CREDENTIAL STORAGE STRUCTURE WITH ENCRYPTED PASSWORD
    11.
    发明申请
    CREDENTIAL STORAGE STRUCTURE WITH ENCRYPTED PASSWORD 审中-公开
    具有加密密码的凭证存储结构

    公开(公告)号:US20120294445A1

    公开(公告)日:2012-11-22

    申请号:US13108883

    申请日:2011-05-16

    IPC分类号: H04L9/06 H04L9/08

    摘要: In accordance with one or more aspects, a storage structure including both an encrypted credential and an encrypted password is obtained. A key can be obtained from a key distribution service and the encrypted password decrypted, based on the key, to obtain a password. The encrypted credential is decrypted, based on the password to obtain the credential. Both devices able to obtain the key from the key distribution service, and devices otherwise able to obtain the password, are able to obtain the credential by decrypting the encrypted credential.

    摘要翻译: 根据一个或多个方面,获得包括加密凭证和加密密码的存储结构。 可以从密钥分发服务和密钥解密的密钥获得密钥以获得密码。 加密凭证根据密码进行解密以获取凭据。 能够从密钥分发服务获得密钥的两个设备以及能够获得密码的设备能够通过解密加密的凭证来获取凭证。

    Protecting user credentials using an intermediary component
    12.
    发明授权
    Protecting user credentials using an intermediary component 有权
    使用中间组件保护用户凭据

    公开(公告)号:US08984597B2

    公开(公告)日:2015-03-17

    申请号:US12789160

    申请日:2010-05-27

    摘要: An access component sends an access request to an intermediary component, the access request being a request to access a service or resource without credentials of a current user of the intermediary component being revealed to the access component. The intermediary component obtains user credentials, for the current user, that are associated with the service or resource. The access request and the user credentials are sent to the service or resource, and in response session state information is received from the service or resource. The session state information is returned to the access component, which allows the access component and the service or resource to communicate with one another based on the session state information and independently of the first component.

    摘要翻译: 访问组件向中间组件发送访问请求,所述访问请求是访问服务或资源的请求,而没有中继组件的当前用户的凭证被显示给访问组件。 中间组件获得与服务或资源相关联的当前用户的用户凭证。 访问请求和用户凭证被发送到服务或资源,并且响应于从服务或资源接收会话状态信息。 会话状态信息被返回到访问组件,其允许访问组件和服务或资源基于会话状态信息彼此通信并且独立于第一组件。

    Revocation Information for Revocable Items
    13.
    发明申请
    Revocation Information for Revocable Items 有权
    撤销信息撤销信息

    公开(公告)号:US20130212383A1

    公开(公告)日:2013-08-15

    申请号:US13370185

    申请日:2012-02-09

    IPC分类号: H04L29/06

    摘要: Techniques for providing revocation information for revocable items are described. In implementations, a revocation service is employed to manage revocation information for various revocable items. For example, the revocation service can maintain a revoked list that includes revoked revocable items, such as revoked digital certificates, revoked files (e.g., files that are considered to the unsafe), unsafe network resources (e.g., a website that is determined to be unsafe), and so on. In implementations, the revocation service can communicate a revoked list to a client device to enable the client device to maintain an updated list of revocation information.

    摘要翻译: 描述了可撤销项目的撤销信息提供技术。 在实现中,使用撤销服务来管理各种可撤销项目的撤销信息。 例如,撤销服务可以维护撤销的列表,其中包括撤销的可撤销项目,例如撤销的数字证书,撤销的文件(例如,被认为是不安全的文件),不安全的网络资源(例如,确定为 不安全),等等。 在实现中,撤销服务可以将撤销的列表传送到客户端设备,以使客户端设备能够维护更新的撤销信息列表。

    PROTECTING OPERATING SYSTEM CONFIGURATION VALUES
    17.
    发明申请
    PROTECTING OPERATING SYSTEM CONFIGURATION VALUES 有权
    保护操作系统配置值

    公开(公告)号:US20120226895A1

    公开(公告)日:2012-09-06

    申请号:US13037962

    申请日:2011-03-01

    IPC分类号: G06F9/00

    CPC分类号: G06F21/575

    摘要: In a pre-operating system environment on a device prior to loading and running an operating system on the device, a policy identifying configuration settings for the operating system is obtained. The operating system itself is prevented from changing this policy, but the policy can be changed under certain circumstances by components of the pre-operating system environment. The policy is compared to configuration values used by the operating system, and the operating system is allowed to boot with the configuration values if the configuration values satisfy the policy. However, if the configuration values do not satisfy the policy, then a responsive action is taken.

    摘要翻译: 在装置上装载和运行操作系统之前的设备上的预操作系统环境中,获得识别操作系统的配置设置的策略。 操作系统本身被阻止更改此策略,但在特定情况下可以通过操作前系统环境的组件来更改策略。 该策略与操作系统使用的配置值进行比较,如果配置值满足策略,则允许操作系统使用配置值进行引导。 但是,如果配置值不符合策略,则执行响应动作。