OBLIGATION ENFORCEMENT FOR RESOURCE ACCESS CONTROL
    1.
    发明申请
    OBLIGATION ENFORCEMENT FOR RESOURCE ACCESS CONTROL 有权
    资源访问控制的义务执行

    公开(公告)号:US20160014157A1

    公开(公告)日:2016-01-14

    申请号:US14328505

    申请日:2014-07-10

    CPC classification number: H04L63/20 H04L63/0263 H04L63/10

    Abstract: A request handler may be configured to receive an enforcement request for enforcement of an obligation required as a condition for a previously-granted first resource access request. n obligation enforcer may be configured to enforce the obligation, based on the enforcement request, and a compliance manager may be configured to obtain certification of execution of the obligation from an obligation certification service, and to provide the certification as a basis for granting a second resource access request.

    Abstract translation: 请求处理程序可以被配置为接收强制执行请求,以执行作为先前授权的第一资源访问请求的条件所需的义务。 责任执行者可以被配置为根据执行请求来执行义务,并且合规经理可以被配置为从义务认证服务获得执行义务的证明,并且提供认证作为授予第二个 资源访问请求。

    SCORING SECURITY RISKS OF WEB BROWSER EXTENSIONS
    2.
    发明申请
    SCORING SECURITY RISKS OF WEB BROWSER EXTENSIONS 审中-公开
    评估网络浏览器扩展的安全风险

    公开(公告)号:US20150007330A1

    公开(公告)日:2015-01-01

    申请号:US13927946

    申请日:2013-06-26

    Applicant: Laurent Gomez

    Inventor: Laurent Gomez

    CPC classification number: G06F21/577

    Abstract: A computer-implemented method involves obtaining a web browser extension to a web browser, extracting the web browser extension's imported library dependencies, and evaluating security risks associated with the web browser extension and the imported library dependencies.

    Abstract translation: 计算机实现的方法包括获取Web浏览器的Web浏览器扩展,提取Web浏览器扩展的导入的库依赖性,以及评估与Web浏览器扩展和导入的库依赖关系相关的安全风险。

    Method and system for access control using resource filters
    4.
    发明授权
    Method and system for access control using resource filters 有权
    使用资源过滤器进行访问控制的方法和系统

    公开(公告)号:US08156537B2

    公开(公告)日:2012-04-10

    申请号:US11948150

    申请日:2007-11-30

    CPC classification number: G06F21/6218

    Abstract: The present description refers in particular to a method, a system, and a computer program product for access control using resource filters for a strict separation of application and security logic. The computer-implemented method for access control may include receiving at least one access request to at least one resource from an application; providing a resource hierarchy for the at least one resource, the resource having at least one resource class, wherein the resource hierarchy is defined in a single resource; providing a policy comprising at least one access control rule for accessing at least one element of the at least one resource class; verifying the at least one access request based on the policy through an authorization service; and processing the at least one access request through a service interface.

    Abstract translation: 本说明书特别涉及使用资源过滤器进行访问控制的方法,系统和计算机程序产品,用于严格分离应用和安全逻辑。 用于访问控制的计算机实现的方法可以包括从应用向至少一个资源接收至少一个访问请求; 为所述至少一个资源提供资源层级,所述资源具有至少一个资源类别,其中所述资源层级被定义在单个资源中; 提供包括用于访问所述至少一个资源类别中的至少一个元素的至少一个访问控制规则的策略; 基于所述策略通过授权服务验证所述至少一个访问请求; 以及通过服务接口处理所述至少一个访问请求。

    Client authentication using a challenge provider
    7.
    发明授权
    Client authentication using a challenge provider 有权
    使用挑战提供商进行客户端身份验证

    公开(公告)号:US07673141B2

    公开(公告)日:2010-03-02

    申请号:US10959102

    申请日:2004-10-07

    CPC classification number: H04L63/0869

    Abstract: A system for providing secured access to an application service includes a challenge provider that uses a first cryptographic technique to provide a challenge to a client seeking access to an application service. The client uses a second cryptographic technique to generate a response, and provides the response to an authentication service. The authentication service grants the client access to the application service only if the challenge and response are authenticated using a first authentication technique complementary to the first cryptographic technique and a second authentication technique complementary to the second cryptographic technique, respectively.

    Abstract translation: 用于提供对应用服务的安全访问的系统包括使用第一密码技术向寻求对应用服务的访问的客户端提供挑战的挑战提供商。 客户端使用第二密码技术生成响应,并向认证服务提供响应。 认证服务只有在使用与第一密码技术互补的第一认证技术和补充第二密码技术的第二认证技术来认证质询和响应时,授予客户端对应用服务器的访问。

    Enterprise secure messaging architecture
    9.
    发明授权
    Enterprise secure messaging architecture 有权
    企业安全消息架构

    公开(公告)号:US07272716B2

    公开(公告)日:2007-09-18

    申请号:US10638545

    申请日:2003-08-12

    CPC classification number: G06Q99/00 G06Q10/087 H04L51/38 H04L63/0428 H04W12/02

    Abstract: An enterprise system with secure wireless messaging includes an application service to process a message. The enterprise system also includes a security service that uses a cryptographic technique to transform between the message and a secure message that is based on the message. A communication service communicates the secure message with a mobile client using a public network. The message may be secured using a cryptographic technique to provide end-to-end security. The enterprise system also may include an information service including information indicating occurrence of a triggering event. The information indicating occurrence of a triggering event may cause the enterprise system to push a secure message to the mobile client.

    Abstract translation: 具有安全无线消息的企业系统包括处理消息的应用服务。 企业系统还包括使用加密技术在消息和基于消息的安全消息之间转换的安全服务。 通信服务使用公共网络将安全消息与移动客户端进行通信。 可以使用加密技术来保护消息以提供端到端的安全性。 企业系统还可以包括包括指示触发事件的发生的信息的信息服务。 指示触发事件的发生的信息可能导致企业系统向移动客户端推送安全消息。

    Method and system for automatically controlling forum posting
    10.
    发明申请
    Method and system for automatically controlling forum posting 审中-公开
    自动控制论坛发帖的方法和系统

    公开(公告)号:US20070143403A1

    公开(公告)日:2007-06-21

    申请号:US11639989

    申请日:2006-12-15

    CPC classification number: G06F17/277 H04L12/1822 H04L63/0227

    Abstract: A method, for automatically controlling a data submission in a forum, the control being based on the respective data content, comprises: the data content submitted by a user for the forum is automatically parsed with respect to specifically selected characters, the selected characters being provided together with respective selection ancillary information, if any selected character is found within the data content, the respective selection ancillary information is analyzed, the data is handled conformable with the analyzed respective selection ancillary information, an answer for the user is elaborated, the answer including the respective found character together with an appropriate analysis of its selection ancillary information and informing the user about the manner the data is handled, and the elaborated answer is communicated to the user.

    Abstract translation: 一种用于在论坛中自动控制数据提交的方法,所述控件基于相应的数据内容,包括:由用户为论坛提交的数据内容相对于特定选择的字符被自动解析,所提供的所选字符 以及相应的选择辅助信息,如果在数据内容中找到任何所选择的字符,则分析各个选择辅助信息,处理数据与所分析的各个选择辅助信息一致,详细说明用户的答案,答案包括 各自发现的字符以及其选择辅助信息的适当分析,并向用户通知数据的处理方式,并将详细的答案传达给用户。

Patent Agency Ranking