COMMUNICATING A PASSWORD SECURELY
    1.
    发明申请
    COMMUNICATING A PASSWORD SECURELY 有权
    传播密码

    公开(公告)号:US20090222888A1

    公开(公告)日:2009-09-03

    申请号:US12038815

    申请日:2008-02-28

    IPC分类号: G06F21/00 H04L9/00

    CPC分类号: G06F21/556

    摘要: A secure (e.g., HTTPS) connection is established between a client and a server. Communication over the connection may utilize an application (e.g., a Web browser) that is not part of the client's trusted computing base. A password is sent from the client to the server over the connection such that the clear text password is unavailable to the application. For example, the password can be encrypted and inserted directly into the HTTPS stream from the client's trusted computing base.

    摘要翻译: 在客户端和服务器之间建立安全(例如HTTPS)连接。 通过连接的通信可以利用不是客户机的可信计算基础的一部分的应用(例如,Web浏览器)。 密码通过连接从客户端发送到服务器,使得明文密码对应用程序不可用。 例如,密码可以被加密并直接从客户端的可信计算基础插入到HTTPS流中。

    Communicating a password securely
    2.
    发明授权
    Communicating a password securely 有权
    安全地通信密码

    公开(公告)号:US08281368B2

    公开(公告)日:2012-10-02

    申请号:US12038815

    申请日:2008-02-28

    CPC分类号: G06F21/556

    摘要: A secure (e.g., HTTPS) connection is established between a client and a server. Communication over the connection may utilize an application (e.g., a Web browser) that is not part of the client's trusted computing base. A password is sent from the client to the server over the connection such that the clear text password is unavailable to the application. For example, the password can be encrypted and inserted directly into the HTTPS stream from the client's trusted computing base.

    摘要翻译: 在客户端和服务器之间建立安全(例如HTTPS)连接。 通过连接的通信可以利用不是客户机的可信计算基础的一部分的应用(例如,Web浏览器)。 密码通过连接从客户端发送到服务器,使得明文密码对应用程序不可用。 例如,密码可以被加密并直接从客户端的可信计算基础插入到HTTPS流中。

    Method and system for dynamic evaluation of a wireless network with a portable computing device
    3.
    发明授权
    Method and system for dynamic evaluation of a wireless network with a portable computing device 失效
    用便携式计算设备对无线网络进行动态评估的方法和系统

    公开(公告)号:US06801756B1

    公开(公告)日:2004-10-05

    申请号:US10071907

    申请日:2002-02-08

    IPC分类号: H04B1700

    摘要: Aspects of the invention are found in an apparatus for monitoring data on a wireless network. The data is transmitted according to a wireless data network protocol across the network. The apparatus is contained on a portable wireless network analysis device. The portable wireless network analysis device has a wireless network interface that communicatively couples the portable wireless network analysis device to the wireless network. This allows the portable wireless network analysis device to receive data from the wireless network. The portable wireless network analysis device also has a network traffic analyzer. The network traffic analyzer is communicatively coupled to the wireless network interface. The analyzer receives and analyzes the data received from the wireless network. The portable wireless network analysis device is capable of being operated by user at one location and transported to second location. The portable wireless network analysis device is able to continue to monitor data on the wireless network while being transported from the first location to the second location. The apparatus may also have a user interface. Information about the data may be displayed on the user interface. In a specific instance, the user interface is a display screen. The apparatus can have a storage system. The storage system stores the data when initiated by a user. The apparatus can also have a filter system. The filter system filters the data based on a predefined criteria. The apparatus may have an alarm system. The alarm system indicates when a predefined network event has occurred.

    摘要翻译: 本发明的方面在用于在无线网络上监视数据的装置中找到。 数据根据网络上的无线数据网络协议进行传输。 该装置包含在便携式无线网络分析装置上。 便携式无线网络分析设备具有将便携式无线网络分析设备通信地耦合到无线网络的无线网络接口。 这允许便携式无线网络分析设备从无线网络接收数据。 便携式无线网络分析设备还具有网络流量分析器。 网络流量分析器通信地耦合到无线网络接口。 分析仪接收并分析从无线网络接收的数据。 便携式无线网络分析装置能够在一个位置由用户操作并被运送到第二位置。 便携式无线网络分析装置能够在从第一位置传输到第二位置的同时继续监视无线网络上的数据。 该装置还可以具有用户界面。 有关数据的信息可能会显示在用户界面上。 在具体情况下,用户界面是显示屏幕。 该装置可以具有存储系统。 存储系统在用户启动时存储数据。 该装置还可以具有过滤系统。 过滤器系统基于预定义的标准过滤数据。 该装置可以具有报警系统。 报警系统指示何时发生预定义的网络事件。

    Special group logon tracking
    4.
    发明授权
    Special group logon tracking 有权
    特殊组登录跟踪

    公开(公告)号:US07690036B2

    公开(公告)日:2010-03-30

    申请号:US11301304

    申请日:2005-12-12

    IPC分类号: G06F11/30 G06F15/173

    CPC分类号: G06F21/316

    摘要: A method of generating a computer user activity log for a user belonging to a specially monitored group includes allowing a user to logon to a local computer. The local computer verifying the user account credentials and creating a user logon session. A token is created by the local computer for identification of any group membership with which the user associated and also having the user access privileges. The group information in the token is compared with a specially monitored group list. The specially monitored group list may be obtained from a domain server or may be configured locally. If the user has membership in the specially monitored group, then a special logon session is created and activities of the user are recorded.

