Local verification of trusted display based on remote server verification
    21.
    发明授权
    Local verification of trusted display based on remote server verification 有权
    基于远程服务器验证的受信任显示的本地验证

    公开(公告)号:US08205248B2

    公开(公告)日:2012-06-19

    申请号:US11865048

    申请日:2007-09-30

    IPC分类号: G06F7/04 H04L9/32

    CPC分类号: G06F21/57 H04L63/12

    摘要: In a system with a main memory, a network adapter, and a display, a transaction security module in communication with the network adapter. The transaction security module acts to: establish a secure identification item with an entity which positively identifies the entity; accept an application OS of the entity; and initiate a guest OS with the entity; the network adapter acting to connect with the entity subsequent to initiation of a guest OS; and the display acting to display the secure identification item subsequent to connection with the entity.

    摘要翻译: 在具有主存储器,网络适配器和显示器的系统中,与网络适配器通信的事务安全模块。 交易安全模块用于:建立一个安全的识别项目,该实体确实标识该实体; 接受实体的应用程序OS; 并与实体发起客户操作系统; 所述网络适配器在发起客户操作系统之后与所述实体进行连接; 以及显示器,用于在与所述实体连接之后显示所述安全识别项目。

    AUDIT TRAILS FOR ELECTRONIC FINANCIAL TRANSACTIONS
    23.
    发明申请
    AUDIT TRAILS FOR ELECTRONIC FINANCIAL TRANSACTIONS 有权
    电子金融交易审计报告

    公开(公告)号:US20110238541A1

    公开(公告)日:2011-09-29

    申请号:US12748423

    申请日:2010-03-28

    摘要: An exemplary method includes transmitting, via a network interface, at least a currency amount in an attempt to confirm a financial transaction; responsive to the transmitting, receiving a confirmation indicator for the financial transaction; storing at least the currency amount in non-volatile memory; hashing at least the currency amount to generate a hash and storing the hash in a secure non-volatile memory; hashing at least the currency amount stored in the non-volatile memory to generate a verification hash; and in an attempt to verify at least the financial transaction, comparing the verification hash to the hash stored in the secure non-volatile memory. Various other apparatuses, systems, methods, etc., are also disclosed.

    摘要翻译: 一种示例性方法包括经由网络接口​​至少发送货币金额来尝试确认金融交易; 响应于发送,接收金融交易的确认指标; 将至少存储在非易失性存储器中的货币量; 至少散列货币量以产生散列并将散列存储在安全的非易失性存储器中; 至少散列存储在非易失性存储器中的货币量以产生验证散列; 并且尝试至少验证金融交易,将验证散列与存储在安全非易失性存储器中的散列进行比较。 还公开了各种其它装置,系统,方法等。

    SECURITY FOR STORAGE DEVICES
    24.
    发明申请
    SECURITY FOR STORAGE DEVICES 有权
    存储设备安全

    公开(公告)号:US20100250959A1

    公开(公告)日:2010-09-30

    申请号:US12415495

    申请日:2009-03-31

    IPC分类号: G06F12/14 H04L9/00 G06F12/16

    摘要: The invention broadly contemplates a security solution for storage devices that is inexpensive and robust. The invention allows a store of system specific data to be used to release the hard disk key of full-disk encryption (FDE) drives. This system specific data is passed to the FDE drives and used to calculate the actual encryption key. This allows for safe disposal of an FDE drive containing confidential data, as the lack of available system specific decryption data makes decryption virtually impossible.

