Native Use Of Web Service Protocols And Claims In Server Authentication
    11.
    发明申请
    Native Use Of Web Service Protocols And Claims In Server Authentication 有权
    在服务器认证中本地使用Web服务协议和声明

    公开(公告)号:US20080301784A1

    公开(公告)日:2008-12-04

    申请号:US11755968

    申请日:2007-05-31

    IPC分类号: G06F7/04

    摘要: Architecture for natively authenticating a client application to a web server via HTTP authentication. The Web Services Architecture, and more specifically, Web Services Security, is leveraged to enable legacy applications to access web services transparently to the existing legacy applications. A security support provider (SSP) is created that employs WS-* protocol to at least emulate ws-trust and ws-mex thereby enabling policy exchange via an HTTP protocol stack. Policy can be exchanged via a WWW-Authenticate header enabling legacy applications to use the WS-* family of protocols without modifying the client application. The WS-* protocols are abstracted into a generic programming interface for native client application use.

    摘要翻译: 通过HTTP认证将客户端应用程序本地验证到Web服务器的体系结构。 Web服务体系结构,更具体地说,Web服务安全性是有利于使传统应用程序能够透明地访问现有的遗留应用程序的Web服务。 创建了一个安全支持提供程序(SSP),它使用WS- *协议来至少模拟ws-trust和ws-mex,从而通过HTTP协议栈实现策略交换。 可以通过WWW-Authenticate标头来交换策略,使得遗留应用程序能够使用WS- *系列协议,而无需修改客户端应用程序。 将WS- *协议抽象为通用编程接口,用于本机客户机应用程序的使用。

    System and method for analog voltage processing in wide range for cold-cathode fluorescent lamp
    12.
    发明申请
    System and method for analog voltage processing in wide range for cold-cathode fluorescent lamp 有权
    用于冷阴极荧光灯的大范围模拟电压处理系统和方法

    公开(公告)号:US20070177408A1

    公开(公告)日:2007-08-02

    申请号:US11357350

    申请日:2006-02-17

    IPC分类号: H02M7/00

    CPC分类号: H05B41/39 H05B41/282

    摘要: System and method for processing analog voltage for cold-cathode fluorescent lamp. The system includes a voltage-to-current converter configured to receive an input analog voltage signal and generate a first current signal, and a current processing component configured to receive the first current signal and a predetermined current and generate a second current signal. Additionally, the system includes a current-to-voltage converter configured to receive the second current signal and generate an output analog voltage signal, and a dimming controller configured to receive the output analog voltage signal and generate a control signal for driving at least a cold-cathode fluorescent lamp. The voltage-to-current converter, the current processing component, and the current-to-voltage converter are configured to be biased between a first power supply voltage level and a second power supply voltage level.

    摘要翻译: 冷阴极荧光灯模拟电压处理系统及方法。 该系统包括被配置为接收输入模拟电压信号并产生第一电流信号的电压 - 电流转换器,以及被配置为接收第一电流信号和预定电流并产生第二电流信号的电流处理部件。 另外,该系统包括被配置为接收第二电流信号并产生输出模拟电压信号的电流 - 电压转换器,以及调光控制器,被配置为接收输出模拟电压信号并产生用于至少驱动冷的控制信号 阴极荧光灯。 电压 - 电流转换器,当前处理组件和电流 - 电压转换器被配置为在第一电源电压电平和第二电源电压电平之间被偏置。

    User mapping information extension for protocols
    13.
    发明申请
    User mapping information extension for protocols 有权
    协议的用户映射信息扩展

    公开(公告)号:US20070016782A1

    公开(公告)日:2007-01-18

    申请号:US11181525

    申请日:2005-07-14

    IPC分类号: H04L9/00

    摘要: A hint containing user mapping information is provided in messages that may be exchanged during authentication handshakes. For example, a client may provide user mapping information to the server during authentication. The hint (e.g., in the form of a TLS extension mechanism) may be used to send the domain/user name information of a client to aid the server in mapping the user's certificate to an account. The extension mechanism provides integrity and authenticity of the mapping data sent by the client. The user provides a hint as to where to find the right account or domain controller (which points to, or otherwise maintains, the correct account). Based on the hint and other information in the certificate, the user is mapped to an account. The hint may be provided by the user when he logs in. Thus, a certificate is mapped to an identity to authenticate the user. A hint is sent along with the certificate information to perform the binding. Existing protocols may be extended to communicate the additional mapping information (the hint) to perform the binding. A vendor specific extension to Kerberos is defined to obtain the authorization data based on an X.509 certificate and the mapping user name hint.