    摘要翻译: 为属于特别监视的组的用户生成计算机用户活动日志的方法包括允许用户登录到本地计算机。 验证用户帐户凭据并创建用户登录会话的本地计算机。 令牌由本地计算机创建,用于识别与用户相关联并且具有用户访问权限的任何组成员身份。 将令牌中的组信息与特殊监视的组列表进行比较。 特殊监视的组列表可以从域服务器获取,也可以在本地配置。 如果用户拥有特殊监控组的成员身份,则会创建一个特殊的登录会话并记录用户的活动。

    Portable computing device and associated method for analyzing a wireless local area network
    5.
    发明授权
    Portable computing device and associated method for analyzing a wireless local area network 失效
    用于分析无线局域网的便携式计算设备和相关方法

    公开(公告)号:US06879812B2

    公开(公告)日:2005-04-12

    申请号:US10244953

    申请日:2002-09-17

    摘要: Aspects of the invention are found in an apparatus for monitoring data on a wireless network. The data is transmitted according to a wireless data network protocol across the network. The apparatus is contained on a portable wireless network analysis device. The portable wireless network analysis device has a wireless network interface that communicatively couples the portable wireless network analysis device to the wireless network. This allows the portable wireless network analysis device to receive data from the wireless network. The portable wireless network analysis device also has a network traffic analyzer. The network traffic analyzer is communicatively coupled to the wireless network interface. The analyzer receives and analyzes the data received from the wireless network. The portable wireless network analysis device is capable of being operated by user at one location and transported to second location. The portable wireless network analysis device is able to continue to monitor data on the wireless network while being transported from the first location to the second location. The apparatus may also have a user interface. Information about the data may be displayed on the user interface. In a specific instance, the user interface is a display screen. The apparatus can have a storage system. The storage system stores the data when initiated by a user. The apparatus can also have a filter system. The filter system filters the data based on a predefined criteria. The apparatus may have an alarm system. The alarm system indicates when a predefined network event has occurred.

    摘要翻译: 本发明的方面在用于在无线网络上监视数据的装置中找到。 数据根据网络上的无线数据网络协议进行传输。 该装置包含在便携式无线网络分析装置上。 便携式无线网络分析设备具有将便携式无线网络分析设备通信地耦合到无线网络的无线网络接口。 这允许便携式无线网络分析设备从无线网络接收数据。 便携式无线网络分析设备还具有网络流量分析器。 网络流量分析器通信地耦合到无线网络接口。 分析仪接收并分析从无线网络接收的数据。 便携式无线网络分析装置能够在一个位置由用户操作并被运送到第二位置。 便携式无线网络分析装置能够在从第一位置传输到第二位置的同时继续监视无线网络上的数据。 该装置还可以具有用户界面。 有关数据的信息可能会显示在用户界面上。 在具体情况下,用户界面是显示屏幕。 该装置可以具有存储系统。 存储系统在用户启动时存储数据。 该装置还可以具有过滤系统。 过滤器系统基于预定义的标准过滤数据。 该装置可以具有报警系统。 报警系统指示何时发生预定义的网络事件。

    Secure and usable protection of a roamable credentials store
    6.
    发明授权
    Secure and usable protection of a roamable credentials store 有权
    安全可用的保护漫游凭证存储

    公开(公告)号:US08205098B2

    公开(公告)日:2012-06-19

    申请号:US12037020

    申请日:2008-02-25

    IPC分类号: G06F12/14

    摘要: A tool which facilitates a balancing of security with usability enabling secure user access to multiple secure sites and locations from several computing devices utilizing a roamable credential store (RCS) which is highly resistant to offline attack. The RCS facilitates a protected Unified Credential Vault (UCV) via a multi-stage encryption process such that user credentials are protected by making offline dictionary attacks prohibitively expensive to an attacker without causing usability to deteriorate commensurately.

    摘要翻译: 一种有助于安全性与可用性平衡的工具,从而能够使用可抵御脱机攻击的可漫游凭证存储(RCS)从多个计算设备访问多个安全站点和位置。 RCS通过多阶段加密过程促进了受保护的统一凭证保险库(UCV),从而使得用户凭据受到保护,使离线字典攻击对攻击者来说价格昂贵,而不会使可用性相应地恶化。

    Per-user and system granular audit policy implementation
    7.
    发明授权
    Per-user and system granular audit policy implementation 有权
    每用户和系统的细粒度审计政策实施

    公开(公告)号:US07739721B2

    公开(公告)日:2010-06-15

    申请号:US11271014

    申请日:2005-11-10

    IPC分类号: G06F17/00

    摘要: System performance may be optimized, and extraneous audit noise reduced, by providing the capability of exercising a fine degree of control over individual audit events. A user such as an auditor interested in an individual audit event can obtain desired results without also obtaining results of all other individual audit events in the category containing the individual audit event. Additionally, audits may be obtained on either a per-user basis or on a system-wide basis. In this way, the auditor may tailor auditing events without regard to the auditing events established for other users of the system. Thus, there is a capability of establishing auditing policies for the entire system, in which case all users of the system may obtain results of the system-wide auditing.

