Method for handling data in a secure container

    公开(公告)号:US11102014B2

    公开(公告)日:2021-08-24

    申请号:US16262261

    申请日:2019-01-30

    Applicant: Safenet Inc.

    Abstract: The invention is a method for handling data in a secure container comprising first and second private keys uniquely allocated to the secure container. The secure container is configured to use the first private key to handle said data in a first operating mode and to use the second private key to handle said data in a second operating mode. The secure container is configured to prevent the update of the first private key after its clearing. The method comprises the step of automatically clearing the first private key in response to a request for enabling a software module in the second operating mode and a step of automatically using the first operating mode by the secure container if the first private key has not been cleared and of automatically using the second operating mode by the secure container if the first private key has been cleared.

    SYSTEMS AND METHODS FOR CONTROLLING ILLNESS RISK INFORMATION

    公开(公告)号:US20230326611A1

    公开(公告)日:2023-10-12

    申请号:US17714759

    申请日:2022-04-06

    CPC classification number: G16H50/80 H04L51/046 G16H50/30 G16H10/20

    Abstract: A system for controlling notifications relating to illness information includes a processor and memory. The processor is configured to set first criteria for (1) vital information, (2) questionnaire response information, (3) vaccination information, and (4) illness test result information, the first criteria relating to a first illness, receive first data relating to an illness risk of a first user, the first data including (1) vital information, (2) questionnaire response information, (3) vaccination information, and (4) illness test result information, of the first user, and determine, based on the first criteria and the first data, whether the first user has an illness risk. In response to determining that the first user has an illness risk, the processor is configured to send to the first user an illness risk notification.

    METHOD, CHIP, DEVICE AND SYSTEM FOR AUTHENTICATING A SET OF AT LEAST TWO USERS

    公开(公告)号:US20210203657A1

    公开(公告)日:2021-07-01

    申请号:US16730722

    申请日:2019-12-30

    Applicant: SafeNet, Inc.

    Abstract: A set of users who may authenticate is predefined and is associated, each, with a reference secret share. A first subset of users who has, each, to authenticate is predefined. The device defines a second subset of the users who has, each, to authenticate while further satisfying, each, to be physically proximate to the device and an authentication condition(s). The second user subset is comprised within the first user subset comprised within the user set. The device verifies whether each user of the second user subset satisfies to be physically proximate to the device and the authentication condition(s), if yes, requests, to each user device, the secret share and receives, from each user device relating to at least the first user subset, the secret share. The device reconstructs a secret with each received secret share, verifies whether the reconstructed matches the reference and, if yes, authenticates the user set.

    ASSEMBLY FOR DETECTING AN INTRUSION INTO AN APPLIANCE AND A CORRESPONDING APPLIANCE

    公开(公告)号:US20210199413A1

    公开(公告)日:2021-07-01

    申请号:US16728725

    申请日:2019-12-27

    Applicant: SafeNet, Inc.

    Inventor: James ANDRASI

    Abstract: An assembly allows detecting an intrusion into an appliance that includes a chamber(s). At least one wall relating to one and the same chamber is designed, so as to form a chamber opening allowing to access at least one appliance chip. The assembly includes at least one baffle that is, each, disposed at the chamber opening. The assembly includes at least one chip that comprises a baffle manager. The baffle manager is configured to cause the at least one baffle to move repeatedly between a first and a second position with respect to the chamber opening, during an appliance chip operation. The baffle manager is configured to detect whether a baffle movement is slowed or blocked during the appliance chip operation. If yes, the baffle manager is configured to send a predetermined signal(s) for alerting the appliance chip or a device(s) or take an action(s).

    Methods for securely managing a paper document

    公开(公告)号:US10956590B2

    公开(公告)日:2021-03-23

    申请号:US16166770

    申请日:2018-10-22

    Applicant: SAFENET INC.

    Abstract: A method for securely accessing a document containing a set of data comprises (a) detecting the existence of target data belonging to an enhanced version of the document and missing from the current version of the document, (b) generating a link value allocated to the target data by applying a preset function to a subset of said set of data, (c) retrieving metadata from a secure storage unit by using the link value and, using a message based on said metadata, proposing to the user to get the target data, (d) getting both agreement of the user and credentials of the user, (e) generating a request by using the link value and said credentials for retrieving the target data from the secure storage unit, (f) providing the user with the target data only if the secure storage unit successfully checked the compliance of the request with preset access rules.

    Method for securing a digital document

    公开(公告)号:US10970408B2

    公开(公告)日:2021-04-06

    申请号:US16156353

    申请日:2018-10-10

    Applicant: SAFENET INC.

    Abstract: A method for securing a digital document comprising first and second types of data, where a set of data of the second type is previously identified in an initial version of the document. For each data of the second type, an identifier is allocated to the data and an entry comprising the data is stored in a secure storage unit. The identifier comprises a display value and a link value. The data is reachable in the secure storage unit through the link value. The secure storage unit is configured to use access rules for authorizing or denying a request initiated by a user for accessing data of the second type contained in an entry of the secure storage unit. An updated version of the digital document is generated by replacing each data of the second type by its allocated identifier in the initial version of the digital document.

