Challenge response-based device authentication system and method
    112.
    发明授权
    Challenge response-based device authentication system and method 有权
    基于挑战响应的设备认证系统和方法

    公开(公告)号:US08074072B2

    公开(公告)日:2011-12-06

    申请号:US12428170

    申请日:2009-04-22

    IPC分类号: H04L9/32

    摘要: A challenge response scheme authenticates a requesting device by an authenticating device. The authenticating device generates and issues a challenge to the requesting device. The requesting device combines the challenge with a hash of a password provided by a user, and the combination is further hashed in order to generate a requesting encryption key used to encrypt the user supplied password. The encrypted user supplied password is sent to the authenticating device as a response to the issued challenge. The authenticating device generates an authenticating encryption key by generating the hash of a combination of the challenge and a stored hash of an authenticating device password. The authenticating encryption key is used to decrypt the response in order to retrieve the user-supplied password. If the user-supplied password hash matches the stored authenticating device password hash, the requesting device is authenticated and the authenticating device is in possession of the password.

    摘要翻译: 挑战响应方案通过认证设备认证请求设备。 认证设备生成并向请求设备发出质询。 请求设备将挑战与由用户提供的密码的散列相结合,并且组合进一步进行散列,以便生成用于加密用户提供的密码的请求加密密钥。 加密的用户提供的密码作为对发布的挑战的响应被发送到认证设备。 认证设备通过生成质询的组合和存储的认证设备密码的哈希的散列来生成认证加密密钥。 认证加密密钥用于解密响应,以便检索用户提供的密码。 如果用户提供的密码哈希与存储的认证设备密码散列匹配,则请求设备被认证,认证设备拥有密码。

    DEVICE AND METHOD FOR GENERATING USER NOTIFICATIONS ASSOCIATED WITH TASKS THAT ARE PENDING COMPLETION
    113.
    发明申请
    DEVICE AND METHOD FOR GENERATING USER NOTIFICATIONS ASSOCIATED WITH TASKS THAT ARE PENDING COMPLETION 有权
    用于生成与要求完成的任务相关的用户通知的设备和方法

    公开(公告)号:US20110294471A1

    公开(公告)日:2011-12-01

    申请号:US13206847

    申请日:2011-08-10

    IPC分类号: H04W4/00

    CPC分类号: H04M1/72519 G06Q10/107

    摘要: A device and method for generating user notifications associated with tasks that are pending completion on a mobile device. When additional input is required from a user of the mobile device to complete performance of a task and is not being received from the user within a predefined time period, at least one form of user notification is generated. The particular form or forms of user notification are defined by a user profile associated with the user. User notifications may comprise visual, audible, and/or vibratory alerts, and different forms of these user notifications may be generated in a sequence. The volume of audible alerts or the period between periodic user notifications may vary over time.

    摘要翻译: 一种用于生成与在移动设备上等待完成的任务相关联的用户通知的设备和方法。 当需要来自移动设备的用户的附加输入以完成任务的执行并且在预定时间段内没有从用户接收到时,将产生至少一种形式的用户通知。 用户通知的特定形式或形式由与用户相关联的用户简档定义。 用户通知可以包括视觉,听觉和/或振动警报,并且可以按顺序生成这些用户通知的不同形式。 可听警报的音量或定期用户通知之间的时间间隔可能会随时间而变化。

    SYSTEM AND METHOD FOR EXCHANGING ENCRYPTION KEYS BETWEEN A MOBILE DEVICE AND A PERIPHERAL DEVICE
    114.
    发明申请
    SYSTEM AND METHOD FOR EXCHANGING ENCRYPTION KEYS BETWEEN A MOBILE DEVICE AND A PERIPHERAL DEVICE 有权
    用于交换移动设备和外围设备之间的加密密钥的系统和方法

    公开(公告)号:US20110280401A1

    公开(公告)日:2011-11-17

    申请号:US13192898

    申请日:2011-07-28

    IPC分类号: H04L9/00 H04W12/04

    摘要: Embodiments of a system and method for providing additional security for data being transmitted across a wireless connection that has been established using a known wireless protocol (e.g. Bluetooth) are described. An encryption key is exchanged between a computing device (e.g. a mobile device) and a wireless peripheral device (e.g. a keyboard, a printer). In exemplary embodiments, the encryption key is generated at one of the two devices. Data associated with the encryption key is output at the one device, which can be input by the user at the other device. The encryption key is then recovered at the other device from the input, thereby completing the key exchange. The encryption key can then be used to encrypt and decrypt data transmitted over the established wireless connection, providing additional security.

