This class provides, within a computer or digital data processing
system, for processes or apparatus for increasing a system s extension
of protection of system hardware, software, or data from maliciously
caused destruction, unauthorized modification, or unauthorized disclosure.
INFORMATION SECURITY
This class provides for protection of data processing systems,
apparatus, and methods as well as protection of information and
services. Subject matter included in this class includes security
policies, access control, monitoring, scanning data, countermeasures,
usage control, and data protection from maliciously caused destruction,
unauthorized modification, or unauthorized disclosure. This class
also includes protection of hardware, and user protection, e.g.,
privacy, etc.
Electronic Digital Logic Circuitry,
subclass 8 for digital logic circuits acting to disable or prevent
access to stored data or designated integrated circuit structure.
Communications: Electrical,
subclasses 5.2 through 5.74for authorization control without significant data
process features claimed, particularly subclasses 5.22-5.25 for
programmable or code learning authorization control; and subclasses
5.8-5.86 for intelligence comparison for authentication.
Static Information Storage and Retrieval,
subclass 185.04 for floating gate memory device having ability
for securing data signal from being erased from memory cells.
Cryptography,
subclasses 200 through 242for video with data encryption; subclasses 243-246 for
facsimile encryption; subclasses 247-250 for cellular telephone
cryptographic authentication; subclass 251 for electronic game using cryptography;
subclasses 255-276 for communication using cryptography; subclasses
277-47 for key management; and subclasses 287-53 for electrical
signal modification with digital signal handling.
Data Processing: Speech Signal Processing, Linguistics,
Language Translation, and Audio Compression/Decompression,
subclass 273 for an application of speech processing in a security
system.
Data Processing: Financial, Business Practice, Management,
or Cost/Price Determination,
subclass 18 for security in an electronic cash register or
point of sale terminal having password entry mode, and subclass
44 for authorization or authentication in a credit transaction or
loan processing system.
Electrical Computers: Arithmetic Processing And
Calculating,
subclass 135 for electrical digital calculating computer with
specialized input for security.
Electrical Computers and Digital Data Processing
Systems: Input/Output,
subclasses 36 through 51for regulating access of peripherals to computers
or vice-versa; subclasses 107-125 for regulating access of processors
or memories to a bus; and subclasses 200-240 for general purpose
access regulating and arbitration.
Electrical Computers and Digital Processing Systems:
Memory,
subclass 150 for regulating access to shared memories, subclasses
163-164 for preventing unauthorized memory access requests.
Electrical Computers and Digital Processing Systems:
Support,
subclasses 150 through 181for multiple computer communication using cryptography;
subclasses 182-186 for system access control based on user identification
by cryptography; subclass 187 for computer program modification
detection by cryptography; subclass 188 for computer virus detection
by cryptography; and subclasses 189-194 for data processing protection
using cryptography.
Error Detection/Correction and Fault
Detection/Recovery,
subclasses 1 through 57for recovering from, locating, or detecting a system
fault caused by malicious or unauthorized access (e.g., by virus,
etc.).
SECTION III - GLOSSARY
ACCESS CONTROL
The prevention of unauthorized access to resources of
a system or information system, including the prevention of their
use in an unauthorized manner.
INFORMATION
Data with meaning concerning a particular act or circumstance
in general. Note: May include or consist of graphics or text or
numerical or non-numerical values.
MONITORING
Subject matter includes means of watching, tracking, inspecting,
analyzing of system or user activity. This includes the auditing
of system vulnerabilities and system configuration, assessing the
integrity of files within a system, identifying and recognizing
patterns that dictate known attacks, analysis of abnormal activity
patterns, recognizing user activity in regards to policy violations
and operating system audit trail management.
POLICY
Rules for protecting information, services and other
data processing resources.
USAGE CONTROL
Subject matter includes means placing restrictions on computer
and/or user use of applications
USER PROTECTION/PRIVACY
Subject matter includes means for ensuring the state
or integrity of information or data associated with a user.
This subclass is indented under the class definition. Subject matter comprising systems, methods, and apparatus
that provide for the administration and management of rules or regulations
governing the protection of information, services and other data
processing resources involving coordination of more than one security
mechanisms among a plurality of entities, resources, or processes.
This subclass is indented under the class definition. Subject matter comprising systems, methods, and apparatus
for the prevention of unauthorized access to resources of a system
or information system, including the manner of identifying and verifying
the entity, process, or mechanism requesting access to the resource.
(1)
Note. This subclass is directed to access control in information
security systems. The concept of access control exists throughout
the class. Therefore, a search to a particular concept of access
control should consider the related topics in bus access control,
memory access control, computer system access control, generic access
control, etc.
Communications: Electrical,
subclasses 5.8 through 5.86for selective electrical communications systems with
intelligence comparison for identity authentication.
Computer Graphics Processing and Selective Visual
Display Systems,
subclasses 716 through 726for operator interface aspects of workgroup data
processing environments for plural users or sites.
Cryptography, appropriate subclasses for systems employing encrypted
user or record actuated authentication, and for digital control
or digital computer communication in which an encrypting or decrypting
device utilizes a digital signal manipulation technique on the computer
signal, and
subclasses 247 through 250for cellular telephone cryptographic authentication.