    Kernel mode protection
    7.
    发明申请

    公开(公告)号:US20020051538A1

    公开(公告)日:2002-05-02

    申请号:US09897670

    申请日:2001-07-02

    Applicant: SafeNet, Inc.

    Abstract: A kernel mode protection circuit includes a processor, a program counter, a kernel program fetch supervisor circuit, a kernel data fetch supervisor circuit, a program memory, a data memory, a flip-flop circuit and two AND circuits. The data memory includes two user memories, protected registers and random access memory (RAM). The program memory includes two user memories and a kernel read only memory (ROM). The circuit may operate in either a user mode (kernel ROM is not accessible) or a kernel mode (kernel ROM is accessible). When in the kernel mode the kernel RAM and certain protected registers are accessible only by a secure kernel. The kernel mode control circuit will reset the processor should a security violation occur, such as attempting to access the kernel RAM while in the user mode. The kernel program fetch supervisor circuit monitors and compares an address within the program counter to a predetermined address, stored within the kernel program fetch supervisor circuit, to determine if a security violation has occurred. The kernel data fetch supervisor circuit monitors and compares the data address to addresses defining a protected memory area. A security violation will occur if the data address is within the protected memory address range and the processor will be reset. A method of kernel mode protection includes the step of fetching a program opcode. If the program opcode is from the kernel memory, the processor is reset. If the program opcode is from a user memory, then the processor may fetch the data operand. If the data operand is fetched from the kernel memory, the processor is reset. If the data operand is fetched from a user memory, the processor is permitted to enter the kernel memory. If a program opcodes is fetched from the kernel memory the processor may continue to fetch operands from either the kernel memory or the data memory. The processor remains in kernel mode and continues to fetch program opcodes until all of the opcodes have been fetched, or until an opcode fetched is from the user memory. If an opcode fetched is from the user memory, the processor switches back to user mode.

    Method, first device, second device and system for managing access to data

    公开(公告)号:US10963167B2

    公开(公告)日:2021-03-30

    申请号:US15858882

    申请日:2017-12-29

    Abstract: The invention relates to a method for managing data access. The method includes receiving at least one request for accessing data; capturing data relating to at least one current context signal during each data access request; comparing, as a current authorization step, the data relating to at least one captured current context signal to predetermined reference data relating to at least one corresponding context signal according to at least one corresponding predetermined authorization policy; determining, based upon the current authorization result and at least one predetermined dynamic data access policy, whether the data access is or is not authorized, as a data access decision; and issuing the data access decision. The invention also relates to corresponding first device, second device and system.

    Constrained Information Transfer
    9.
    发明申请
    Constrained Information Transfer 审中-公开
    限制信息传递

    公开(公告)号:US20160085975A1

    公开(公告)日:2016-03-24

    申请号:US14490093

    申请日:2014-09-18

    Applicant: SafeNet, Inc.

    CPC classification number: G06F21/62 H04L67/12 H04W12/00522 H04W12/02

    Abstract: A secure processing facility has a plurality of workstations, with associated computers to provide data to, and/or receive data from, the workstations. The computers are provided with a visual display unit, and display machine-readable data codes on the display. The computers are provided with a scanner to read the machine-readable data codes on the display of another of the computers. The computers have no other connection to receive or transmit machine readable data. A method of operating the facility includes processing a workpiece at a first workstation. A display of the computer of the first workstation displays a data code containing data related to the processing of the workpiece. The scanner of the computer associated with a second workstation scans the data code. The workpiece is transferred from the first workstation to the second workstation. The workpiece is processed at the second workstation.

    Abstract translation: 安全处理设备具有多个工作站,其中相关联的计算机向工作站提供数据和/或从工作站接收数据。 这些计算机设置有可视显示单元,并且在显示器上显示机器可读数据代码。 这些计算机设有扫描仪,用于读取另一台计算机的显示器上的机器可读数据代码。 计算机没有其他连接来接收或发送机器可读数据。 操作该设备的方法包括在第一工作站处处理工件。 第一工作站的计算机的显示器显示包含与工件的处理相关的数据的数据代码。 与第二工作站相关联的计算机的扫描器扫描数据代码。 工件从第一个工作站传送到第二个工作站。 工件在第二个工作站处理。

    SYSTEMS AND METHODS FOR MONITORING BODY TEMPERATURE

    公开(公告)号:US20220018715A1

    公开(公告)日:2022-01-20

    申请号:US17330178

    申请日:2021-05-25

    Abstract: An autonomous vehicle control system includes at least one processor. The at least one processor is configured to cause a first device to monitor a body temperature of a first person, determine, responsive to the monitoring, as a first determination result, whether the monitored body temperature exceeds a predetermined threshold, perform image processing on an image of the first person, determine, based on a result of the image processing, as a second determination result, whether the first person wears a face mask, and control a second device based on at least one of the first determination result or the second determination result.

Patent Agency Ranking