-
公开(公告)号:US20120294445A1
公开(公告)日:2012-11-22
申请号:US13108883
申请日:2011-05-16
CPC分类号: H04L9/083 , H04L9/0863 , H04L9/0894 , H04L9/3263
摘要: In accordance with one or more aspects, a storage structure including both an encrypted credential and an encrypted password is obtained. A key can be obtained from a key distribution service and the encrypted password decrypted, based on the key, to obtain a password. The encrypted credential is decrypted, based on the password to obtain the credential. Both devices able to obtain the key from the key distribution service, and devices otherwise able to obtain the password, are able to obtain the credential by decrypting the encrypted credential.
摘要翻译: 根据一个或多个方面,获得包括加密凭证和加密密码的存储结构。 可以从密钥分发服务和密钥解密的密钥获得密钥以获得密码。 加密凭证根据密码进行解密以获取凭据。 能够从密钥分发服务获得密钥的两个设备以及能够获得密码的设备能够通过解密加密的凭证来获取凭证。
-
公开(公告)号:US08984597B2
公开(公告)日:2015-03-17
申请号:US12789160
申请日:2010-05-27
CPC分类号: G06F21/6218 , G06F21/6263 , G06F2221/2105 , G06F2221/2115 , G06F2221/2141 , H04L9/3226 , H04L63/08 , H04L63/0884 , H04L63/166 , H04L67/142 , H04L2209/80
摘要: An access component sends an access request to an intermediary component, the access request being a request to access a service or resource without credentials of a current user of the intermediary component being revealed to the access component. The intermediary component obtains user credentials, for the current user, that are associated with the service or resource. The access request and the user credentials are sent to the service or resource, and in response session state information is received from the service or resource. The session state information is returned to the access component, which allows the access component and the service or resource to communicate with one another based on the session state information and independently of the first component.
摘要翻译: 访问组件向中间组件发送访问请求,所述访问请求是访问服务或资源的请求,而没有中继组件的当前用户的凭证被显示给访问组件。 中间组件获得与服务或资源相关联的当前用户的用户凭证。 访问请求和用户凭证被发送到服务或资源,并且响应于从服务或资源接收会话状态信息。 会话状态信息被返回到访问组件,其允许访问组件和服务或资源基于会话状态信息彼此通信并且独立于第一组件。
-
公开(公告)号:US20130212383A1
公开(公告)日:2013-08-15
申请号:US13370185
申请日:2012-02-09
IPC分类号: H04L29/06
CPC分类号: H04L9/3268 , G06F21/6209 , H04L63/0823 , H04L63/20
摘要: Techniques for providing revocation information for revocable items are described. In implementations, a revocation service is employed to manage revocation information for various revocable items. For example, the revocation service can maintain a revoked list that includes revoked revocable items, such as revoked digital certificates, revoked files (e.g., files that are considered to the unsafe), unsafe network resources (e.g., a website that is determined to be unsafe), and so on. In implementations, the revocation service can communicate a revoked list to a client device to enable the client device to maintain an updated list of revocation information.
摘要翻译: 描述了可撤销项目的撤销信息提供技术。 在实现中,使用撤销服务来管理各种可撤销项目的撤销信息。 例如,撤销服务可以维护撤销的列表,其中包括撤销的可撤销项目,例如撤销的数字证书,撤销的文件(例如,被认为是不安全的文件),不安全的网络资源(例如,确定为 不安全),等等。 在实现中,撤销服务可以将撤销的列表传送到客户端设备,以使客户端设备能够维护更新的撤销信息列表。
-
公开(公告)号:US09256745B2
公开(公告)日:2016-02-09
申请号:US13037962
申请日:2011-03-01
申请人: Scott D. Anderson , David J. Linsley , Magnus Bo Gustaf Nyström , Douglas M. MacIver , Robert Karl Spiger
发明人: Scott D. Anderson , David J. Linsley , Magnus Bo Gustaf Nyström , Douglas M. MacIver , Robert Karl Spiger
IPC分类号: G06F9/00 , G06F15/177 , G06F21/57
CPC分类号: G06F21/575
摘要: In a pre-operating system environment on a device prior to loading and running an operating system on the device, a policy identifying configuration settings for the operating system is obtained. The operating system itself is prevented from changing this policy, but the policy can be changed under certain circumstances by components of the pre-operating system environment. The policy is compared to configuration values used by the operating system, and the operating system is allowed to boot with the configuration values if the configuration values satisfy the policy. However, if the configuration values do not satisfy the policy, then a responsive action is taken.
-
公开(公告)号:US08924737B2
公开(公告)日:2014-12-30
申请号:US13218029
申请日:2011-08-25
CPC分类号: G06F21/575 , G06F21/602 , G06F21/73
摘要: In accordance with one or more aspects, a representation of a configuration of a firmware environment of a device is generated. A secret of the device is obtained, and a platform secret is generated based on both the firmware environment configuration representation and the secret of the device. One or more keys can be generated based on the platform secret.
摘要翻译: 根据一个或多个方面,生成设备的固件环境的配置的表示。 获得设备的秘密,并且基于固件环境配置表示和设备的秘密生成平台秘密。 可以基于平台秘密生成一个或多个密钥。
-
公开(公告)号:US20130054946A1
公开(公告)日:2013-02-28
申请号:US13218029
申请日:2011-08-25
CPC分类号: G06F21/575 , G06F21/602 , G06F21/73
摘要: In accordance with one or more aspects, a representation of a configuration of a firmware environment of a device is generated. A secret of the device is obtained, and a platform secret is generated based on both the firmware environment configuration representation and the secret of the device. One or more keys can be generated based on the platform secret.
摘要翻译: 根据一个或多个方面,生成设备的固件环境的配置的表示。 获得设备的秘密,并且基于固件环境配置表示和设备的秘密生成平台秘密。 可以基于平台秘密生成一个或多个密钥。
-
公开(公告)号:US20120226895A1
公开(公告)日:2012-09-06
申请号:US13037962
申请日:2011-03-01
申请人: Scott D. Anderson , David J. Linsley , Magnus Bo Gustaf Nyström , Douglas M. MacIver , Robert Karl Spiger
发明人: Scott D. Anderson , David J. Linsley , Magnus Bo Gustaf Nyström , Douglas M. MacIver , Robert Karl Spiger
IPC分类号: G06F9/00
CPC分类号: G06F21/575
摘要: In a pre-operating system environment on a device prior to loading and running an operating system on the device, a policy identifying configuration settings for the operating system is obtained. The operating system itself is prevented from changing this policy, but the policy can be changed under certain circumstances by components of the pre-operating system environment. The policy is compared to configuration values used by the operating system, and the operating system is allowed to boot with the configuration values if the configuration values satisfy the policy. However, if the configuration values do not satisfy the policy, then a responsive action is taken.
摘要翻译: 在装置上装载和运行操作系统之前的设备上的预操作系统环境中,获得识别操作系统的配置设置的策略。 操作系统本身被阻止更改此策略,但在特定情况下可以通过操作前系统环境的组件来更改策略。 该策略与操作系统使用的配置值进行比较,如果配置值满足策略,则允许操作系统使用配置值进行引导。 但是,如果配置值不符合策略,则执行响应动作。
-
-
-
-
-
-