Data Processing: Financial, Business Practice,
Management, or Cost/Price Determination,
subclass 18 for an electronic cash register having cryptography;
and subclass 44 for a general funds transfer or credit transaction
requiring authorization or authentication not including a cryptographic
limitation.
Electrical Computers and Digital Processing Systems:
Multicomputer Data Transferring,
subclass 225 for controlling which of plural computers may transfer
data via a communications medium.
Electrical Computers and Digital Processing Systems:
Memory,
subclasses 147 through 153for shared memory access and control, and subclasses
163-164 for access limiting and password use therein.
Electrical Computers and Digital Processing Systems:
Support,
subclasses 155 through 159for central trusted authority authentication; subclasses 168-181
for particular communication authentication technique; and subclasses
182-186 for system access control based on cryptographic user identification.
Electrical Computers and Digital Processing Systems:
Multicomputer Data Transferring,
subclass 22 controlling which of plural computers may transfer
data via a communications medium.
This subclass is indented under subclass 3. Subject matter including permitting the use of rights,
privileges, and permissions in a network environment.
This subclass is indented under subclass 3. Subject matter including the existence of network data
that can be used to establish the claimed identity of a principal
including passwords, biometrics.
This subclass is indented under subclass 5. Subject matter including means or steps for administering
credentials, including specific techniques for creating the credentials.
This subclass is indented under subclass 5. Subject matter whereby the credential includes a unique
combination of bits used to confer transmit privileges to a computer
on a local network.
Data Processing: Financial, Business Practice,
Management, or Cost /Price Determination,
subclasses 65 through 69for secure transaction including intelligent token.
Electrical Computers and Digital Processing Systems:
Support,
subclasses 172 through 174for generic authentication using intelligent token
in multiple computer communication.
This subclass is indented under subclass 5. Subject matter whereby the credential includes data used
to indicate that the bearer is authorized for access.
Electrical Computers and Digital Processing Systems:
Support,
subclasses 156 through 158for computer network certificates, and subclass
175 for generation of a certificate.
This subclass is indented under subclass 3. Subject matter including a device installed between internal
(private) networks and outside networks (public) and which protects
the internal network from network-based attacks that may originate
from the outside and to provide a traffic point where security constraints and
audits may be affected.
Data Processing: Financial, Business Practice,
Management, or Cost /Price Determination,
subclass 79 for cryptographic remote charge determination of
a secure transaction including payment switch or gateway.
Electrical Computers and Digital Processing Systems:
Support,
subclasses 153 and 154 for a particular node in cryptographically
protected multiple computer communication.
This subclass is indented under subclass 11. Subject matter including an intermediate internetworking
device that connects one or more networks to another for a specific
application.
(1)
Note. The gateway runs a process at the request of the client/user
and obtains the service of a particular server; hence it works as
both a client and a server provider.
This subclass is indented under subclass 11. Subject matter including a multi-ported internetworking
device that applies a set of rules to each incoming IP packet in
order to decide whether it is to be forwarded or dropped.
(1)
Note. The filtering usually takes place on information contained
in the headers, such as protocol numbers, source or destination
addresses/ports, TCP connections, and other options. The
filtering may be dynamic or static.
(2)
Note. The packet filter may be different and distinct from
routers; see note on routers. Routers are
internetworking devices that run a custom operating system to transfer
packets between two or more physically separated network segments
(via the use of routing tables). This device operates at the network
level of the OSI model, or the Internet level of the Internet model.
(3)
Note. Some routers have a scanning ability and are know as screening routers, effectively becoming
a packet-filtering device.
This subclass is indented under subclass 11. Subject matter including a set of rules, procedures,
or conventions governing the format and relative timing of message
exchange between two communications terminals to prevent unauthorized
intrusion or interference (i.e., attacks).
This subclass is indented under subclass 14. Subject matter wherein the protocol is used for a software-defined
network offering the appearance, functionality, and usefulness of
a dedicated private network or for a terminal that is defined as
a standard on the network that can handle diverse terminals.
This subclass is indented under subclass 2. Subject matter wherein the access control or authentication
includes the means of limiting access to the resources of a system
based on a single computer or end user level.
(1)
Note. The end user level is the occupant of the premises who
uses the product.
This subclass is indented under subclass 16. Subject matter wherein the access control or authentication
includes permitting the use of rights, privileges, and permissions
in the stand-alone network environment.
This subclass is indented under subclass 17. Subject matter wherein the authorization includes systems,
methods, or apparatus for administering information supplied to
authenticate a communication.
(1)
Note. This subject includes specific techniques for creating
the credentials.
This subclass is indented under subclass 17. Subject matter wherein the authorization includes systems,
methods, and apparatus for using information supplied to authenticate
a communication to establish the identity of the bearer.
This subclass is indented under subclass 17. Subject matter wherein the authorization includes a unique
combination of bits used to confer transmit privileges to a computer
on a stand-alone.
