Apparatus and method for virtual pairing using an existing wireless connection key
    21.
    发明授权
    Apparatus and method for virtual pairing using an existing wireless connection key 有权
    使用现有无线连接密钥进行虚拟配对的装置和方法

    公开(公告)号:US09015487B2

    公开(公告)日:2015-04-21

    申请号:US12415911

    申请日:2009-03-31

    IPC分类号: H04L29/06 H04W12/04 H04L9/08

    摘要: Disclosed is a method for virtual pairing of a first peer device with a second peer device. In the method, a nonce is generated at the first peer device for use in virtually pairing the first and second peer devices to establish a first-type wireless connection. The nonce is forwarded from the first peer device to the second peer device over an already established second-type wireless connection between the first and second peer devices. At least one new key is generated from the nonce and a shared key for the already established second-type wireless connection. The first peer device is virtually paired with the second peer device using the at least one new key to establish the first-type wireless connection between the first and second peer devices.

    摘要翻译: 公开了一种用于将第一对等设备与第二对等设备进行虚拟配对的方法。 在该方法中,在第一对等设备处生成随机数,用于虚拟地配对第一和第二对等设备以建立第一类型的无线连接。 通过已经建立的第一和第二对等设备之间的第二类无线连接,该随机数从第一对等设备转发到第二对等设备。 至少一个新密钥是从该随机数生成的,另一个是已经建立的第二类无线连接的共享密钥。 第一对等设备使用至少一个新密钥与第二对等设备实际配对,以在第一和第二对等设备之间建立第一类型的无线连接。

    Synchronization test for device authentication
    22.
    发明授权
    Synchronization test for device authentication 有权
    设备认证同步测试

    公开(公告)号:US08837724B2

    公开(公告)日:2014-09-16

    申请号:US11844855

    申请日:2007-08-24

    摘要: Device authentication is based on the ability of a human to synchronize the movements of his or her fingers. A pairing procedure for two wireless devices may thus involve a synchronization test that is based on the relative timing of actuations of input devices on each of the wireless devices. In some aspects a synchronization test involves determining whether actuations of user input devices on two different wireless devices occurred within a defined time interval. In some aspects a synchronization test involves comparing time intervals defined by multiple actuations of user input devices on two wireless devices.

    摘要翻译: 设备认证是基于人类同步他或她的手指的动作的能力。 因此,用于两个无线设备的配对过程可能涉及基于每个无线设备上的输入设备的启动的相对定时的同步测试。 在一些方面,同步测试涉及确定是否在限定的时间间隔内发生两个不同无线设备上的用户输入设备的启动。 在一些方面,同步测试涉及比较由两个无线设备上的用户输入设备的多次致动所限定的时间间隔。

    Apparatus and method for evaluating a cipher structure's resistance to cryptanalysis
    24.
    发明授权
    Apparatus and method for evaluating a cipher structure's resistance to cryptanalysis 有权
    用于评估密码结构对密码分析的抵抗力的装置和方法

    公开(公告)号:US08098816B2

    公开(公告)日:2012-01-17

    申请号:US12253767

    申请日:2008-10-17

    IPC分类号: H04L9/28

    CPC分类号: H04L9/002 H04L9/0631

    摘要: Disclosed is a method for evaluating resistance to cryptanalysis of a cipher structure having a diffusion element including a linear transformation placed between differently-sized confusion elements at an input and an output of the diffusion element. A generalized minimum number of non-zero symbols at the diffusion element's input and output is determined. The diffusion element's input is divided into subset inputs, each having a size corresponding to the size of each confusion element at the diffusion element input. For each subset input, a subset number of non-zero symbols at the subset input and the diffusion element output is determined. Each subset number is summed to generate a summed subset number. The summed subset number is subtracted from the generalized minimum number to generate a worst-case number. An upper bound of a maximum differential characteristic probability is calculated and used to evaluate the cipher structure.

    摘要翻译: 公开了一种用于评估具有扩散元件的密码分析电阻的方法,该扩散元件包括放置在扩散元件的输入端和输出端的不同大小的混淆元件之间的线性变换。 确定扩散元件输入和输出处的非零符号的通用最小数量。 扩散元件的输入被分成子集输入,每个子集具有与扩散元素输入处的每个混淆元素的大小相对应的大小。 对于每个子集输入,确定子集输入处的非零符号的子集数量和扩散元素输出。 将每个子集数相加以生成一个总和子集。 从广义最小数字中减去总和子集数,以生成最坏情况数。 计算最大微分特征概率的上限并用于评估密码结构。