    摘要翻译: 在认证握手期间可以交换的消息中提供了包含用户映射信息的提示。 例如,客户端可以在认证期间向服务器提供用户映射信息。 提示(例如,以TLS扩展机制的形式)可以用于发送客户端的域/用户名信息,以帮助服务器将用户的证书映射到帐户。 扩展机制提供客户端发送的映射数据的完整性和真实性。 用户提供关于在哪里找到正确的帐户或域控制器(指向或以其他方式维护正确的帐户)的提示。 根据证书中的提示和其他信息,用户被映射到一个帐户。 提示可以由用户在登录时提供。因此,证书被映射到身份以验证用户。 发送提示与证书信息一起执行绑定。 可以扩展现有协议以传达额外的映射信息(提示)来执行绑定。 定义了针对Kerberos的供应商特定扩展,以根据X.509证书和映射用户名提示获取授权数据。

    One time password integration with Kerberos
    14.
    发明申请
    One time password integration with Kerberos 有权
    与Kerberos一次性密码集成

    公开(公告)号:US20060288230A1

    公开(公告)日:2006-12-21

    申请号:US11153631

    申请日:2005-06-15

    IPC分类号: H04L9/00

    摘要: A domain controller (DC) side plugin supports one time passwords natively in Kerberos, Part of the key material is static and the other part is dynamic, thereby leveraging properties unique to each to securely support one time passwords in an operating system. The user is permitted to type in the one time passcode into a logon user interface. Rather than calling the SAM APIs to get the static passwords, vendors may register callbacks on the DC to plugin their algorithm. These callback functions will return the dynamically calculated passcodes for the user at a specific point in time. This passcode will then be treated as a normal password by the DC.

    摘要翻译: 域控制器(DC)侧插件在Kerberos中本地支持一次密码,部分密钥材料是静态的,另一部分是动态的,从而利用每个密钥的属性来安全地支持操作系统中的一次密码。 允许用户将一次性密码输入登录用户界面。 供应商可以在DC上注册回调来插入其算法,而不是调用SAM API来获取静态密码。 这些回调函数将在特定时间点返回动态计算的用户密码。 然后,该密码将被DC视为正常密码。

    Systems and methods for dimming control using system controllers
    15.
    发明授权
    Systems and methods for dimming control using system controllers 有权
    使用系统控制器进行调光控制的系统和方法

    公开(公告)号:US09301349B2

    公开(公告)日:2016-03-29

    申请号:US13527475

    申请日:2012-06-19

    摘要: System and method for dimming control. The system includes a system controller, a transistor, and a resistor. The system controller includes a first controller terminal and a second controller terminal. The transistor includes a first transistor terminal, a second transistor terminal and a third transistor terminal. The resistor including a first resistor terminal and a second resistor terminal. The first transistor terminal is coupled, directly or indirectly, to the second controller terminal. The first resistor terminal is coupled to the second transistor terminal. The second resistor terminal is coupled to the third transistor terminal. The system controller is configured to receive an input signal at the first controller terminal and to generate an output signal at the second controller terminal. The transistor is configured to receive the output signal at the first transistor terminal and to change between a first condition and a second condition.

    摘要翻译: 调光控制系统及方法。 该系统包括系统控制器,晶体管和电阻器。 系统控制器包括第一控制器端子和第二控制器端子。 晶体管包括第一晶体管端子,第二晶体管端子和第三晶体管端子。 电阻器包括第一电阻器端子和第二电阻器端子。 第一晶体管端子直接或间接耦合到第二控制器端子。 第一电阻端子耦合到第二晶体管端子。 第二电阻端子耦合到第三晶体管端子。 系统控制器被配置为在第一控制器端接收输入信号并在第二控制器端产生输出信号。 晶体管被配置为在第一晶体管端子处接收输出信号并且在第一状态和第二状态之间改变。

    Back-end constrained delegation model
    16.
    发明授权
    Back-end constrained delegation model 有权
    后端约束委托模型

    公开(公告)号:US09118672B2

    公开(公告)日:2015-08-25

    申请号:US12965445

    申请日:2010-12-10

    IPC分类号: G06F7/04 H04L29/06 H04L9/32

    摘要: A client can communicate with a middle tier, which can then, in turn, communicate with a back end tier to access information and resources on behalf of the client within the context of a system that can scale well. Each individual back end can establish a policy that defines which computing device can delegate to that back end. That policy can be enforced by a domain controller within the same administrative domain as the particular back end. When a middle tier requests to delegate to a back end, the domain controller to which that request was directed can either apply the policy, or, if the domain controller is in a different domain than the targeted back end, it can direct the middle tier to a domain controller in a different domain and can sign relevant information that the middle tier can utilize when communicating with that different domain controller.