    摘要翻译: 可以优化系统性能,通过提供对单个审计事件进行微细控制的能力,减少了无关的审计噪音。 诸如对个人审计事件感兴趣的审计师的用户可以获得期望的结果,而不获得包含个人审计事件的类别中的所有其他个人审计事件的结果。 此外,可以在每个用户的基础上或在全系统的基础上获得审核。 以这种方式,审计师可以定制审计事件,而不考虑为系统的其他用户建立的审计事件。 因此,有能力为整个系统建立审计政策,在这种情况下,系统的所有用户都可以获得全系统审计的结果。

    Special group logon tracking
    8.
    发明申请
    Special group logon tracking 有权
    特殊组登录跟踪

    公开(公告)号:US20070136798A1

    公开(公告)日:2007-06-14

    申请号:US11301304

    申请日:2005-12-12

    IPC分类号: G06K9/00

    CPC分类号: G06F21/316

    摘要: A method of generating a computer user activity log for a user belonging to a specially monitored group includes allowing a user to logon to a local computer. The local computer verifying the user account credentials and creating a user logon session. A token is created by the local computer for identification of any group membership with which the user associated and also having the user access privileges. The group information in the token is compared with a specially monitored group list. The specially monitored group list may be obtained from a domain server or may be configured locally. If the user has membership in the specially monitored group, then a special logon session is created and activities of the user are recorded.

    摘要翻译: 为属于特别监视的组的用户生成计算机用户活动日志的方法包括允许用户登录到本地计算机。 验证用户帐户凭据并创建用户登录会话的本地计算机。 令牌由本地计算机创建,用于识别与用户相关联并且具有用户访问权限的任何组成员身份。 将令牌中的组信息与特殊监视的组列表进行比较。 特殊监视的组列表可以从域服务器获取,也可以在本地配置。 如果用户拥有特殊监控组的成员身份,则会创建一个特殊的登录会话并记录用户的活动。

    Secure and usable protection of a roamable credentials store
    9.
    发明授权
    Secure and usable protection of a roamable credentials store 有权
    安全可用的保护漫游凭证存储

    公开(公告)号:US09262618B2

    公开(公告)日:2016-02-16

    申请号:US13524427

    申请日:2012-06-15

    IPC分类号: G06F21/34 G06F21/41

    摘要: A tool facilitates a balancing of security with usability enabling secure user access to multiple secure sites and locations from several computing devices. Access to the multiple secure sites and locations occur by utilizing a roamable credential store (RCS), which is highly resistant to offline attack. The RCS facilitates a protected Unified Credential Vault (UCV) via a multi-stage encryption process such that user credentials are protected by making offline dictionary attacks prohibitively expensive to an attacker without causing usability to deteriorate commensurately.

    摘要翻译: 一种工具有助于平衡安全性和可用性,从而实现安全用户访问来自多个计算设备的多个安全站点和位置。 通过使用可抵御脱机攻击的可漫游凭据存储(RCS)来访问多个安全站点和位置。 RCS通过多阶段加密过程促进了受保护的统一凭证保险库(UCV),从而使得用户凭据受到保护,使离线字典攻击对攻击者来说价格昂贵,而不会使可用性相应地恶化。

    Pre-fetching content items based on social distance
    10.
    发明授权
    Pre-fetching content items based on social distance 有权
    根据社交距离预取内容

    公开(公告)号:US08539161B2

    公开(公告)日:2013-09-17

    申请号:US12577464

    申请日:2009-10-12

    CPC分类号: G06F17/30867 G06F17/30902

    摘要: Retrieving content items based on a social distance between a user and content providers. The social distance is determined based on, for example, user interaction with the content providers. The content providers are ranked, for the user, based on the determined social distance. Prior to a request from the user, the content items are pre-fetched based on the ranked content providers and constraints such as storage space, bandwidth, and battery power level of a computing device of the user. In some embodiments, additional content items are retrieved, or retrieved content items are deleted, as a variable-size cache on the computing device fills or changes size.

    摘要翻译: 基于用户和内容提供商之间的社交距离检索内容项。 基于例如用户与内容提供商的交互来确定社交距离。 内容提供商根据确定的社交距离对用户进行排名。 在来自用户的请求之前,基于排名内容提供商和诸如用户的计算设备的存储空间,带宽和电池功率级别的约束来预取内容项。 在一些实施例中,随着计算设备上的可变大小的高速缓存填充或改变大小,检索附加内容项目或检索到的内容项目。