Deriving keys used to securely process electronic messages
    22.
    发明授权
    Deriving keys used to securely process electronic messages 有权
    派生用于安全处理电子邮件的密钥

    公开(公告)号:US07283629B2

    公开(公告)日:2007-10-16

    申请号:US10310280

    申请日:2002-12-05

    IPC分类号: H04L9/00

    摘要: A plurality of message processors exchange public and secret information. Based on the exchanged information, each message processor computes a key sequence such that any one of a plurality of keys may be derived from the key sequence depending on key derivation data. A first message processor generates key derivation data that can be used to derive a particular key from among the plurality of keys. The first message processor sends a security token that includes the generated key derivation data to express to at least one other message processor how to derive the particular key from the computed key sequence. At least a second message processor receives the security token expressing how to derive the particular key from the computed key sequence. The first and/or second message processors apply the key derivation data to the computed key sequence to derive the particular key.

    摘要翻译: 多个消息处理器交换公共和秘密信息。 基于交换的信息,每个消息处理器计算密钥序列,使得可以根据密钥导出数据从密钥序列导出多个密钥中的任何一个。 第一消息处理器产生可以用于从多个密钥中导出特定密钥的密钥导出数据。 第一消息处理器发送包括生成的密钥导出数据的安全令牌,以向至少一个其他消息处理器表示如何从所计算的密钥序列中导出特定密钥。 至少第二消息处理器接收表示如何从所计算的密钥序列导出特定密钥的安全令牌。 第一和/或第二消息处理器将密钥导出数据应用于所计算的密钥序列以导出特定密钥。

    Performing generic challenges in a distributed system
    24.
    发明授权
    Performing generic challenges in a distributed system 有权
    在分布式系统中执行通用挑战

    公开(公告)号:US07395311B2

    公开(公告)日:2008-07-01

    申请号:US10340225

    申请日:2003-01-10

    IPC分类号: G06F15/16

    摘要: A client issues a first electronic request to access a service at a server. The server receives the request and identifies a type of challenge form among a number of different types of challenges (e.g., represented by a number of different XML schemas). The server issues a challenge, in accordance with the identified type of challenge, to the client. The challenge can include state information that indicates to the server when an appropriate response to the challenge is received. The client receives the challenge and formulates a response (including the state information) to the challenge in accordance with the identified type of challenge. The client issues a second electronic request, which includes the formulated response. The server receives the response and determines, based on the response, if the second electronic request is to be processed.

    摘要翻译: 客户端发出第一个电子请求以访问服务器上的服务。 服务器接收请求并且在许多不同类型的挑战中(例如,由多个不同的XML模式表示)来识别挑战表单的类型。 服务器根据确定的挑战类型向客户端发出挑战。 挑战可以包括当接收到对挑战的适当响应时向服务器指示的状态信息。 客户端接受挑战并根据所识别的挑战类型对挑战制定响应(包括状态信息)。 客户发出第二个电子请求,其中包括制定的响应。 服务器接收响应,并根据响应确定是否要处理第二个电子请求。

    Grouping and nesting hierarchical namespaces
    25.
    发明授权
    Grouping and nesting hierarchical namespaces 失效
    分组和嵌套分层命名空间

    公开(公告)号:US07925966B2

    公开(公告)日:2011-04-12

    申请号:US11227785

    申请日:2005-09-15

    IPC分类号: G06F17/00

    摘要: A group identifier represents an association between each of a number of different abbreviated namespace identifiers with a corresponding hierarchical namespace (e.g., an XML namespace). A hierarchically-structured document (e.g., an XML document) is accessed by a computing system that determines that the group identifier is associated with the hierarchically-structured document. Hence, when using the abbreviated namespace identifiers in the hierarchically-structured document, the computing system knows that the corresponding namespace is associated with the designated portions of the hierarchically-structured document. Also, a schema description language document (e.g., an XSD document) may specify multiple target namespaces for a single element. Accordingly, groupings of elements may be included in different namespaces to creating overlapping or even nested namespaces.