    SECURE NODE IDENTIFIER ASSIGNMENT IN A DISTRIBUTED HASH TABLE FOR PEER-TO-PEER NETWORKS
    25.
    发明申请
    SECURE NODE IDENTIFIER ASSIGNMENT IN A DISTRIBUTED HASH TABLE FOR PEER-TO-PEER NETWORKS 有权
    用于对等网络的分布式散列表中的安全节点标识符分配

    公开(公告)号:US20100161817A1

    公开(公告)日:2010-06-24

    申请号:US12342021

    申请日:2008-12-22

    IPC分类号: G06F15/173

    摘要: A multi-party commitment method is provided whereby a joining node uses contributions provided by contributor nodes in a peer-to-peer overlay network to generate a node identifier. The joining node generates a first contribution and sends a join request to an introducer node (or a plurality of contributor nodes), where the join request seeks to obtain one or more contributions for generating the node identifier within an identifier space of the overlay network. A hash of the first contribution may be included as part of the join request. In response, the joining node may receive a plurality of contributions, wherein the contributions are bound to each other and the first contribution by a prior external multi-node commitment operation. The joining node can then generate its node identifier as a function of the first contribution and the received contributions. Consequently, collusion between nodes and malicious manipulation during ID generation can be frustrated.

    摘要翻译: 提供了一种多方承诺方法,其中加入节点使用对等覆盖网络中的贡献者节点提供的贡献来生成节点标识符。 加入节点生成第一贡献并将连接请求发送到导引器节点(或多个贡献者节点),其中连接请求寻求获得用于在覆盖网络的标识符空间内生成节点标识符的一个或多个贡献。 作为连接请求的一部分,可以包括第一贡献的散列。 作为响应,加入节点可以接收多个贡献,其中贡献通过先前的外部多节点承诺操作彼此绑定和第一贡献。 然后,加入节点可以生成其作为第一贡献和接收到的贡献的函数的节点标识符。 因此,在ID生成期间,节点之间的串通和恶意操纵可能会受挫。

    APPARATUS AND METHOD FOR TRANSITIONING ACCESS RIGHTS FOR ROLE-BASED ACCESS CONTROL COMPATIBILIITY
    26.
    发明申请
    APPARATUS AND METHOD FOR TRANSITIONING ACCESS RIGHTS FOR ROLE-BASED ACCESS CONTROL COMPATIBILIITY 有权
    用于基于角色访问控制兼容性的用于过渡访问权限的装置和方法

    公开(公告)号:US20100100933A1

    公开(公告)日:2010-04-22

    申请号:US12253754

    申请日:2008-10-17

    IPC分类号: G06F21/00

    CPC分类号: H04L63/102 G06F21/6218

    摘要: Disclosed is a method for transitioning access rights, in a remote station with role-based access control, for an unknown role having access rights defined by a central access control management module. In the method, a role capability table is maintained in the remote station specifying centrally-defined access rights of roles that are interpretable in the remote station. An access request associated with an unknown role that is not interpretable in the remote station is received. The access request includes a role transition list that relates the unknown role to other centrally-defined roles. At least one of the other centrally-defined roles is interpretable in the remote station. A role is selected, from the role transition list, that is interpretable in the remote station for interpreting the unknown role of the access request. Access is granted based on the access request associated with the unknown role using the access rights of the interpretable role selected from the role transition table.

    摘要翻译: 公开了一种用于在具有基于角色的访问控制的远程站中转换访问权限的方法,用于具有由中央访问控制管理模块定义的访问权限的未知角色。 在该方法中,在远程站中维护角色能力表,指定在远程站中可解释的角色的集中定义的访问权限。 接收到与远程站中不可解释的未知角色相关联的访问请求。 访问请求包括将未知角色与其他中心定义角色相关联的角色转换列表。 其他中心定义角色中的至少一个可在远程站中解释。 从角色转换列表中选择一个角色,该角色可在远程站中解释,用于解释访问请求的未知角色。 基于与角色转换表中选择的可解释角色的访问权限,基于与未知角色关联的访问请求授予访问权限。

    APPARATUS AND METHOD FOR EVALUATING A CIPHER STRUCTURE'S RESISTANCE TO CRYPTANALYSIS
    27.
    发明申请
    APPARATUS AND METHOD FOR EVALUATING A CIPHER STRUCTURE'S RESISTANCE TO CRYPTANALYSIS 有权
    评估水泥结构抗CRYPTANALYSIS的电阻和方法

