Pocket encrypting and authenticating communications device
First Claim
1. An encrypting and authenticating communications device for establishing a secure communications link for data exchanged over a communications network between one of a plurality of remote computing systems and a computing system of a user, the device comprising:
- computer processing means, the computer processing means controlling establishment of the secure communications link;
encrypting means, the encrypting means being electrically interconnected with the computer processing means, the encrypting means encrypting data transmitted from the computing system of the user to one of the plurality of remote computing systems and decrypting data received from one of the plurality of remote computing systems by the computing system of the user;
authenticating means, the authenticating means being electrically interconnected with the computer processing means, the authenticating means authenticating to one of the plurality of remote computing systems that the device is authorized;
network interfacing means, the network interfacing means being electrically interconnected with the computer processing means, the network interfacing means establishing a data interface compatible with the communications network for allowing the device to transmit and receive data over the communications network; and
a compact housing, the housing containing the computer processing means, the encrypting means, the authenticating means and the network interfacing means therein, the housing having electrical interconnection means for establishing electrical interconnection of the device with the communications network and the computing system of the user.
10 Assignments
0 Petitions
Accused Products
Abstract
A portable security device is disclosed which can be carried by an individual and connected directly to telephone circuits to both authenticate that individual and encrypt data communications. The invention can operate as an electronic "token" to uniquely identify the user to a network, to a computer system or to an application program. The "token" contains the complete network interface, such as a modem, which modulates the data and provides the circuitry required for direct connection to the network. Furthermore, this "token" will preferably not permit communications to proceed until the device, and optionally the user, have been identified by the proper authentication. The token also contains all of the cryptographic processing required to protect the data using data encryption or message authentication or digital signatures or any combination thereof. Thus, the present invention provides the user with all of the communications and security equipment needed for use with personal computers and electronic notebooks and eliminates the need for any other security measures and/or devices.
-
Citations
22 Claims
-
1. An encrypting and authenticating communications device for establishing a secure communications link for data exchanged over a communications network between one of a plurality of remote computing systems and a computing system of a user, the device comprising:
-
computer processing means, the computer processing means controlling establishment of the secure communications link; encrypting means, the encrypting means being electrically interconnected with the computer processing means, the encrypting means encrypting data transmitted from the computing system of the user to one of the plurality of remote computing systems and decrypting data received from one of the plurality of remote computing systems by the computing system of the user; authenticating means, the authenticating means being electrically interconnected with the computer processing means, the authenticating means authenticating to one of the plurality of remote computing systems that the device is authorized; network interfacing means, the network interfacing means being electrically interconnected with the computer processing means, the network interfacing means establishing a data interface compatible with the communications network for allowing the device to transmit and receive data over the communications network; and a compact housing, the housing containing the computer processing means, the encrypting means, the authenticating means and the network interfacing means therein, the housing having electrical interconnection means for establishing electrical interconnection of the device with the communications network and the computing system of the user. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21)
-
-
22. An encrypting and authenticating communications device for establishing a secure communications link for data exchanged over a communications network between one of a plurality of remote computing systems and a computing system of a user, the device comprising:
-
first and second connector ports, the first connector port being electrically interconnected with the communications network and the second connector port being electrically interconnected with the computing system of the user; a smartcard receptacle for accepting a smartcard; first and second indicators; a cryptographic module, the cryptographic module performing at least one of an encryption and authentication function and including a microprocessor, a system memory, an input/output controller, a crypto engine and a communications controller, all being electrically interconnected via a microprocessor bus; and an interface module, the interface module performing system interfacing functions and including a network interface, a smartcard interface and a communications port interface, the network interface being electrically interconnected with the first connector and the communications controller, the smartcard interface being electrically interconnected with the smartcard receptacle and to the input/output controller, the first and second indicators being respectively electrically interconnected with the input/output controller and the communications port interface being electrically interconnected with the second connector and the communications controller; transmit data from the computer system of the user entering the device through the second connector and being buffered and transferred by the communications port interface to the communications controller, the communications controller formatting and placing the transmit data on the microprocessor bus, the microprocessor, in conjunction with the system memory and in response to the transmit data being placed on the microprocessor bus, causing the transmit data to be transferred to the crypto engine, the crypto engine performing at least one of encrypting and authenticating the transmit data, the smartcard sending a user identification code to the crypto engine via the smartcard interface and the input/output controller for performing the authenticating function, the microprocessor then transferring the transmit data back to the communications controller, the communications controller reformatting and sending the transmit data to the network interface, the network interface modulating the transmit data for transmission onto the communications network via the first connector; receive data received from one of the plurality of remote computer systems over the communications network entering the device through the first connector, the network interface demodulating the receive data for manipulation by the device in response to entry of the receive data, the network interface transferring the receive data to the communications controller, the communications controller formatting the receive data and placing the receive data on the microprocessor bus, the microprocessor, in conjunction with the system memory and in response to the receive data being placed on the microprocessor bus, causing the receive data to be transferred to the crypto engine, the crypto engine performing at least one of decrypting and validating the receive data, the microprocessor then transferring the receive data back to the communications controller, the communications controller reformatting and providing the receive data to the communications port interface, the communications port interface converting the transmit data for transmission to the computer system of the user via the second connector; the first and second indicators being electrically interconnected with the microprocessor via the input/output controller and providing device status indications to the user.
-
Specification