Systems, devices, and methods for outputting alerts to indicate the use of a weak hash function
    101.
    发明授权
    Systems, devices, and methods for outputting alerts to indicate the use of a weak hash function 有权
    用于输出警报以指示使用弱散列函数的系统,设备和方法

    公开(公告)号:US08295486B2

    公开(公告)日:2012-10-23

    申请号:US11863712

    申请日:2007-09-28

    IPC分类号: G06F21/00

    摘要: Systems, devices, and methods for outputting an alert on a mobile device to indicate the use of a weak hash function are disclosed herein. In one example embodiment, the method comprises receiving data (e.g. from a server) that identifies at least one first hash function, identifying a hash digest generated using a second hash function, determining if the second hash function is weak using the received data, and outputting an alert indicating that the second hash function is weak if it is determined that the second hash function is weak.

    摘要翻译: 本文公开了用于在移动设备上输出警报以指示使用弱散列函数的系统,设备和方法。 在一个示例实施例中,该方法包括接收标识至少一个第一散列函数的数据(例如,从服务器),识别使用第二散列函数生成的散列摘要,使用接收到的数据确定第二散列函数是否为弱;以及 如果确定第二散列函数较弱,则输出指示第二散列函数较弱的警报。

    E-MAIL WITH SECURE MESSAGE PARTS
    103.
    发明申请
    E-MAIL WITH SECURE MESSAGE PARTS 有权
    电子邮件与安全消息部分

    公开(公告)号:US20110258707A1

    公开(公告)日:2011-10-20

    申请号:US13167259

    申请日:2011-06-23

    IPC分类号: H04L9/32 G06F21/24

    CPC分类号: H04L63/04 G06Q10/107

    摘要: A method for preventing a recipient of an electronically transmitted message from taking at least one action in relation to the message is disclosed. The message has at least two parts with one of the parts having a higher level of security than the other part. The method includes the step of extracting information from the message. The information indicates that the higher level security part is not permitted to have the action taken on it while the other part is so permitted. The method also includes the step of preventing the higher level security part from having the action taken on it in reaction to said recipient making an offending request.

    摘要翻译: 公开了一种用于防止电子传送的消息的接收者相对于消息采取至少一个动作的方法。 消息至少有两部分,其中一个部分的安全级别高于其他部分。 该方法包括从消息中提取信息的步骤。 该信息表明,较高级别的安全部分不允许采取行动,而另一部分被允许。 该方法还包括防止较高级别的安全部分对所述接收者作出违规请求的反应而采取的动作的步骤。

    System and method for obscuring hand-held device data traffic information
    105.
    发明授权
    System and method for obscuring hand-held device data traffic information 有权
    遮挡手持设备数据流量信息的系统和方法

    公开(公告)号:US07900001B2

    公开(公告)日:2011-03-01

    申请号:US12475986

    申请日:2009-06-01

    IPC分类号: G06F12/00

    摘要: Increasing security for a hand-held data processing device with communication functionality where such a device includes an access-ordered memory cache relating to communications carried out by the device. The hand-held data processing device has a locked state that is entered by the device receiving or initiating a trigger. On occurrence of the trigger to enter the locked state the memory cache is reordered so as to disrupt the access-ordering of the cache to obscure device traffic information and thus increase the security of the device in the locked state.

    摘要翻译: 提高具有通信功能的手持式数据处理设备的安全性,其中这样的设备包括与由设备执行的通信相关的访问有序的存储器高速缓存。 手持式数据处理装置具有被接收或发起触发的装置输入的锁定状态。 在发生触发器进入锁定状态时,存储器高速缓存被重新排序,以便中断高速缓存的访问排序以模糊设备交通信息,从而增加处于锁定状态的设备的安全性。

    System and method for retrieving certificates associated with senders of digitally signed messages
    106.
    发明授权
    System and method for retrieving certificates associated with senders of digitally signed messages 有权
    用于检索与数字签名消息的发送者相关联的证书的系统和方法

    公开(公告)号:US07886144B2

    公开(公告)日:2011-02-08

    申请号:US10975987

    申请日:2004-10-29

    IPC分类号: H04L29/06

    摘要: A system and method for retrieving certificates and/or verifying the revocation status of certificates. In one embodiment, when a user opens a digitally signed message, a certificate that is required to verify the digital signature on the message may be automatically retrieved if it is not stored on the user's computing device (e.g. a mobile device), eliminating the need for users to initiate the task manually. Verification of the digital signature may also be automatically performed by the application after the certificate is retrieved. Verification of the revocation status of a certificate may also be automatically performed if it is determined that the time that has elapsed since the status was last updated exceeds a pre-specified limit.

