Patent No. US9251332 (titled "Security system and method for controlling access to computing resources") on Dec 19, 2008. The application was issued on Feb 2, 2016.
’332 is related to the field of proximity-based security for computing resources. It addresses the administrative burden and security risks associated with managing multiple passwords and sensitive files across various devices. The background context involves the need for a non-intrusive, automatic way to secure local files and third-party system logins without requiring the user to manually encrypt data or memorize a vast array of credentials.
The underlying idea behind ’332 is the decoupling of security instructions from the actual credentials required for access. By utilizing a personal digital key (PDK) as a portable hardware token, the system ensures that sensitive credentials never reside permanently on the host computer. Instead, the host stores only the logic for how to handle a resource, while the physical presence of the PDK provides the necessary data to unlock it, creating a seamless security perimeter that moves with the user.
The claims of ’332 focus on a tripartite architecture consisting of a PDK, a reader, and a computing device that utilizes a vault storage located in a dedicated encrypted portion of the host memory. This vault contains security setup data—user-defined rules and logic for different resources—but specifically lacks the actual security data (credentials) needed for access. The claims also emphasize the use of exit-based rules that automatically terminate access or trigger security actions when the PDK moves out of a predefined wireless range.
In practice, the system functions through a detection engine that monitors for triggers, such as a web browser displaying a sign-on screen or a user attempting to open a protected directory. When a trigger is detected, the engine checks for a linked PDK via the reader. If the key is present, the system retrieves the specific handling instructions from the vault and the required credentials from the PDK to automate the login or decryption process. This allows for granular control, where different resources can require different levels of authentication, such as adding a biometric confirmation for high-security files.
This approach differs from prior solutions by eliminating the need for the user to manually specify which files are encrypted or to interact with complex management software during daily use. Unlike standard proximity locks that merely lock the entire workstation, this invention provides resource-specific security actions and automated credential injection. By storing the 'how-to' logic locally and the 'secret' data on the portable key, it ensures that even if the computer is compromised, the sensitive credentials remain physically isolated from the machine once the user walks away.
In the late 2000s when ’332 was filed, digital security for personal computing environments was typically implemented using static authentication methods, such as manual password entry for local OS login and individual web-based services. At a time when users were increasingly managing a high volume of disparate credentials for third-party systems, security architectures commonly relied on local software-based password managers or manual user intervention rather than automated hardware-proximity triggers. Hardware and software constraints of the era made the seamless, background synchronization of encrypted credentials between a portable physical token and a host workstation non-trivial, often requiring active user engagement to initiate secure sessions or decrypt sensitive local file directories.
The disclosed invention represents a technical advancement in access control through the integration of a wireless personal digital key (PDK) and a dedicated reader that automate the authentication lifecycle based on physical proximity. The architectural shift involves a detection engine that monitors system events and wireless link status to dynamically grant or deny access to both local files and remote third-party systems without requiring manual credential entry. This configuration enables a background security layer where encrypted vault storage—containing diverse usernames and passwords—is unlocked only when a specific radio frequency link is maintained. By overcoming the technical constraint of manual authentication overhead, the system achieves a non-intrusive security state that protects sensitive data and manages complex credential sets automatically as the user moves in and out of range of the computing device.
The patent contains a total of 23 claims, with claims 1, 10, and 12 serving as the independent claims. These independent claims focus on a system, a security architecture, and a method for controlling access to computing resources by utilizing a wireless personal digital key that interacts with a reader to trigger security actions based on proximity, specifically employing encrypted setup data and user-defined rules like biometric confirmation and exit-based termination. The dependent claims serve to further define the hardware components, such as USB connectors and transceivers, specify the types of security information and events monitored, and detail the execution of specific entry, exit, and time-based rules for managing resource access.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents