Method and apparatus to bind a key to a namespace
    14.
    发明授权
    Method and apparatus to bind a key to a namespace 有权
    将密钥绑定到命名空间的方法和设备

    公开(公告)号:US08566910B2

    公开(公告)日:2013-10-22

    申请号:US12782216

    申请日:2010-05-18

    IPC分类号: G06F7/04

    摘要: A method includes identifying an application installed on a device as an authorized application of a certain domain, the application being signed with a private key; deriving a signer identity using a public key that forms a key pair with the private key; mapping the certain domain to another domain using a deterministic function map; making a request to the another domain to obtain a list of signer identities that are authorized to act on behalf of the certain domain; determining whether the signer of the application is in the list and, if it is, authorizing the application to act with the same privileges as granted in the certain domain. Apparatus and computer programs for performing the method are also disclosed.

    摘要翻译: 一种方法包括将安装在设备上的应用标识为特定域的授权应用,该应用使用私钥进行签名; 使用与私钥形成密钥对的公钥来导出签名者身份; 使用确定性函数图将特定域映射到另一个域; 向另一个域发出请求以获得被授权代表某个域的签名者身份的列表; 确定应用程序的签名者是否在列表中,如果是,授权应用程序以在特定域中授予的相同权限来执行。 还公开了用于执行该方法的装置和计算机程序。

    System and method for establishing bearer-independent and secure connections
    15.
    发明授权
    System and method for establishing bearer-independent and secure connections 有权
    用于建立承载无关和安全连接的系统和方法

    公开(公告)号:US08484466B2

    公开(公告)日:2013-07-09

    申请号:US11575967

    申请日:2006-11-16

    IPC分类号: H04L29/06

    摘要: A system and method for efficiently enabling local security connectivity between electronic devices over multiple bearers. Electronic devices are configured to advertise, over each bearer, their respective configuration parameters for each bearer. After a connection has been established between the electronic devices over a first bearer, the two electronic devices use the first bearer to establish connections over the other bearers using the configuration parameters contained in the advertisements and advertised over the first bearer. Shared keys are established for the other bearers either using keys derived from the first shared key or by using the first secure connection as an out-of-band channel. The present invention also provides for the creation of an ad hoc WLAN connection once a Bluetooth connection has been established.

    摘要翻译: 一种用于在多个承载上有效地实现电子设备之间的本地安全连接的系统和方法。 电子设备被配置为在每个承载上通告每个承载的各自的配置参数。 在通过第一承载在电子设备之间建立连接之后,两个电子设备使用第一承载通过使用包含在广告中并通过第一承载通告的配置参数在其他承载上建立连接。 使用从第一共享密钥导出的密钥或通过使用第一安全连接作为带外信道为其他承载建立共享密钥。 一旦建立蓝牙连接,本发明还提供了创建自组织WLAN连接。

    CREDENTIAL TRANSFER
    16.
    发明申请
    CREDENTIAL TRANSFER 审中-公开
    资格转让

    公开(公告)号:US20120239936A1

    公开(公告)日:2012-09-20

    申请号:US13513662

    申请日:2009-12-18

    IPC分类号: G06F21/00 H04L9/32 H04L9/30

    摘要: Methods and apparatus, including computer program products, are provided for credential transfer. In one aspect there is provided a method. The method may include receiving, at a first device, an authorization token; determining, at the first device, a delegation token, one or more credentials, and metadata; and providing, by the first device to a second device, the delegation token, the one or more credentials, and the metadata. Related apparatus, systems, methods, and articles are also described.

    摘要翻译: 提供方法和设备,包括计算机程序产品,用于凭证转移。 在一个方面,提供了一种方法。 该方法可以包括在第一设备处接收授权令牌; 在第一设备处确定委托令牌,一个或多个凭证和元数据; 以及由第一设备向第二设备提供委托令牌,一个或多个凭证和元数据。 还描述了相关装置,系统,方法和制品。

    Accessing protected data on network storage from multiple devices
    17.
    发明授权
    Accessing protected data on network storage from multiple devices 有权
    从多个设备访问网络存储上的受保护数据

    公开(公告)号:US08059818B2

    公开(公告)日:2011-11-15

    申请号:US11057107

    申请日:2005-02-11

    IPC分类号: H04L9/00

    摘要: The present invention relates to a method and a system of securely storing data on a network (100) for access by an authorized domain (101, 102, 103), which authorized domain includes at least two devices that share a confidential domain key (K), and an authorized domain management system for securely storing data on a network for access by an authorized domain. The present invention enables any member device to store protected data on the network such that any other member device can access the data in plaintext without having to communicate with the device that actually stored the data.

    摘要翻译: 本发明涉及一种在由授权域(101,102,103)进行访问的网络(100)上安全地存储数据的方法和系统,该授权域包括至少两个共享机密域密钥(K )以及用于在网络上安全地存储数据以由授权域访问的授权域管理系统。 本发明使得任何成员设备能够在网络上存储受保护的数据,使得任何其他成员设备可以以明文方式访问数据,而不必与实际存储数据的设备进行通信。

    Linked authentication protocols
    18.
    发明授权
    Linked authentication protocols 有权
    链接的认证协议

    公开(公告)号:US07707412B2

    公开(公告)日:2010-04-27

    申请号:US10528161

    申请日:2002-11-25

    IPC分类号: H04L9/32

    摘要: A system and method for authenticating a terminal in a communication system is described. The method includes executing a terminal authentication protocol, whereby the executing the terminal authentication protocol includes authenticating an identity of a network entity by a terminal in a communication system. The method further includes executing a challenge authentication protocol, wherein the executing the challenge authentication protocol includes sharing challenge data between the terminal and the network entity, and forming at the terminal, test data by at least applying one authentication function to the challenge data using the identifier. The executing the challenge authentication protocol further includes transmitting a message including terminal authentication data from the terminal to the network entity, and determining, based on the terminal authentication data, whether to provide the terminal with access to a service.

    摘要翻译: 描述用于认证通信系统中的终端的系统和方法。 该方法包括执行终端认证协议,由此执行终端认证协议包括通信系统中的终端认证网络实体的身份。 该方法还包括执行挑战认证协议,其中执行挑战认证协议包括在终端和网络实体之间共享挑战数据,以及在终端上形成测试数据,至少使用一个认证功能将其应用于质询数据 标识符 执行挑战认证协议还包括从终端向网络实体发送包括终端认证数据的消息,并且基于终端认证数据确定是否向终端提供对服务的访问。

    Method for protecting electronic device, and electronic device
    19.
    发明授权
    Method for protecting electronic device, and electronic device 失效
    电子设备保护方法及电子设备

    公开(公告)号:US07630495B2

    公开(公告)日:2009-12-08

    申请号:US10186222

    申请日:2002-06-28

    IPC分类号: H04K1/00

    CPC分类号: H04W88/02 H04W12/08

    摘要: Identity data of an operational unit and a verification key of the cryptographic method employed by the service provider are protected with a key of the cryptographic method employed by the manufacturer of the operational unit. The verification key of the cryptographic method employed by the manufacturer of the operational unit is stored in the operational unit of the electronic device. The identity data of the operational unit and the identity data of the service provider are protected with a key of the cryptographic method employed by the service provider. The identity data of the operational unit and the verification key of the service provider are verified with the verification key of the manufacturer of the operational unit. The identity data of the operational unit and the identity data of the service provider are verified with the verified verification key of the service provider. The identity data stored in the user-specific module are compared with the verified identity data. The device starts if the identity data verified by the cryptographic method correspond with the identity data stored in the user-specific module.

    摘要翻译: 操作单元的身份数据和由服务提供商使用的密码方法的验证密钥由操作单元的制造商采用的密码方法的密钥进行保护。 操作单元的制造商使用的密码方法的验证密钥存储在电子设备的操作单元中。 操作单元的身份数据和服务提供商的身份数据由服务提供商使用的密码方法的密钥保护。 操作单元的身份数据和服务提供商的验证密钥由操作单元的制造商的验证密钥进行验证。 操作单元的身份数据和服务提供商的身份数据用服务提供商的已验证验证密钥进行验证。 将存储在用户特定模块中的身份数据与验证的身份数据进行比较。 如果通过加密方法验证的身份数据与存储在用户特定模块中的身份数据相对应,则设备启动。

    METHODS, APPARATUSES, AND COMPUTER PROGRAM PRODUCTS FOR AUTHENTICATION OF FRAGMENTS USING HASH TREES
    20.
    发明申请
    METHODS, APPARATUSES, AND COMPUTER PROGRAM PRODUCTS FOR AUTHENTICATION OF FRAGMENTS USING HASH TREES 失效
    方法,设备和计算机程序产品,用于使用哈希树进行片段验证

    公开(公告)号:US20090164783A1

    公开(公告)日:2009-06-25

    申请号:US11961542

    申请日:2007-12-20

    IPC分类号: H04L9/00

    CPC分类号: H04L9/3236 H04L2209/80

    摘要: An apparatus for authentication of fragments using hash trees may include a processor. The processor may be configured to provide one or more data fragments and a hash tree representing the one or more fragments, send at least one first fragment accompanied by any nodes of the hash tree necessary to authenticate the one or more first sent fragments, and send one or more subsequent fragments accompanied by only some, but not all, of the nodes of the hash tree necessary to authenticate the one or more subsequent fragments with the other nodes that are not sent but are necessary for authentication having been previously sent in conjunction with a prior fragment.

    摘要翻译: 用于使用散列树验证片段的装置可以包括处理器。 处理器可以被配置为提供表示一个或多个片段的一个或多个数据片段和散列树,发送伴随着认证一个或多个第一发送片段所需的散列树的任何节点的至少一个第一片段,并发送 一个或多个随后的片段仅伴随着一些但不是全部的散列树节点,用于认证一个或多个后续片段与其他节点不被发送,但是先前已经与 先前的片段。