    摘要翻译: 组标识符表示多个不同的缩写命名空间标识符中的每一个与相应的分级命名空间(例如,XML命名空间)之间的关联。 分层结构化文档(例如,XML文档)由计算系统访问,该计算系统确定组标识符与分层结构化文档相关联。 因此,当在分层结构化文档中使用缩写名称空间标识符时,计算系统知道对应的命名空间与分层结构化文档的指定部分相关联。 此外,模式描述语言文档(例如,XSD文档)可以为单个元素指定多个目标命名空间。 因此,元素的分组可以包括在不同的命名空间中以创建重叠或甚至嵌套的命名空间。

    Using conditional statements in electronic messages to prevent overuse of resources or time when delivering the electronic message
    26.
    发明授权
    Using conditional statements in electronic messages to prevent overuse of resources or time when delivering the electronic message 有权
    在电子信息中使用条件语句来防止资源的过度使用或传递电子信息的时间

    公开(公告)号:US07359945B2

    公开(公告)日:2008-04-15

    申请号:US10310303

    申请日:2002-12-05

    IPC分类号: G06F15/16 G06F15/173

    摘要: A originating computing system sends an electronic message to a destination computing system via a routing path that includes one or more intermediary message processing computing systems. The originating computing system includes information in the electronic message that designates constraints related to resources or time use to delivery the message. For example, the constraints may include the number of hops, the amount of raw time, or the amount of processor time needed to delivery the message. If along the routing path, any of the intermediary computing systems detects that any of the constraints have been exceeded, then delivery of the electronic message may be abandoned. Any of the intermediary message processing computing systems may also specify constraints related to the resources or time used to delivery the electronic message.

    摘要翻译: 始发计算系统经由包括一个或多个中间消息处理计算系统的路由路径向目的地计算系统发送电子消息。 始发计算系统包括电子消息中的信息,其指定与资源相关的约束或用于传递消息的时间使用。 例如,约束可以包括传送消息所需的跳数,原始时间量或处理器时间量。 如果沿着路由路径,任何中间计算系统检测到任何约束已经被超过,则电子消息的递送可以被放弃。 任何中间消息处理计算系统还可以指定与用于传递电子消息的资源或时间有关的约束。

    Scoped referral statements
    27.
    发明授权
    Scoped referral statements 有权
    范围介绍声明

    公开(公告)号:US07676540B2

    公开(公告)日:2010-03-09

    申请号:US10270442

    申请日:2002-10-15

    IPC分类号: G06F15/16

    摘要: Methods, systems, and data structures for communicating object metadata are provided. A generic metadata container is presented that allows object metadata to be described in an extensible manner using protocol-neutral and platform-independent methodologies. A metadata scope refers to a dynamic universe of targets to which the included metadata statements correspond. Metadata properties provide a mechanism to describe the metadata itself, and metadata security can be used to ensure authentic metadata is sent and received. Mechanisms are also provided to allow refinement and replacement of metadata statements. The metadata container may be used to convey referral data to update routing tables in network nodes, and may also be used register referral statements and query a node for referral information.

    摘要翻译: 提供了传达对象元数据的方法,系统和数据结构。 提出了一个通用的元数据容器,允许使用协议中立和平台无关的方法以可扩展的方式描述对象元数据。 元数据范围是指所包含的元数据语句对应的目标的动态范围。 元数据属性提供了一种描述元数据本身的机制,并且可以使用元数据安全性来确保发送和接收真实的元数据。 还提供了机制来允许细化和替换元数据语句。 元数据容器可以用于传送参考数据以更新网络节点中的路由表,并且还可以使用注册参考语句并查询节点以获得推荐信息。

    Above-transport layer message partial compression
    28.
    发明授权
    Above-transport layer message partial compression 有权
    以上传输层消息部分压缩

    公开(公告)号:US07567586B2

    公开(公告)日:2009-07-28

    申请号:US11263196

    申请日:2005-10-31

    IPC分类号: H04J3/22

    CPC分类号: H04L69/04 H04L67/02

    摘要: Compression of a portion of a message at above a transport layer in a protocol stack. In the transmission direction, the message is accessed in a form that includes a number of initially parseable components, at least one of which being in compressed form. The message also includes a marker that identifies the component(s) that are compressed. The message is then passed to the transport layer in further preparation for transmission. In the receiving direction, the message is received from the transport layer. The message is initially parsed, and then the compressed component(s) are identified based on the marker.

