Virtual private network for real-time data
    93.
    发明授权
    Virtual private network for real-time data 有权
    用于实时数据的虚拟专用网

    公开(公告)号:US08640222B2

    公开(公告)日:2014-01-28

    申请号:US13540686

    申请日:2012-07-03

    IPC分类号: G06F9/00

    摘要: The present disclosure describes a method for protecting real-time data exchanged between a mobile electronic device and a VPN gateway over a communications link. The method comprises: establishing a first VPN connection between the mobile electronic device and the VPN gateway through the communications link; establishing, while the first VPN connection is established, a second VPN connection between the mobile electronic device and the VPN gateway through the communications link; providing key information to at least one of the mobile electronic device or VPN gateway through the first VPN connection; and exchanging real-time data packets between the mobile electronic device and the VPN gateway through the second VPN connection, wherein the key information is for encrypting and decrypting the real-time data packets exchanged through the second VPN connection.

    摘要翻译: 本公开描述了一种用于通过通信链路保护在移动电子设备和VPN网关之间交换的实时数据的方法。 该方法包括:通过通信链路建立移动电子设备与VPN网关之间的第一VPN连接; 在建立第一VPN连接的同时,通过通信链路建立移动电子设备与VPN网关之间的第二VPN连接; 通过第一VPN连接向至少一个移动电子设备或VPN网关提供密钥信息; 以及通过所述第二VPN连接在所述移动电子设备与所述VPN网关之间交换实时数据分组,其中所述密钥信息用于加密和解密通过所述第二VPN连接交换的实时数据分组。

    Multiple-stage system and method for processing encoded messages
    94.
    发明授权
    Multiple-stage system and method for processing encoded messages 有权
    用于处理编码消息的多阶段系统和方法

    公开(公告)号:US08526618B2

    公开(公告)日:2013-09-03

    申请号:US13462266

    申请日:2012-05-02

    IPC分类号: H04L29/06

    摘要: System and methods for processing encoded messages at a message receiver are described. Encoded message processing is performed in multiple stages. In a first stage, a new received message is at least partially decoded by performing any decoding operations that require no user input and a resulting context object is stored in memory, before a user is notified that the new message has been received. When the user accesses the new message, any further required decoding operations are performed on the stored context object in a second stage of processing. The message can subsequently be displayed or otherwise processed relatively quickly, without repeating the first stage decoding operations. Decoding operations may include signature verification, decryption, other types of decoding, or some combination thereof.

    摘要翻译: 描述了在消息接收机处理编码消息的系统和方法。 编码消息处理在多个阶段执行。 在第一阶段中,在通知用户已经接收到新消息之前,通过执行不需要用户输入的任何解码操作,并且所得到的上下文对象被存储在存储器中,至少部分解码新的接收到的消息。 当用户访问新消息时,在第二阶段的处理中对存储的上下文对象执行任何进一步的所需解码操作。 随后可以相对快速地显示或以其他方式处理消息,而不重复第一级解码操作。 解码操作可以包括签名验证,解密,其他类型的解码,或其某些组合。

    Packet-based communication system and method
    95.
    发明授权
    Packet-based communication system and method 有权
    基于分组的通信系统和方法

    公开(公告)号:US08520653B2

    公开(公告)日:2013-08-27

    申请号:US13616203

    申请日:2012-09-14

    IPC分类号: G06F9/44

    CPC分类号: H04L63/0272 H04L67/04

    摘要: A system and method for facilitating communication of packets between one or more applications residing on a first computing device and at least one second computing device. The system comprises a connection manager adapted to receive packets from the at least one second computing device, and a packet cache for storing packets received by the connection manager. The connection manager, upon receiving a packet from a second computing device, transmits the packet to the packet cache for storage and notifies each of the applications of receipt of the packet. Subsequently, the packet is retrievable from the packet cache by a notified application, and verification that the packet is intended for communication to the notified application is made.

    摘要翻译: 一种用于促进驻留在第一计算设备和至少一个第二计算设备之间的一个或多个应用之间的分组通信的系统和方法。 所述系统包括适于从所述至少一个第二计算设备接收分组的连接管理器,以及用于存储由所述连接管理器接收的分组的分组高速缓存。 连接管理器在从第二计算设备接收到分组时,将分组发送到分组高速缓存用于存储,并通知每个应用接收分组。 随后,通过通知的应用程序从分组缓存中检索分组,并且确认分组旨在用于通知应用的通信。

    System and method for processing messages being composed by a user
    96.
    发明授权
    System and method for processing messages being composed by a user 有权
    用于处理由用户组成的消息的系统和方法

    公开(公告)号:US08516068B2

    公开(公告)日:2013-08-20

    申请号:US13568222

    申请日:2012-08-07

    IPC分类号: G06F15/16

    摘要: A system and method for processing messages being composed by a user of a computing device (e.g. a mobile device). Embodiments are described in which the performance of certain tasks is initiated before a direction is received from a user to send a message being composed by the user. This may involve, for example, “pre-fetching” security-related data that will be required in order to send a message that is in the process of being composed by the user securely. Such data may include security policy data, certificate data, and/or certificate status data, for example.

