System and method for managing multiple smart card sessions
    22.
    发明授权
    System and method for managing multiple smart card sessions 有权
    用于管理多个智能卡会话的系统和方法

    公开(公告)号:US07891557B2

    公开(公告)日:2011-02-22

    申请号:US12335212

    申请日:2008-12-15

    IPC分类号: G06K5/00

    CPC分类号: G06K7/0008

    摘要: A system and method is provided for managing multiple smart card sessions with multiple communications or computing devices in association with a single smart card reader. A wireless smart card reader is provided for communicating with a plurality of devices requiring smart card functionality in a number of smart card sessions, in which each smart card session is addressed with an identifier identifying a single device. The smart card session is secured by a wireless connection pairing and by a secure pairing, such that each connection between the smart card reader and a device is secured against all other devices in communication with the smart card reader using a master connection key, which is unique for each device.

    摘要翻译: 提供了一种系统和方法,用于与单个智能卡读取器相关联地管理具有多个通信或计算设备的多个智能卡会话。 提供了一种无线智能卡读取器,用于与在许多智能卡会话中需要智能卡功能的多个设备进行通信,其中每个智能卡会话使用识别单个设备的标识符来寻址。 通过无线连接配对和安全配对来保护智能卡会话,使得智能卡读卡器和设备之间的每个连接都使用主连接密钥来抵御与智能卡读卡器通信的所有其他设备,该主连接密钥是 每个设备都是独一无二的

    System and method for retrieving certificates associated with senders of digitally signed messages
    23.
    发明授权
    System and method for retrieving certificates associated with senders of digitally signed messages 有权
    用于检索与数字签名消息的发送者相关联的证书的系统和方法

    公开(公告)号:US07886144B2

    公开(公告)日:2011-02-08

    申请号:US10975987

    申请日:2004-10-29

    IPC分类号: H04L29/06

    摘要: A system and method for retrieving certificates and/or verifying the revocation status of certificates. In one embodiment, when a user opens a digitally signed message, a certificate that is required to verify the digital signature on the message may be automatically retrieved if it is not stored on the user's computing device (e.g. a mobile device), eliminating the need for users to initiate the task manually. Verification of the digital signature may also be automatically performed by the application after the certificate is retrieved. Verification of the revocation status of a certificate may also be automatically performed if it is determined that the time that has elapsed since the status was last updated exceeds a pre-specified limit.

    摘要翻译: 用于检索证书和/或验证证书的撤销状态的系统和方法。 在一个实施例中,当用户打开数字签名的消息时,如果消息中没有存储在用户的计算设备(例如,移动设备)上,则可以自动检索需要验证消息上的数字签名的证书,从而消除了需要 为用户手动启动任务。 检索证书后,应用程序也可以自动执行数字签名的验证。 如果确定自上次更新状态以来已经过去的时间超过预定限制,则也可以自动执行证书的撤销状态的验证。

    SYSTEM AND METHOD OF INSTALLING SOFTWARE APPLICATIONS ON ELECTRONIC DEVICES
    25.
    发明申请
    SYSTEM AND METHOD OF INSTALLING SOFTWARE APPLICATIONS ON ELECTRONIC DEVICES 有权
    在电子设备上安装软件应用的系统和方法

    公开(公告)号:US20100275029A1

    公开(公告)日:2010-10-28

    申请号:US12829555

    申请日:2010-07-02

    IPC分类号: H04L9/32 G06F9/445

    摘要: In at least one embodiment, there is provided a mobile wireless device comprising: a microprocessor and memory, the memory comprising a set of control settings used to control a plurality of device operations; wherein the microprocessor is configured to: receive a first digital signature key for verifying digital signatures on software applications to be installed on the device; determine if any digital signature keys for verifying digital signatures on software applications to be installed on the device exist on the device, and if not, store the received first digital signature key in the memory; receive a software application for installation on the device; verify a digital signature on the received software application using the first digital signature key; and install the software application on the device if the digital signature on the received software application is successfully verified.