    摘要翻译: 在协议栈中的传输层上方压缩消息的一部分。 在传输方向上,消息以包括多个最初可解析组件的形式被访问,其中至少一个是压缩形式的。 消息还包括标识被压缩的组件的标记。 然后将消息传递到传输层,以进一步准备传输。 在接收方向,从传输层接收消息。 该消息最初被解析,然后基于该标记识别压缩的组件。

    Grouping and nesting hierarchical namespaces
    29.
    发明授权
    Grouping and nesting hierarchical namespaces 有权
    分组和嵌套分层命名空间

    公开(公告)号:US07613997B2

    公开(公告)日:2009-11-03

    申请号:US11260656

    申请日:2005-10-27

    IPC分类号: G06F17/00

    摘要: A group identifier represents an association between each of a number of different abbreviated namespace identifiers with a corresponding hierarchical namespace (e.g., an XML namespace). A hierarchically-structured document (e.g., an XML document) is accessed by a computing system that determines that the group identifier is associated with the hierarchically-structured document. Hence, when using the abbreviated namespace identifiers in the hierarchically-structured document, the computing system knows that the corresponding namespace is associated with the designated portions of the hierarchically-structured document. Also, a schema description language document (e.g., an XSD document) may specify multiple target namespaces for a single element. Accordingly, groupings of elements may be included in different namespaces to creating overlapping or even nested namespaces.

    摘要翻译: 组标识符表示多个不同的缩写命名空间标识符中的每一个与相应的分级命名空间(例如,XML命名空间)之间的关联。 分层结构化文档(例如,XML文档)由计算系统访问,该计算系统确定组标识符与分层结构化文档相关联。 因此,当在分层结构化文档中使用缩写名称空间标识符时,计算系统知道对应的命名空间与分层结构化文档的指定部分相关联。 此外,模式描述语言文档(例如,XSD文档)可以为单个元素指定多个目标命名空间。 因此,元素的分组可以包括在不同的命名空间中以创建重叠或甚至嵌套的命名空间。

    Scoped metadata in a markup language
    30.
    发明授权
    Scoped metadata in a markup language 有权
    标记语言中的范围元数据

    公开(公告)号:US07451157B2

    公开(公告)日:2008-11-11

    申请号:US10270440

    申请日:2002-10-15

    IPC分类号: G06F17/00

    摘要: Methods, systems, and data structures for communicating object metadata are provided. A generic metadata container is presented that allows object metadata to be described in an extensible manner using protocol-neutral and platform-independent methodologies. A metadata scope refers to a dynamic universe of targets to which the included metadata statements correspond. Metadata properties provide a mechanism to describe the metadata itself, and metadata security can be used to ensure authentic metadata is sent and received. Mechanisms are also provided to allow refinement and replacement of metadata statements. Communication of metadata is expedited using hash digests to confirm metadata versions, and by piggybacking policy metadata requests and responses on other substantive data communication messages, thereby dynamically altering future communications.

    摘要翻译: 提供了传达对象元数据的方法,系统和数据结构。 提出了一个通用的元数据容器,允许使用协议中立和平台无关的方法以可扩展的方式描述对象元数据。 元数据范围是指所包含的元数据语句对应的目标的动态范围。 元数据属性提供了一种描述元数据本身的机制,并且可以使用元数据安全性来确保发送和接收真实的元数据。 还提供了机制来允许细化和替换元数据语句。 通过使用散列摘要来确认元数据版本,并通过捎带政策元数据请求和对其他实质性数据通信消息的响应来加速元数据的通信,从而动态地改变将来的通信。