    摘要翻译: 描述了用于为已经使用已知的无线协议(例如,蓝牙)建立的无线连接传输的数据提供附加安全性的系统和方法的实施例。 在计算设备(例如移动设备)和无线外围设备(例如,键盘,打印机)之间交换加密密钥。 在示例性实施例中,在两个设备之一上生成加密密钥。 与加密密钥相关联的数据在一个设备处输出,其可由用户在另一设备处输入。 然后,加密密钥从输入端在另一个设备处恢复,从而完成密钥交换。 加密密钥然后可用于加密和解密通过建立的无线连接传输的数据,提供额外的安全性。

    System and method for deleting confidential information
    116.
    发明授权
    System and method for deleting confidential information 有权
    删除机密信息的系统和方法

    公开(公告)号:US08024809B2

    公开(公告)日:2011-09-20

    申请号:US11097147

    申请日:2005-04-04

    IPC分类号: G06F21/00

    CPC分类号: G06F21/60 H04W12/02 H04W88/02

    摘要: A system includes a first wireless-enabled device that transparently stores confidential information and a second wireless-enabled device that stores the same confidential information. The confidential information is to be used to secure a wireless communication link between the first device and the second device. One or both of the first device and the second device is to delete the confidential information upon fulfillment of one or more conditions related to the communication link.

    摘要翻译: 系统包括透明地存储机密信息的第一无线功能设备和存储相同机密信息的第二无线功能设备。 机密信息将用于保护第一设备和第二设备之间的无线通信链路。 第一装置和第二装置中的一个或两个是在履行与通信链路相关的一个或多个条件时删除机密信息。

    System and method for processing attachments to messages sent to a mobile device
    119.
    发明授权
    System and method for processing attachments to messages sent to a mobile device 有权
    用于处理发送到移动设备的消息的附件的系统和方法

    公开(公告)号:US07949355B2

    公开(公告)日:2011-05-24

    申请号:US11849433

    申请日:2007-09-04

    IPC分类号: H04W4/00

    CPC分类号: H04L51/38

    摘要: A system and method for processing attachments to messages sent to a mobile device is described herein. Embodiments described herein apply to encrypted messages comprising multiple message parts, in which different encryption keys (e.g. session keys) have been used to encrypt the different message parts. In at least one example embodiment, the encrypted session keys for every message content part comprising an attachment is received at the mobile device. In one embodiment, all of the encrypted session keys are stored together in a main message header. The mobile device may then decrypt the encrypted session key associated with a user requested attachment, and transmits the decrypted session key to one or more remote servers in an attachment request for use in decrypting the requested attachment. Data associated with the requested attachment, in decrypted form, is returned to the mobile device.

    摘要翻译: 本文描述了用于处理发送到移动设备的消息的附件的系统和方法。 本文描述的实施例适用于包括多个消息部分的加密消息,其中已经使用不同的加密密钥(例如,会话密钥)来加密不同的消息部分。 在至少一个示例实施例中,在移动设备处接收包括附件的每个消息内容部分的加密会话密钥。 在一个实施例中,所有加密的会话密钥一起存储在主消息头中。 然后,移动设备可以解密与用户请求的附件相关联的加密的会话密钥,并将解密的会话密钥发送到附件请求中的一个或多个远程服务器,以用于解密所请求的附件。 与所请求的附件相关联的数据以解密格式返回给移动设备。

    SYSTEM AND METHOD FOR RETRIEVING CERTIFICATES ASSOCIATED WITH SENDERS OF DIGITALLY SIGNED MESSAGES
    120.
    发明申请
    SYSTEM AND METHOD FOR RETRIEVING CERTIFICATES ASSOCIATED WITH SENDERS OF DIGITALLY SIGNED MESSAGES 有权
    与数字签名信息的发送者相关的证书的系统和方法

    公开(公告)号:US20110099381A1

    公开(公告)日:2011-04-28

    申请号:US12981689

    申请日:2010-12-30

    IPC分类号: H04L9/32 G06F15/16

    摘要: A system and method for retrieving certificates and/or verifying the revocation status of certificates. In one embodiment, when a user opens a digitally signed message, a certificate that is required to verify the digital signature on the message may be automatically retrieved if it is not stored on the user's computing device (e.g. a mobile device), eliminating the need for users to initiate the task manually. Verification of the digital signature may also be automatically performed by the application after the certificate is retrieved. Verification of the revocation status of a certificate may also be automatically performed if it is determined that the time that has elapsed since the status was last updated exceeds a pre-specified limit.

    摘要翻译: 用于检索证书和/或验证证书的撤销状态的系统和方法。 在一个实施例中,当用户打开数字签名的消息时,如果消息中没有存储在用户的计算设备(例如,移动设备)上,则可以自动检索需要验证该消息上的数字签名的证书,从而消除了需要 为用户手动启动任务。 检索证书后,应用程序也可以自动执行数字签名的验证。 如果确定自上次更新状态以来已经过去的时间超过预定限制,则也可以自动执行证书的撤销状态的验证。