    摘要翻译: 在至少一个实施例中,提供了一种移动无线设备,包括:微处理器和存储器,所述存储器包括用于控制多个设备操作的一组控制设置; 其中所述微处理器被配置为:接收用于验证要安装在所述设备上的软件应用上的数字签名的第一数字签名密钥; 确定用于在设备上存在用于验证要安装在设备上的软件应用上的数字签名的数字签名密钥是否存在,如果不存在,则将接收到的第一数字签名密钥存储在存储器中; 接收在设备上安装的软件应用程序; 使用第一数字签名密钥验证所接收的软件应用上的数字签名; 并且如果接收到的软件应用程序上的数字签名被成功验证,则将软件应用程序安装在设备上。

    System and method of owner application control of electronic devices
    26.
    发明授权
    System and method of owner application control of electronic devices 有权
    电子设备所有者应用控制的系统和方法

    公开(公告)号:US07815100B2

    公开(公告)日:2010-10-19

    申请号:US11118844

    申请日:2005-04-29

    IPC分类号: G06F9/45

    摘要: Systems and methods of owner application control of an electronic device are provided. Owner application control information is stored on the electronic device and/or one or more remote servers. Owner application control information is consulted to determine if one or more required applications are available for execution on the electronic device. If not, one or more required applications not available are downloaded and installed. This could be in a manner transparent to the user of the electronic device. If one or more required applications are not available on the electronic device, the device can be functionally disabled in whole, or in part, until one or more required applications are available.

    摘要翻译: 提供了电子设备的所有者应用控制的系统和方法。 所有者应用控制信息存储在电子设备和/或一个或多个远程服务器上。 咨询所有者应用程序控制信息以确定一个或多个所需应用程序是否可用于在电子设备上执行。 如果没有,则下载并安装一个或多个不可用的必需应用程序。 这可以以对电子设备的用户透明的方式。 如果一个或多个所需的应用程序在电子设备上不可用,则该设备可以在全部或部分功能上禁用,直到一个或多个所需的应用程序可用。

    SYSTEM AND METHOD FOR ENCRYPTED SMART CARD PIN ENTRY
    27.
    发明申请
    SYSTEM AND METHOD FOR ENCRYPTED SMART CARD PIN ENTRY 有权
    加密智能卡引脚的系统和方法

    公开(公告)号:US20100241867A1

    公开(公告)日:2010-09-23

    申请号:US12795383

    申请日:2010-06-07

    IPC分类号: H04L9/32

    摘要: A smart card, system, and method for securely authorizing a user or user device using the smart card is provided. The smart card is configured to provide, upon initialization or a request for authentication, a public key to the user input device such that the PIN or password entered by the user is encrypted before transmission to the smart card via a smart card reader. The smart card then decrypts the PIN or password to authorize the user. Preferably, the smart card is configured to provide both a public key and a nonce to the user input device, which then encrypts a concatenation or other combination of the nonce and the user-input PIN or password before transmission to the smart card. The smart card reader thus never receives a copy of the PIN or password in the clear, allowing the smart card to be used with untrusted smart card readers.

    摘要翻译: 提供了使用智能卡安全授权用户或用户设备的智能卡,系统和方法。 智能卡被配置为在初始化或请求验证时向用户输入设备提供公钥,使得在经由智能卡读卡器传输到智能卡之前,由用户输入的PIN或密码被加密。 智能卡然后解密PIN或密码以授权用户。 优选地,智能卡被配置为向用户输入设备提供公开密钥和随机数,该用户输入设备然后在发送到智能卡之前加密随机数和用户输入的PIN或密码的级联或其他组合。 因此,智能卡读卡器从未收到PIN或密码的副本,允许智能卡与不可信的智能卡读卡器一起使用。

    Method and apparatus for providing intelligent error messaging
    28.
    发明授权
    Method and apparatus for providing intelligent error messaging 有权
    提供智能错误信息的方法和装置

    公开(公告)号:US07802139B2

    公开(公告)日:2010-09-21

    申请号:US12407834

    申请日:2009-03-20

    IPC分类号: G06F11/00

    摘要: A method and apparatus for providing intelligent error messaging is disclosed wherein a user of a mobile communications device is provided with descriptive error messaging information to assist the user in overcoming errors associated with the processing of electronic messages and data. For example, when the mobile device is being used to decrypt a cryptographically secured electronic message, and a problem is encountered, program logic of the device provides the user with (1) an indication of exactly what problem is preventing opening of the message, for example, a required cryptographic key is not available; (2) an indication of exactly what may be done to overcome the problem, for example, what utilities should be run on the device; and (3) exactly what data, if any, needs to be downloaded to the device, for example, what cryptographic keys should be downloaded.