    摘要翻译: 用于检索证书和/或验证证书的撤销状态的系统和方法。 在一个实施例中,当用户打开数字签名的消息时,如果消息中没有存储在用户的计算设备(例如,移动设备)上,则可以自动检索需要验证消息上的数字签名的证书,从而消除了需要 为用户手动启动任务。 检索证书后,应用程序也可以自动执行数字签名的验证。 如果确定自上次更新状态以来已经过去的时间超过预定限制,则也可以自动执行证书的撤销状态的验证。

    System and method for handling electronic mail mismatches
    107.
    发明授权
    System and method for handling electronic mail mismatches 有权
    处理电子邮件不匹配的系统和方法

    公开(公告)号:US07814161B2

    公开(公告)日:2010-10-12

    申请号:US11473313

    申请日:2006-06-23

    IPC分类号: G06F15/16 H04L29/06

    摘要: A system and method for handling e-mail address mismatches between the address contained within a user's certificate or certificate chain, and the account address actually being used is disclosed. In order to resolve address mismatches a canonical or generic domain name or user name may, for example, be used as a lifelong address of a user that is contained in the user's certificate. Upon detection of an address mismatch, the system and method disclosed herein may automatically re-check the certificate or search for a certificate containing the canonical or generic domain name and/or user name to attempt to resolve the mismatch. This mismatch resolution is preferably transparent to the user and occurs automatically. The canonical or generic domain and/or user names that are available to the device may be typically controlled by IT policy that is in place on the system for the device. While this system is suitable for any type of electronic messaging system, it has particular applicability to systems that use mobile wireless communication devices with electronic messaging capability.

    摘要翻译: 公开了一种用于处理用户证书或证书链中包含的地址与实际使用的帐户地址之间的电子邮件地址不匹配的系统和方法。 为了解决地址不匹配,规范或通用的域名或用户名例如可以被用作包含在用户证书中的用户的终身地址。 在检测到地址不匹配时,本文公开的系统和方法可以自动重新检查证书或搜索包含规范或通用域名和/或用户名的证书来尝试解决不匹配。 该失配分辨率对于用户来说优选是透明的并且自动发生。 设备可用的规范或通用域和/或用户名通常可以由设备上的系统上的IT策略来控制。 虽然该系统适用于任何类型的电子消息传送系统,但是它对具有电子消息传送能力的移动无线通信设备的系统具有特别的适用性。

    Method and apparatus for providing intelligent error messaging
    108.
    发明授权
    Method and apparatus for providing intelligent error messaging 有权
    提供智能错误信息的方法和装置

    公开(公告)号:US07802139B2

    公开(公告)日:2010-09-21

    申请号:US12407834

    申请日:2009-03-20

    IPC分类号: G06F11/00

    摘要: A method and apparatus for providing intelligent error messaging is disclosed wherein a user of a mobile communications device is provided with descriptive error messaging information to assist the user in overcoming errors associated with the processing of electronic messages and data. For example, when the mobile device is being used to decrypt a cryptographically secured electronic message, and a problem is encountered, program logic of the device provides the user with (1) an indication of exactly what problem is preventing opening of the message, for example, a required cryptographic key is not available; (2) an indication of exactly what may be done to overcome the problem, for example, what utilities should be run on the device; and (3) exactly what data, if any, needs to be downloaded to the device, for example, what cryptographic keys should be downloaded.

    摘要翻译: 公开了一种用于提供智能错误消息的方法和装置,其中向移动通信设备的用户提供描述性错误消息信息,以帮助用户克服与电子消息和数据的处理相关的错误。 例如,当移动设备被用于解密密码保护的电子消息并且遇到问题时,该设备的程序逻辑向用户提供(1)正确地指出什么问题阻止该消息打开的指示,用于 例如,所需的加密密钥不可用; (2)可以确切地说明什么可以做以克服这个问题,例如什么实用程序应该在设备上运行; 和(3)需要什么数据(如果有的话)需要下载到设备,例如什么加密密钥应该被下载。

    SYSTEM AND METHOD FOR VERIFYING DIGITAL SIGNATURES ON CERTIFICATES
    109.
    发明申请
    SYSTEM AND METHOD FOR VERIFYING DIGITAL SIGNATURES ON CERTIFICATES 有权
    用于在证书上验证数字签名的系统和方法

    公开(公告)号:US20100211795A1

    公开(公告)日:2010-08-19

    申请号:US12771194

    申请日:2010-04-30

    IPC分类号: H04L9/32 H04L9/08

    摘要: A system and method for verifying a digital signature on a certificate, which may be used in the processing of encoded messages. In one embodiment, when a digital signature is successfully verified in a signature verification operation, the public key used to verify that digital signature is cached. When a subsequent attempt to verify the digital signature is made, the public key to be used to verify the digital signature is compared to the cached key. If the keys match, the digital signature can be successfully verified without requiring that a signature verification operation in which some data is decoded using the public key be performed.

    摘要翻译: 用于验证证书上的数字签名的系统和方法,其可以用于编码消息的处理。 在一个实施例中,当在签名验证操作中成功验证数字签名时,用于验证数字签名被缓存的公开密钥。 当进行随后的验证数字签名的尝试时,将用于验证数字签名的公开密钥与缓存密钥进行比较。 如果密钥匹配,则可以成功验证数字签名,而不需要执行使用公钥对一些数据进行解码的签名验证操作。