    公开(公告)号:US20100098242A1

    公开(公告)日:2010-04-22

    申请号:US12253767

    申请日:2008-10-17

    IPC分类号: H04L9/28

    CPC分类号: H04L9/002 H04L9/0631

    摘要: Disclosed is a method for evaluating resistance to cryptanalysis of a cipher structure having a diffusion element including a linear transformation placed between differently-sized confusion elements at an input and an output of the diffusion element. A generalized minimum number of non-zero symbols at the diffusion element's input and output is determined. The diffusion element's input is divided into subset inputs, each having a size corresponding to the size of each confusion element at the diffusion element input. For each subset input, a subset number of non-zero symbols at the subset input and the diffusion element output is determined. Each subset number is summed to generate a summed subset number. The summed subset number is subtracted from the generalized minimum number to generate a worst-case number. An upper bound of a maximum differential characteristic probability is calculated and used to evaluate the cipher structure.

    摘要翻译: 公开了一种用于评估具有扩散元件的密码分析电阻的方法,该扩散元件包括放置在扩散元件的输入端和输出端的不同大小的混淆元件之间的线性变换。 确定扩散元件输入和输出处的非零符号的通用最小数量。 扩散元件的输入被分成子集输入,每个子集具有与扩散元素输入处的每个混淆元素的大小相对应的大小。 对于每个子集输入,确定子集输入处的非零符号的子集数量和扩散元素输出。 将每个子集数相加以生成一个总和子集。 从广义最小数字中减去总和子集数,以生成最坏情况数。 计算最大微分特征概率的上限,并用于评估密码结构。

    METHOD AND APPARATUS FOR VERIFYING DATA PACKET INTEGRITY IN A STREAMING DATA CHANNEL
    28.
    发明申请
    METHOD AND APPARATUS FOR VERIFYING DATA PACKET INTEGRITY IN A STREAMING DATA CHANNEL 有权
    用于在流数据通道中验证数据分组完整性的方法和装置

    公开(公告)号:US20090307766A1

    公开(公告)日:2009-12-10

    申请号:US12135976

    申请日:2008-06-09

    IPC分类号: G06F21/00 G06F15/16

    CPC分类号: H04L63/123 H04L1/02 H04L1/20

    摘要: Disclosed is a method for verifying data packet integrity in a streaming-data channel. In the method, data packets are received from the streaming-data channel. Each data packet includes a data payload and a corresponding message integrity code. The received data packets are processed in a first processing mode, wherein the received data packets are forwarded to an application module before checking the integrity of the data packets using the respective message integrity codes. An integrity-check-failure measurement is generated for monitoring an integrity-check-failure rate in the first processing mode. If the integrity-check-failure measurement exceeds an integrity-check threshold, then the method transitions to a second processing mode. A received data packet is forwarded to the application module in the second processing mode only after passing the integrity check.

    摘要翻译: 公开了一种用于验证流数据信道中的数据分组完整性的方法。 在该方法中,从流数据信道接收数据分组。 每个数据分组包括数据有效载荷和对应的消息完整性代码。 接收到的数据分组以第一处理模式进行处理,其中在使用各自的消息完整性代码检查数据分组的完整性之前,所接收的数据分组被转发到应用模块。 产生完整性检查失败测量,用于在第一处理模式中监视完整性检查失败率。 如果完整性检查失败测量超过完整性检查阈值,则该方法转换到第二处理模式。 只有在通过完整性检查之后,接收的数据包将以第二处理模式转发到应用模块。

    Method and apparatus using a CAPTCHA having visual information related to the CAPTCHA's source
    30.
    发明授权
    Method and apparatus using a CAPTCHA having visual information related to the CAPTCHA's source 有权
    使用CAPTCHA的方法和装置具有与CAPTCHA的来源相关的视觉信息

    公开(公告)号:US09104854B2

    公开(公告)日:2015-08-11

    申请号:US13211818

    申请日:2011-08-17

    IPC分类号: G06F21/00 G06F21/36

    CPC分类号: G06F21/36 G06F2221/2133

    摘要: Disclosed is a method for visual verification a Captcha's source. In the method, a Captcha is served to a user. The Captcha includes visual information related to a characteristic of a source of the Captcha and related to a puzzle question of the Captcha. The visual information is for visual verification by the user of the Captcha's source. A response is received from the user based on the served Captcha. A determination is made as to whether the received response is a solution of the puzzle question of the served Captcha.

    摘要翻译: 披露了一种视觉验证验证码的方法。 在该方法中,向用户提供验证码。 验证码包括与验证码来源相关的视觉信息,并且与Captcha的难题相关。 视觉信息用于验证验证码的来源。 基于提供的验证码从用户接收到响应。 确定接收的响应是否是服务验证码的拼图问题的解决方案。