Security system and method for controlling access to computing resources

Patent No. US9251332 (titled "Security system and method for controlling access to computing resources") on Dec 19, 2008. The application was issued on Feb 2, 2016.

What is this patent about?

’332 is related to the field of proximity-based security for computing resources. It addresses the administrative burden and security risks associated with managing multiple passwords and sensitive files across various devices. The background context involves the need for a non-intrusive, automatic way to secure local files and third-party system logins without requiring the user to manually encrypt data or memorize a vast array of credentials.

The underlying idea behind ’332 is the decoupling of security instructions from the actual credentials required for access. By utilizing a personal digital key (PDK) as a portable hardware token, the system ensures that sensitive credentials never reside permanently on the host computer. Instead, the host stores only the logic for how to handle a resource, while the physical presence of the PDK provides the necessary data to unlock it, creating a seamless security perimeter that moves with the user.

The claims of ’332 focus on a tripartite architecture consisting of a PDK, a reader, and a computing device that utilizes a vault storage located in a dedicated encrypted portion of the host memory. This vault contains security setup data—user-defined rules and logic for different resources—but specifically lacks the actual security data (credentials) needed for access. The claims also emphasize the use of exit-based rules that automatically terminate access or trigger security actions when the PDK moves out of a predefined wireless range.

In practice, the system functions through a detection engine that monitors for triggers, such as a web browser displaying a sign-on screen or a user attempting to open a protected directory. When a trigger is detected, the engine checks for a linked PDK via the reader. If the key is present, the system retrieves the specific handling instructions from the vault and the required credentials from the PDK to automate the login or decryption process. This allows for granular control, where different resources can require different levels of authentication, such as adding a biometric confirmation for high-security files.

This approach differs from prior solutions by eliminating the need for the user to manually specify which files are encrypted or to interact with complex management software during daily use. Unlike standard proximity locks that merely lock the entire workstation, this invention provides resource-specific security actions and automated credential injection. By storing the 'how-to' logic locally and the 'secret' data on the portable key, it ensures that even if the computer is compromised, the sensitive credentials remain physically isolated from the machine once the user walks away.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’332 was filed, digital security for personal computing environments was typically implemented using static authentication methods, such as manual password entry for local OS login and individual web-based services. At a time when users were increasingly managing a high volume of disparate credentials for third-party systems, security architectures commonly relied on local software-based password managers or manual user intervention rather than automated hardware-proximity triggers. Hardware and software constraints of the era made the seamless, background synchronization of encrypted credentials between a portable physical token and a host workstation non-trivial, often requiring active user engagement to initiate secure sessions or decrypt sensitive local file directories.

Prosecution Position

The disclosed invention represents a technical advancement in access control through the integration of a wireless personal digital key (PDK) and a dedicated reader that automate the authentication lifecycle based on physical proximity. The architectural shift involves a detection engine that monitors system events and wireless link status to dynamically grant or deny access to both local files and remote third-party systems without requiring manual credential entry. This configuration enables a background security layer where encrypted vault storage—containing diverse usernames and passwords—is unlocked only when a specific radio frequency link is maintained. By overcoming the technical constraint of manual authentication overhead, the system achieves a non-intrusive security state that protects sensitive data and manages complex credential sets automatically as the user moves in and out of range of the computing device.

Claims

The patent contains a total of 23 claims, with claims 1, 10, and 12 serving as the independent claims. These independent claims focus on a system, a security architecture, and a method for controlling access to computing resources by utilizing a wireless personal digital key that interacts with a reader to trigger security actions based on proximity, specifically employing encrypted setup data and user-defined rules like biometric confirmation and exit-based termination. The dependent claims serve to further define the hardware components, such as USB connectors and transceivers, specify the types of security information and events monitored, and detail the execution of specific entry, exit, and time-based rules for managing resource access.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Detection engine
(Claim 10)
The detection engine detects events relating to the access any files and third-party systems by the computing device and receives information from the reader as to whether the PDK is present/linked. The detection engine controls whether a user is able to access any of the functionality provided by the computing device based upon whether the PDK is in communication with the reader or not.A functional component that monitors for access events and determines if access should be granted or denied based on the proximity of the personal digital key and the rules defined in the vault storage.
Exit-based rule
(Claim 1, Claim 10)
The security system is controlled by the signal from the reader indicating whether the reader is linked to the personal digital key and terminating access to the computing resource based on an exit-based rule. The detection engine controls whether a user is able to access any of the functionality provided by the computing device based upon whether the PDK is in communication with the reader or not. This allows the system to automatically deny access to functionality.A specific security instruction within the set up data that triggers the termination of access to a resource when the personal digital key moves outside the wireless communication range.
Item set up record
(Claim 12)
Allowing and terminating access is based on the item set up record associated with the computing resource. The item set up record includes one or more user defined options allowing a user to implement different security actions for different computing resources. It includes information on how to use the security data stored by the personal digital key to control access to the computing resource, but lacks the security data itself.A specific data entry or record stored in encrypted memory that associates a computing resource with user-defined security actions and instructions on how to apply security data.
Personal digital key
(Claim 1, Claim 10, Claim 12)
The PDK is a portable, personal transceiver that includes a controller and one or more passwords or codes. The PDK is able to link and communicate with the reader via a wireless radio frequency (RF) signal. The PDK and/or the vault storage include encrypted information such as usernames, passwords and other information utilized by the computing device to grant access.A portable, personal transceiver that includes a controller and stores security data (such as passwords or codes) used to access specific computing resources.
Security set up data
(Claim 1, Claim 10)
The security set up data is stored in a dedicated encrypted portion of a memory of the computing device and includes information on how to control access to the computing resources using security data, but does not include the security data used to obtain access. The security set up data is based on one or more user defined options allowing the user to implement different security actions for different computing resources. These actions can include biometric confirmation.Configuration information stored in a dedicated encrypted memory portion that defines how to control access to resources using security data, without containing the actual security data itself.
Vault storage
(Claim 10)
The computing device includes a detection engine, vault storage and a set up module. The vault storage includes encrypted information such as usernames, passwords and other information utilized by the computing device to grant access to components, files and third-party systems. It is stored in a dedicated encrypted portion of a memory of the computing device.A dedicated, encrypted storage area within the computing device's memory used to hold the security set up data and instructions for utilizing the personal digital key's security data.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
6:25-cv-00016Jan 14, 2025Proxense, Llc V. Hyundai Motor Company

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9251332

Application Number
US12340501A
Filing Date
Dec 19, 2008
Publication Date
Feb 2, 2016
External Links
Slate, USPTO , Google Patents