MONITORING OR SCANNING OF SOFTWARE OR DATA INCLUDING ATTACK
PREVENTION:
This subclass is indented under the class definition. Subject matter comprising systems, methods, and apparatus
for ensuring data integrity by scanning of software or data or otherwise
monitoring data to prevent or detect attacks.
Data Processing: Financial, Business Practice,
Management, or Cost/Price Determination,
subclasses 51 through 54for usage protection of a distributed data file,
and subclass 405 for cost/data protection.
Data Processing: Software Development, Installation,
and Management, 168-173 for software upgrading or updating (including plural
version management) and
subclasses 174 through 178for software installation.
Electrical Computers and Digital Processing Systems:
Support,
subclasses 150 through 181for multiple computer communication using cryptography;
and subclasses 187 and 188 for software program protection or computer
virus detection in combination with data encryption.
This subclass is indented under subclass 22. Subject matter wherein monitoring or scanning of software
or data includes methods or systems to evaluate the defensive capabilities
of a system, process, apparatus, or entity against attacks.
(1)
Note. The subject matter of this subclass is primarily concerned
with keeping out intruders and preventing attacks as opposed to
authenticating users.
PREVENTION OF UNAUTHORIZED USE OF DATA INCLUDING PREVENTION
OF PIRACY, PRIVACY VIOLATIONS, OR UNAUTHORIZED DATA MODIFICATION:
This subclass is indented under the class definition. Subject matter comprising systems, methods, and apparatus
for prohibiting any impersonation, unauthorized browsing, falsification
or theft of data, or alteration of data not consistent with defined
security policy.
Cryptography,
subclasses 200 through 242for video with data encryption; subclasses 243-246
for facsimile encryption; subclasses 247-250 for cellular telephone
cryptographic authentication; subclass 251 for electronic game using
cryptography; subclasses 255-276 for communication using cryptography;
subclasses 277-47 for key management; and subclasses 287-53 for
electrical signal modification with digital signal handling.
Data Processing: Generic Control Systems or Specific
Applications,
subclasses 225 through 227for data processing article handling system having
identification code, and subclass 237 for an operator or payment initiated
dispensing or ending data processing system having password or PIN
authorization.
Data Processing: Financial, Business Practice,
Management, or Cost/Price Determination,
subclass 18 for security in an electronic cash register or point
of sale terminal having password entry mode; subclasses 57 and 58
for preventing access to or copying of stored information in a distributed data
file.
Electrical Computers and Digital Processing Systems:
Memory,
subclass 164 for memory access requiring authorization code
information (e.g., password or key other than encryption key, etc.).
This subclass is indented under subclass 26. Subject matter comprising means to control data tampering
by limiting access to authorized entities or processes.
This subclass is indented under subclass 26. Subject matter wherein the prevention of unauthorized
use of data includes means to limit number or amount of electronic
copies of the data that can be made.
This subclass is indented under subclass 26. Subject matter including means to prevent unauthorized
use by rendering an electronic copy inactive unless access is authorized.
This subclass is indented under the class definition. Subject matter comprising systems, methods, and apparatus
used for safeguarding physical equipment used in data processing.
Safes, Bank Protection, or a Related Device,
subclass 21 for bank protection device with alarm or indicator; subclass
31 for art device combined with fluent material distributing, generating
device for alarm or indicator; and subclass 38 for combined art device
with alarm or indicator.
Communications: Electrical,
subclasses 287 through 309for a signal box alarm arrangement, particularly subclass
288 for alarm transmission over a power line; subclasses 426.1-426.36
for vehicle alarms or indication of burglary or unauthorized use; and
subclasses 541-567 for an intrusion responsive indicator or alarm.
Telephonic Communications,
subclasses 37 through 51for emergency or alarm communications (e.g., watchman’s
circuit, etc.), particularly subclass 39 for subject matter responsive
to sense nonsystem condition, external to the telephone system,
and subclasses 106.01-106.11 for remote condition indication, other
than an emergency or alarm condition, over a telephone line.
This subclass is indented under subclass 34. Subject matter wherein the protection of hardware includes
means to prevent unauthorized removal of hardware.
This subclass is indented under subclass 34. Subject matter wherein the protection of hardware includes
means for protecting hardware by interruption of power supply.
Note: The Patent
and Trademark Depository Library Program (PTDLP) administers a nationwide
network of public, state and academic libraries designated as Patent and
Trademark Depository Libraries authorized by 35 U.S.C. 13 to: Disseminate
Patent and Trademark Information Support Diverse Intellectual Property
Needs of the Public. PTDL Contact Information
Note: For information/comments on electronic information products, such
as purchasing USPTO data, or to discuss system requirements for magnetic
tape products, contact:
KEY: =online
business system =fees =forms=help =laws/regulations =definition
(glossary)
The Inventors
Assistance Center is available to help you on patent
matters.Send questions about USPTO programs and services
to theUSPTO
Contact Center (UCC). You can suggest USPTO webpages
or material you would like featured on this section by E-mail
to the webmaster@uspto.gov.
While we cannot promise to accommodate all requests, your suggestions
will be considered and may lead to other improvements on the
website.