    摘要翻译: 公开了一种用于提供智能错误消息的方法和装置,其中向移动通信设备的用户提供描述性错误消息信息,以帮助用户克服与电子消息和数据的处理相关的错误。 例如,当移动设备被用于解密密码保护的电子消息并且遇到问题时,该设备的程序逻辑向用户提供(1)正确地指出什么问题阻止该消息打开的指示,用于 例如,所需的加密密钥不可用; (2)可以确切地说明什么可以做以克服这个问题,例如什么实用程序应该在设备上运行; 和(3)需要什么数据(如果有的话)需要下载到设备,例如什么加密密钥应该被下载。

    System and method for registering entities for code signing services
    29.
    发明授权
    System and method for registering entities for code signing services 有权
    用于注册代码签名服务实体的系统和方法

    公开(公告)号:US07797545B2

    公开(公告)日:2010-09-14

    申请号:US11237727

    申请日:2005-09-29

    IPC分类号: H04L9/00

    摘要: A system and method for registering entities for code signing services. The entities may be software application developers or other individuals or entities that wish to have applications digitally signed. Signing of the applications may be required in order to enable the applications to access sensitive APIs and associated resources of a computing device when the applications are executed on the computing device. In one embodiment, a method of registering entities for code signing services will comprise the step of transmitting at least some account data to the registering individual or entity using an out-of-band communication system. This provides added security that the individual or entity registering for a code signing service is who that individual or entity purports to be.

    摘要翻译: 一种用于注册代码签名服务实体的系统和方法。 实体可以是软件应用程序开发人员或希望对应用进行数字签名的其他个人或实体。 可能需要签署应用程序,以便在应用程序在计算设备上执行时,使应用程序能够访问计算设备的敏感API和相关资源。 在一个实施例中,注册用于代码签名服务的实体的方法将包括使用带外通信系统将至少一些帐户数据发送到注册个人或实体的步骤。 这提供了增加的安全性,注册代码签名服务的个人或实体是个人或实体所声称的。

    SYSTEMS AND METHODS FOR PROTECTING HEADER FIELDS IN A MESSAGE
    30.
    发明申请
    SYSTEMS AND METHODS FOR PROTECTING HEADER FIELDS IN A MESSAGE 有权
    用于保护信头中的信头的系统和方法

    公开(公告)号:US20100223342A1

    公开(公告)日:2010-09-02

    申请号:US12394766

    申请日:2009-02-27

    IPC分类号: G06F15/82

    摘要: Embodiments of the systems and methods described herein facilitate the transmitting, receiving, and processing of encoded messages wherein the header fields in the message header are protected. In one embodiment, the contents of the header fields to be protected are inserted into the message body as one or more additional lines of text, for example, prior to encoding and transmitting the message to a message recipient. Upon receipt of the message, the message recipient processes the encoded message such that the contents of the protected header fields can be extracted from the message body. Accordingly, by inserting the contents of the header fields to be protected into the message body, the header fields may be protected using existing standards and protocols for facilitating secure message communication.

    摘要翻译: 本文描述的系统和方法的实施例有助于编码消息的发送,接收和处理,其中消息报头中的报头字段被保护。 在一个实施例中,要保护的报头字段的内容作为一个或多个附加的文本行插入到消息正文中,例如,在编码之前并将消息发送到消息接收者。 在接收到消息时,消息接收者处理编码的消息,使得可以从消息主体中提取受保护的报头字段的内容。 因此,通过将要保护的报头字段的内容插入到消息体中,可以使用现有标准和协议来保护报头字段以便于安全消息通信。