    摘要翻译: 一种用于处理由计算设备(例如,移动设备)的用户组成的消息的系统和方法。 描述了在从用户接收到发送由用户正在组成的消息的方向之前启动某些任务的性能的实施例。 这可能涉及例如“预取”与安全相关的数据,这是为了发送正在由用户安全地组成的消息所需要的。 这样的数据可以包括例如安全策略数据,证书数据和/或证书状态数据。

    System and method for determining a security encoding to be applied to outgoing messages
    97.
    发明授权
    System and method for determining a security encoding to be applied to outgoing messages 有权
    用于确定要应用于传出消息的安全编码的系统和方法

    公开(公告)号:US08370896B2

    公开(公告)日:2013-02-05

    申请号:US13324180

    申请日:2011-12-13

    IPC分类号: H04L9/00 H04L9/32

    摘要: A system and method for determining a security encoding to be applied to a message being sent by a user of a computing device. In one broad aspect, the device comprises a processor configured to: determine whether a general message encoding configuration setting indicates that when a security encoding is to be applied to a message then the security encoding is to be established by a policy engine; if the general message encoding configuration setting so indicates, query the policy engine for the security encoding to be applied to the message; otherwise, determine the security encoding to be applied to the message in accordance with a user-selected security encoding; and apply the determined security encoding to the message prior to transmission of the message to at least one recipient.

    摘要翻译: 一种用于确定要应用于由计算设备的用户发送的消息的安全编码的系统和方法。 在一个广泛的方面,该设备包括:处理器,被配置为:确定一般消息编码配置设置是否指示当将安全编码应用于消息时,安全编码将由策略引擎建立; 如果一般消息编码配置设置如此指示,则查询策略引擎以获得应用于该消息的安全编码; 否则,根据用户选择的安全编码确定要应用于消息的安全编码; 以及在将所述消息发送到至少一个接收者之前,将所确定的安全编码应用于所述消息。

    E-mail with secure message parts
    98.
    发明授权
    E-mail with secure message parts 有权
    电子邮件与安全的消息部分

    公开(公告)号:US08365305B2

    公开(公告)日:2013-01-29

    申请号:US13167259

    申请日:2011-06-23

    IPC分类号: H04L9/32 G06F21/24

    CPC分类号: H04L63/04 G06Q10/107

    摘要: A method for preventing a recipient of an electronically transmitted message from taking at least one action in relation to the message is disclosed. The message has at least two parts with one of the parts having a higher level of security than the other part. The method includes the step of extracting information from the message. The information indicates that the higher level security part is not permitted to have the action taken on it while the other part is so permitted. The method also includes the step of preventing the higher level security part from having the action taken on it in reaction to said recipient making an offending request.

    摘要翻译: 公开了一种用于防止电子传送的消息的接收者相对于消息采取至少一个动作的方法。 消息至少有两部分,其中一个部分的安全级别高于其他部分。 该方法包括从消息中提取信息的步骤。 该信息表明,较高级别的安全部分不允许采取行动,而另一部分被允许。 该方法还包括防止较高级别的安全部分对所述接收者作出违规请求的反应而采取的动作的步骤。

    Key Agreement and Re-keying over a Bidirectional Communication Path
    100.
    发明申请
    Key Agreement and Re-keying over a Bidirectional Communication Path 有权
    双向通信路径的重要协议和重新密钥

    公开(公告)号:US20120294440A1

    公开(公告)日:2012-11-22

    申请号:US13566653

    申请日:2012-08-03

    IPC分类号: H04L9/30

    摘要: A key agreement method is carried out by a first system in conjunction with a second system over a bidirectional communication path, including generating a first key pair having a first public key and a first private key, sending the first public key to the second system, receiving a second public key generated by the second system, and calculating a master key based upon the first private key, the second public key, a long-term private key, and a long-term public key. The long-term private key was generated by the first system during a previous key-agreement method as part of a long-term key pair. The long-term public key was generated by the second system and received during the previous key-agreement method. The previous key-agreement method required a secret to be known to the first system and the second system, thus conferring authentication based on the secret to the long-term public key.

    摘要翻译: 密钥协商方法由第一系统结合第二系统通过双向通信路径执行,包括生成具有第一公钥和第一私钥的第一密钥对,将第一公钥发送到第二系统, 接收由第二系统生成的第二公钥,以及基于第一私钥,第二公钥,长期私钥和长期公钥计算主密钥。 长期私钥是由以前的密钥协商方法中的第一个系统生成的,作为长期密钥对的一部分。 长期公钥是由第二个系统生成的,并在以前的密钥协商方法中得到。 以前的密钥协商方法需要对第一系统和第二系统知道一个秘密,从而基于长期公钥的秘密授予认证。