShirn releases EasySafe Version 3.1 To Secure Data on

DOS/Windows & Windows 95 Laptops, found at

a

e n,

5,572,193 * 11/1996 Flanders et a1. .............. .. 340/825.34

LtOl-)

5,587,878

[email protected] (California Wireless, Inc.).

12/1996 Tsai et a1, Muller ....... ..

361/683

5,598,323

1/1997

5,603,008

2/1997 Hilton et a1. ....................... .. 395/491

y me“

Pem~NYkanen@n¥nP-n°k1a-C9m (Nokla Moblle Phon‘? Paul Rubln Phr@W1r@19SS-C0In,

. 361/726

* cited by eXarniner

Mlke

ChePOIllS

U.S. Patent

Apr. 10,2001

Sheet 1 0f 16

US 6,216,230 B1

J10

f//////_/,, //////////

P20 FIG. 1A

22

HP 24

ROM

261 FIG. 1 B

U.S. Patent

Apr. 10, 2001

Sheet 2 0f 16

US 6,216,230 B1

U.S. Patent

Apr. 10, 2001

Sheet 3 0f 16

US 6,216,230 B1

@

1. PROMPT USER TO ATTACH KEY DEVICE

KEY DEVICE AVAILABLE ?

NO

II

(TIME OUT) 2. READ KEY DEVICE SERIAL NUMBER AND ENCRYPTION KEY

I

II

3. COMPARE SERIAL NUMBER WITH SERIAL NUMBERS STORED IN

VAL_HDAT|(_)N RECORD N

MATCH?

O

=

YES 4. PASS VALIDATION RECORD THRU ENCRYPTION FUNCTION AND DECRYPT RECORD USING ENCRYPTION KEY N

PLAIN TEXT ? YES

I

11. FAILURE/SHUT-DOWN POWER TO COMPUTER II

s. PROMPT USER TO ENTER PIN

I 6. COMPARE PIN WITH PLAIN TEXT PIN OF VALIDATION RECORD NO MATCH?

>

YES

I

7. READ HARD DISK SERIAL NUMBER

I 8. COMPARE HARD DISK SERIAL NUMBER WITH PLAIN TEXT HARD DISK SERIAL NUMBER OF VALIDATION RECORD

%

NO

MATCH?

=

FIG. 3A

|

II

U.S. Patent

I

Apr. 10, 2001

Sheet 4 0f 16

US 6,216,230 B1

9. VALIDATE USER 10. PROMPT USER TO REMOVE KEY DEVICE

FIG. 3B

I

U.S. Patent

Apr. 10, 2001

NNV A>5.

Sheet 5 0f 16

US 6,216,230 B1

»

2 ~

omw

A

.GE3»

8E6054 25 QQ