Secure on-demand supply method and system and traffic type acquisition method
    17.
    发明授权
    Secure on-demand supply method and system and traffic type acquisition method 有权
    安全的按需供应方式和系统和流量类型获取方法

    公开(公告)号:US09356967B2

    公开(公告)日:2016-05-31

    申请号:US14235926

    申请日:2012-05-30

    IPC分类号: H04L29/06 H04L12/851

    摘要: A secure on-demand supply method is disclosed. The method includes: a configuration parameter of a security function module is determined according to a security level set for requested traffic by a user, and/or an application scenario of a user terminal, and/or a traffic type; the security function module is configured by using the configuration parameter; and security protection is carried out on traffic data of the user. A traffic type acquisition method for protecting security of a specific user and/or traffic is disclosed. The method includes: a traffic identifier of data is acquired by using a traffic type classification function of a Quality of Service (QoS) function module, to protect the security of the specific user and/or traffic. The disclosure can provide various traffic security assurances according to security requirements of different users for different traffics.

    摘要翻译: 公开了一种安全的按需供应方法。 该方法包括:根据用户为所请求的流量设置的安全级别和/或用户终端的应用场景和/或流量类型来确定安全功能模块的配置参数; 安全功能模块通过配置参数进行配置; 并对用户的业务数据进行安全保护。 公开了一种用于保护特定用户和/或业务的安全性的流量类型获取方法。 该方法包括:通过使用服务质量(QoS)功能模块的业务类型分类功能获取数据的业务标识符,以保护特定用户和/或业务的安全性。 本公开可以根据不同用户对不同业务的安全要求提供各种业务安全保证。

    Secure on-demand supply method and system and traffic type acquisition method
    18.
    发明申请
    Secure on-demand supply method and system and traffic type acquisition method 有权
    安全的按需供应方式和系统和流量类型获取方法

    公开(公告)号:US20140196113A1

    公开(公告)日:2014-07-10

    申请号:US14235926

    申请日:2012-05-30

    IPC分类号: H04L29/06

    摘要: A secure on-demand supply method is disclosed. The method includes: a configuration parameter of a security function module is determined according to a security level set for requested traffic by a user, and/or an application scenario of a user terminal, and/or a traffic type; the security function module is configured by using the configuration parameter; and security protection is carried out on traffic data of the user. A traffic type acquisition method for protecting security of a specific user and/or traffic is disclosed. The method includes: a traffic identifier of data is acquired by using a traffic type classification function of a Quality of Service (QoS) function module, to protect the security of the specific user and/or traffic. A secure on-demand supply system and a traffic type acquisition method are disclosed. The disclosure can provide various traffic security assurances according to security requirements of different users for different traffics. The system of the disclosure satisfies security requirements of various users and various traffics, provides personalized security assurances for the users, and enhances user experience.

    摘要翻译: 公开了一种安全的按需供应方法。 该方法包括:根据用户为所请求的流量设置的安全级别和/或用户终端的应用场景和/或流量类型来确定安全功能模块的配置参数; 安全功能模块通过配置参数进行配置; 并对用户的业务数据进行安全保护。 公开了一种用于保护特定用户和/或业务的安全性的流量类型获取方法。 该方法包括:通过使用服务质量(QoS)功能模块的业务类型分类功能获取数据的业务标识符,以保护特定用户和/或业务的安全性。 公开了安全的点播供应系统和流量类型获取方法。 本公开可以根据不同用户对不同业务的安全要求提供各种业务安全保证。 本公开的系统满足各种用户和各种业务的安全需求,为用户提供个性化的安全保证,增强用户体验。

    Digital signature method based on braid groups conjugacy and verify method thereof
    19.
    发明申请
    Digital signature method based on braid groups conjugacy and verify method thereof 有权
    基于编织组共轭的数字签名方法及其验证方法

    公开(公告)号:US20070104322A1

    公开(公告)日:2007-05-10

    申请号:US10579801

    申请日:2004-11-12

    IPC分类号: H04L9/28

    摘要: The present invention discloses a digital signature scheme based on braid group conjugacy problem and a verifying method thereof, wherein the signatory S selects three braids xεLBm(l), x′εBn(l), aεBn(l), and considers braid pair (x′,x) as a public key of S, braid a as a private key of S; Signatory S uses hash function h for a message M needing signature to get y=h(M)εBn(l); generating a braid bεRBn−1−m(l) randomly, then signing the message M with the own private key a and the braid b generated randomly to obtain Sign(M)=a−1byb−1a; a signature verifying party V obtains the public key of S, calculating the message M by employing a system parameter hash function h, obtaining the y=h(M); judging whether sign(M) and y are conjugate or not, if not, sign(M) is an illegal signature, the verification fails; if yes, sign(M) is a legal signature of message M; the present invention avoids the problem of k-CSP in SCSS signature scheme of prior art, and improves the security of signature algorithm and reduces the number of braids involved and the number for conjugacy decision without reducing security, thereby improving the operation efficiency of signature.

    摘要翻译: 本发明公开了一种基于编织群共轭问题的数字签名方案及其验证方法,其中签名者S选择三个辫子bra B m SUB SUB SUB SUB SUB SUB SUB SUB SUB SUB (l),aepsilonB(1),并将辫子对(x',x)视为S的公钥,辫子a作为S的私钥; 签名者S使用哈希函数h来获得需要签名的消息M,以获得y = h(M)epsilonB(1); 随机生成辫子bepsilonRB n-1-m(l),然后用自己的私钥a签署消息M,随机生成辫子b以获得Sign(M)= a& 1 BYB -1; 签名验证方V获得S的公开密钥,通过采用系统参数散列函数h来计算消息M,获得y = h(M); 判断符号(M)和y是否是共轭的,如果不是,则(M)是非法签名,验证失败; 如果是,则(M)是消息M的合法签名; 本发明避免了现有技术的SCSS签名方案中的k-CSP问题,提高了签名算法的安全性,减少了涉及的辫子数量和共轭决定的数量,而不降低安全性,从而提高了签名的操作效率。

    Method for establishing identity management trust, identification provider and service provider
    20.
    发明授权
    Method for establishing identity management trust, identification provider and service provider 有权
    建立身份管理信任,识别提供者和服务提供者的方法

    公开(公告)号:US08910244B2

    公开(公告)日:2014-12-09

    申请号:US13257947

    申请日:2010-03-23

    摘要: A method for establishing an identity management trust, and an IDentification Provider (IDP) and a Service Provider (SP) are provided in the present disclosure. The method comprises: after receiving an access from a user, an SP determines whether an IDP to which the user attaches is located in a trust domain of the SP (S102); if the IDP to which the user attaches is not located in the trust domain of the SP, the SP inquires of an IDP in a local trust domain about the IDP to which the user attaches (S104); if the SP receives information of the IDP to which the user attaches, wherein the information is returned by an IDP in the local trust domain, the SP adds the IDP to which the user attaches to a temporary trust list to establish a trust for the IDP to which the user attaches (S106). The present disclosure can establish a trust relationship between an SP and any IDP in case of adding or not adding extra devices, ensuring the user to obtain desired services after logging on for one time.

    摘要翻译: 在本公开中提供了用于建立身份管理信任的方法,以及身份验证提供商(IDP)和服务提供商(SP)。 该方法包括:在接收到来自用户的访问之后,SP确定用户所附加的IDP是否位于SP的信任域中(S102); 如果用户所附的IDP不在SP的信任域中,则SP在本地信任域中查询关于用户所附加的IDP的IDP(S104); 如果SP接收到用户所附加的IDP的信息,其中信息由本地信任域中的IDP返回,则SP将用户附加到的临时信任列表的IDP添加到IDP的信任 (S106)。 本公开可以在添加或不添加额外的设备的情况下在SP和任何IDP之间建立信任关系,确保用户在登录一次之后获得所需的服务。