    摘要翻译: 客户端可以与中间层进行通信,然后可以与后端层进行通信,以便在可以扩展的系统的上下文中代表客户端访问信息和资源。 每个单独的后端可以建立一个策略,定义哪个计算设备可以委托给该后端。 该策略可以由与特定后端相同的管理域中的域控制器实施。 当中间层请求委托给后端时,该请求所针对的域控制器可以应用策略,或者如果域控制器位于与目标后端不同的域中,则可以将中间层 到不同域中的域控制器,并且可以签署中间层在与该不同域控制器通信时可以利用的相关信息。

    Fast-reconnection of negotiable authentication network clients
    17.
    发明授权
    Fast-reconnection of negotiable authentication network clients 有权
    快速重新连接可转让认证网络客户端

    公开(公告)号:US08555069B2

    公开(公告)日:2013-10-08

    申请号:US12399615

    申请日:2009-03-06

    IPC分类号: H04L29/06

    摘要: Modern network communications often require a client application requesting data to authenticate itself to an application providing the data. Such authentication requests can be redundant, especially in the case of stateless network protocols. When a full authentication is performed, a conversation identifier and one or more encryption keys can be agreed upon. Subsequent authentication requests can be answered with a fast reconnect token comprising the conversation identifier and a cryptographically signed version of it using the one or more encryption keys. Should additional security be desirable, a sequence number can be established and incremented in a pre-determined or a random manner to enable detection of replayed fast reconnect tokens. If the recipient can verify the fast reconnect token, the provider can be considered to have been authenticated based on the prior authentication. If an aspect of the fast re-authentication should fail, recourse can be had to the original full authentication process.

    摘要翻译: 现代网络通信通常需要客户端应用程序请求数据对提供数据的应用程序进行身份验证。 这种认证请求可以是冗余的,特别是在无状态网络协议的情况下。 当执行完整认证时,可以同意会话标识符和一个或多个加密密钥。 随后的认证请求可以用包括会话标识符的快速重新连接令牌和使用该一个或多个加密密钥的加密签名版本来应答。 如果需要额外的安全性,则可以以预定或随机的方式建立和递增序列号,以便能够检测重放的快速重新连接令牌。 如果收件人可以验证快速重新连接令牌,则可以认为提供商已经根据先前的身份验证进行了身份验证。 如果快速重新认证的一个方面应该失败,则可能需要对原始的完整身份验证过程进行追索。

    Systems and methods of signal synchronization for driving light emitting diodes

    公开(公告)号:US08519754B2

    公开(公告)日:2013-08-27

    申请号:US13367088

    申请日:2012-02-06

    IPC分类号: H03L7/00

    摘要: System and method for signal synchronization. The system includes a first selection component, a first signal generator, a second signal generator and a first gate drive component. The first selection component is configured to receive a first mode signal and generate a first selection signal based on at least information associated with the first mode signal. The first signal generator is configured to, if the first selection signal satisfies one or more first conditions, receive a first input signal and generate at least a first clock signal based on at least information associated with the first input signal. Furthermore, the first gate drive component is configured to, if the first selection signal satisfies the one or more first conditions, receive at least the first clock signal and output a first drive signal to a first switch.

    SYSTEMS AND METHODS FOR INTELLIGENT CONTROL OF COLD-CATHODE FLUORESCENT LAMPS
    20.
    发明申请
    SYSTEMS AND METHODS FOR INTELLIGENT CONTROL OF COLD-CATHODE FLUORESCENT LAMPS 有权
    智能控制冷阴极荧光灯的系统与方法

    公开(公告)号:US20120326629A1

    公开(公告)日:2012-12-27

    申请号:US13335092

    申请日:2011-12-22

    IPC分类号: H05B41/36

    CPC分类号: H05B41/282

    摘要: System and method for driving one or more cold-cathode fluorescent lamps. For example, the method includes generating at least one drive signal associated with a signal frequency, the signal frequency being equal to a first predetermined frequency, receiving a current-sensing signal, the current-sensing signal being associated with a lamp current for the one or more cold-cathode fluorescent lamps in response to at least the first predetermined frequency, and determining whether the current-sensing signal is larger than a first threshold in magnitude, the current-sensing signal being related to the first predetermined frequency. Additionally, the method includes, if the current-sensing signal related to the first predetermined frequency is determined to be larger than the first threshold in magnitude at anytime during a first period of time, changing the signal frequency from the first predetermined frequency to a second predetermined frequency, the second predetermined frequency being different from the first predetermined frequency.

    摘要翻译: 用于驱动一个或多个冷阴极荧光灯的系统和方法。 例如,该方法包括产生与信号频率相关联的至少一个驱动信号,信号频率等于第一预定频率,接收电流感测信号,该电流感测信号与一个灯电流相关联 或更多个冷阴极荧光灯,并且确定电流感测信号是否大于第一阈值,电流感测信号与第一预定频率相关。 另外,如果在第一时间段内的任何时间将与第一预定频率相关的电流感测信号的幅度确定为大于第一阈值,则将该信号频率从第一预定频率改变为第二阈值 预定频率,第二预定频率不同于第一预定频率。