    摘要翻译: 本发明广泛地考虑了廉价且鲁棒的存储设备的安全解决方案。 本发明允许存储系统特定数据以释放全盘加密(FDE)驱动器的硬盘密钥。 该系统的特定数据被传递到FDE驱动器并用于计算实际的加密密钥。 这允许安全处理包含机密数据的FDE驱动器,因为缺少可用的系统特定解密数据使解密几乎不可能。

    LOCAL VERIFICATION OF TRUSTED DISPLAY BASED ON REMOTE SERVER VERIFICATION
    27.
    发明申请
    LOCAL VERIFICATION OF TRUSTED DISPLAY BASED ON REMOTE SERVER VERIFICATION 有权
    基于远程服务器验证的TRUSTED显示器的本地验证

    公开(公告)号:US20090089875A1

    公开(公告)日:2009-04-02

    申请号:US11865048

    申请日:2007-09-30

    IPC分类号: H04L9/32

    CPC分类号: G06F21/57 H04L63/12

    摘要: In a system with a main memory, a network adapter, and a display, a transaction security module in communication with the network adapter. The transaction security module acts to: establish a secure identification item with an entity which positively identifies the entity; accept an application OS of the entity; and initiate a guest OS with the entity; the network adapter acting to connect with the entity subsequent to initiation of a guest OS; and the display acting to display the secure identification item subsequent to connection with the entity.

    摘要翻译: 在具有主存储器,网络适配器和显示器的系统中,与网络适配器通信的事务安全模块。 交易安全模块用于:建立一个安全的识别项目,该实体确实标识该实体; 接受实体的应用程序OS; 并与实体发起客户操作系统; 所述网络适配器在发起客户操作系统之后与所述实体进行连接; 以及显示器,用于在与所述实体连接之后显示所述安全识别项目。

    Management of hardware passwords
    28.
    发明授权
    Management of hardware passwords 有权
    管理硬件密码

    公开(公告)号:US08756667B2

    公开(公告)日:2014-06-17

    申请号:US12341512

    申请日:2008-12-22

    IPC分类号: H04L9/32

    CPC分类号: G06F21/34

    摘要: In the context of computer systems, the generation of preboot passwords at a server instead of at a client. Preferably, preboot passwords generated at the server are distributed to the client, and a process is offered whereby a user can establish his/her own proxy, not known to the server, that can be used to release the stored passwords to the client hardware. Since the passwords are generated at the server, management of the passwords is greatly facilitated since they are generated at the site where they are stored. This also makes it easy to implement management features such as a group policy, since the password generation software will be able to make logical connections between users and hardware.

    摘要翻译: 在计算机系统的上下文中,在服务器而不是在客户端生成预引导密码。 优选地,在服务器处生成的预引导密码被分发给客户端,并且提供一个过程,由此用户可以建立他/她自己的代理(服务器不知道),可以用于将存储的密码释放到客户端硬件。 由于密码是在服务器上生成的,因此密码的管理因其在存储位置生成而大大方便。 这也使得容易实现诸如组策略的管理功能,因为密码生成软件将能够在用户和硬件之间进行逻辑连接。

    Remote disablement of a computer system
    29.
    发明授权
    Remote disablement of a computer system 有权
    远程禁用计算机系统

    公开(公告)号:US08702812B2

    公开(公告)日:2014-04-22

    申请号:US12040821

    申请日:2008-02-29

    IPC分类号: G06F21/00

    CPC分类号: G06F21/88 G06F2221/2143

    摘要: Methods and arrangements for ensuring that, when a computer system is stolen or otherwise misplaced, the system is rendered unusable (i.e., locked down). Conventional solutions have required software running on the system to perform the lockdown action, but in accordance with at least one preferred embodiment of the present invention is the linkage of TPM (Trusted Platform Module) and AMT (Active Management Technology) solutions whereby an AMT arrangement can remove secure data or identifiers so that any encrypted data present on the system will become unusable.

    摘要翻译: 确保当计算机系统被盗或以其他方式错位时,系统变得无法使用(即锁定)的方法和装置。 常规解决方案需要在系统上运行的软件来执行锁定动作,但是根据本发明的至少一个优选实施例是TPM(可信平台模块)和AMT(主动管理技术)解决方案的联动,由此AMT布置 可以删除安全数据或标识符,使系统上存在的任何加密数据变得不可用。