Electronic system and method for controlling access through...

Electrical computers and digital processing systems: support – Data processing protection using cryptography

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

C713S155000, C713S159000, C713S182000, C713S185000

Reexamination Certificate

active

06633981

ABSTRACT:

BACKGROUND
1. Field
The present invention relates to the field of data security. More particularly, this invention relates to an electronic system and method for controlling access to stored information through enforcement of an improved user authentication technique.
2. General Background
In today's society, it has become necessary to protect information stored within a computer in order to prevent unauthorized persons from downloading information onto a floppy disk, digital tape or other type of storage device. In certain situations, this information may be sensitive in nature such as a trade secret or privileged information. The importance of controlling user access to information stored on a computer has encouraged the creation of different access control mechanisms.
Many conventional access control mechanisms are operating system (OS) dependent. For example, in a computer-based password mechanism, user authentication involves the OS requesting the user to manually enter a password after completion of the boot process. The password may be entered via an alphanumeric keyboard or a keypad. If the entered password matches a password locally stored at system configuration of the computer, the user is granted access to the stored information.
Another type of access control mechanism is a smartcard authentication mechanism. Smartcards are an attractive approach for user authentication due to their convenient form factor and their ease of use. However, similar to the other control access mechanisms, user authentication is based on the correct operations of the OS initiating an exchange of messages with the smartcard.
These above-described user authentication protocols are subject to a number of disadvantages. For example, due to their OS dependency, they are subject to deliberate virus-based corruption, which could result in the installation of a backdoor to circumvent the authentication software. More specifically, the virus may modify the “login” portion of the OS so that when a special key combination or sequence is entered, user authentication functionality would be entirely bypassed.
Another conventional access control mechanism involves the Basic Input/Output System (BIOS). At start-up, BIOS code is executed by a processor and an entered password is compared with a preprogrammed password stored in battery-backed memory of the BIOS. If the entered password matches a preprogrammed password, the user is granted access to information stored within the computer. This user authentication protocol is subject to (i) deliberate virus-based corruption, (ii) the physical removal and substitution of the memory device containing the BIOS code, and/or (iii) electrical shortage of pins associated with the battery-backed memory in order to bypass user authentication.
Hence, it is desirable for a more robust user authentication technique, independent of the operations of the OS, for controlling access to stored information.
SUMMARY
Briefly, one embodiment of the present invention relates to a Basic Input/Output System (BIOS) device. The BIOS device comprises an internal memory and a state machine. The internal memory contains a BIOS code. The state machine controls access to a portion of the BIOS code in response to authentication of a portable token in communication with the state machine.


REFERENCES:
patent: 4811393 (1989-03-01), Hazard
patent: 4860352 (1989-08-01), Laurance et al.
patent: 5153581 (1992-10-01), Hazard
patent: 5280527 (1994-01-01), Gullman et al.
patent: 5371794 (1994-12-01), Diffie et al.
patent: 5473692 (1995-12-01), Davis
patent: 5481611 (1996-01-01), Owens et al.
patent: 5539828 (1996-07-01), Davis
patent: 5568552 (1996-10-01), Davis
patent: 5633932 (1997-05-01), Davis et al.
patent: 5751809 (1998-05-01), Davis et al.
patent: 5796840 (1998-08-01), Davis
patent: 5805706 (1998-09-01), Davis
patent: 5805712 (1998-09-01), Davis
patent: 5818939 (1998-10-01), Davis
patent: 5844986 (1998-12-01), Davis
patent: 6311273 (2001-10-01), Helbig

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Electronic system and method for controlling access through... does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Electronic system and method for controlling access through..., we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Electronic system and method for controlling access through... will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-3115448

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.