System and method for providing access credentials
    21.
    发明授权
    System and method for providing access credentials 有权
    提供访问凭证的系统和方法

    公开(公告)号:US09130935B2

    公开(公告)日:2015-09-08

    申请号:US13101962

    申请日:2011-05-05

    IPC分类号: H04L9/32 H04L29/06

    摘要: Embodiments of the invention are concerned with providing access credentials associated with a user of a service to a server hosting the service, e.g. enabling single sign on by the user to a number of servers.The embodiments include functionality for establishing a first data connection with a terminal associated with the user and a second data connection with the server, and bridging the first and second data connections in order to establish a first communications session, using a first communications protocol, between the terminal and the server. A second communications session, using a second communications protocol, is also established with the server, via which a request for access credentials associated with the user is received. This request includes information received by the server in the first communications session, which is used to identify access credentials of the user that are transmitted to the server via the second communications session.

    摘要翻译: 本发明的实施例涉及将与服务的用户相关联的访问凭证提供给托管服务的服务器,例如, 使用户能够单点登录到多个服务器。 这些实施例包括用于与与用户相关联的终端建立第一数据连接和与服务器的第二数据连接的功能,以及桥接第一和第二数据连接以便使用第一通信协议建立第一通信会话 终端和服务器。 使用第二通信协议的第二通信会话也与服务器建立,通过该服务器接收与用户相关联的访问凭证的请求。 该请求包括由第一通信会话中的服务器接收的信息,其用于识别通过第二通信会话发送到服务器的用户的访问凭证。

    Application installation system
    22.
    发明授权
    Application installation system 有权
    应用安装系统

    公开(公告)号:US09110750B2

    公开(公告)日:2015-08-18

    申请号:US13277051

    申请日:2011-10-19

    IPC分类号: G06F9/44 G06F9/445

    摘要: A method, system and computer program product for controlling the installation of applications on a user terminal is disclosed. In one aspect, a catalog server identifies a first and a second installation control setting corresponding to a first and a second application on the basis of user identification data from a data store comprising entries for a plurality of applications and their corresponding installation control settings. Subsequently, the catalog server determines installation control data for at least one of the first and second application on the basis of the first and the second installation control setting. The determined installation control data is transmitted to the user terminal for controlling installation of at least one of the first and the second application.

    摘要翻译: 公开了一种用于控制用户终端上的应用安装的方法,系统和计算机程序产品。 在一个方面,目录服务器基于来自包括用于多个应用的​​条目的数据存储器的用户标识数据及其相应的安装控制设置来识别与第一和第二应用相对应的第一和第二安装控制设置。 随后,目录服务器基于第一和第二安装控制设置确定第一和第二应用中的至少一个的安装控制数据。 将确定的安装控制数据发送到用户终端,以控制第一和第二应用中的至少一个应用的安装。

    Asynchronous real-time retrieval of data
    23.
    发明授权
    Asynchronous real-time retrieval of data 有权
    异步实时检索数据

    公开(公告)号:US09059956B2

    公开(公告)日:2015-06-16

    申请号:US13923885

    申请日:2013-06-21

    摘要: A data retrieval system includes a gateway server and an access client. The gateway server is communicatively connected to the access client through a network. The gateway server provides a presentation service (PS) and a real-time service (RTS), which cooperate with the access client to retrieve data from a data store and then provide the retrieved data to a user's remote communication device. More particularly, when a user wishes to retrieve data from the data store or to send data to the data store, the user establishes a communication connection between his or her remote communication device and the gateway server, and then requests the desired data from the gateway server. In response, the gateway server sends a command to the access client, instructing it to retrieve the requested data. The access client retrieves the requested data from the data store, and returns the retrieved data to the gateway server. The gateway server then relays the requested information back to the user's remote communication device.

    摘要翻译: 数据检索系统包括网关服务器和访问客户端。 网关服务器通过网络与访问客户端通信连接。 网关服务器提供呈现服务(PS)和实时服务(RTS),其与访问客户端协作以从数据存储中检索数据,然后将检索的数据提供给用户的远程通信设备。 更具体地,当用户希望从数据存储器检索数据或向数据存储器发送数据时,用户建立他或她的远程通信设备与网关服务器之间的通信连接,然后从网关请求所需的数据 服务器。 作为响应,网关服务器向访问客户端发送命令,指示它检索所请求的数据。 访问客户端从数据存储器检索所请求的数据,并将检索的数据返回到网关服务器。 然后,网关服务器将所请求的信息中继回用户的远程通信设备。

    METHODS FOR REMOTE CONFIGURATION OF SOFTWARE APPLICATIONS
    24.
    发明申请
    METHODS FOR REMOTE CONFIGURATION OF SOFTWARE APPLICATIONS 有权
    远程配置软件应用的方法

    公开(公告)号:US20140208088A1

    公开(公告)日:2014-07-24

    申请号:US13745226

    申请日:2013-01-18

    IPC分类号: G06F9/44

    CPC分类号: G06F9/44505 G06F8/65

    摘要: Methods for remotely configuring application software on a user device are described. The application software defines at least one operating parameter having a set of pre-defined values which change the way the application interacts with the operating system. The operating parameter can be configured remotely and pushed to the user device where it is enforced by the application. Methods for providing information of the operating parameter to a remote device and for updating the configuration of an application are also described.

    摘要翻译: 描述在用户设备上远程配置应用软件的方法。 应用软件定义至少一个具有改变应用程序与操作系统交互的方式的预定义值集合的操作参数。 可以远程配置操作参数,并将其推送到应用程序实施的用户设备。 还描述了向远程设备提供操作参数的信息以及用于更新应用的配置的方法。

    METHOD OF OPERATING A COMPUTING DEVICE, COMPUTING DEVICE AND COMPUTER PROGRAM
    25.
    发明申请
    METHOD OF OPERATING A COMPUTING DEVICE, COMPUTING DEVICE AND COMPUTER PROGRAM 有权
    操作计算设备的方法,计算设备和计算机程序

    公开(公告)号:US20130227279A1

    公开(公告)日:2013-08-29

    申请号:US13780191

    申请日:2013-02-28

    IPC分类号: H04L29/06

    摘要: Data is stored on a computing device in an encrypted form using a control application. A data access application requests access to the data. It is determined whether the data access application has available a shared encryption key that is available to the control application. If a shared encryption key is available, the shared encryption key is used to encrypt a request for access to the data. If a shared encryption key is not available, a shared encryption key is negotiated with the control application, and the negotiated shared encryption key is used to encrypt the request for access to the data. The control application receives the encrypted request, decrypts the encrypted request using the shared encryption key, and makes the data stored on the computing device in encrypted form available to the data access application in response to the decrypted request.

    摘要翻译: 数据以加密形式使用控制应用程序存储在计算设备上。 数据访问应用程序请求访问数据。 确定数据访问应用是否具有可用于控制应用的共享加密密钥。 如果共享加密密钥可用,则共享加密密钥用于加密访问数据的请求。 如果共享加密密钥不可用,则与控制应用程序协商共享加密密钥,并且协商的共享加密密钥用于加密访问数据的请求。 控制应用程序接收加密的请求,使用共享加密密钥解密加密的请求,并且响应于解密的请求使存储在计算设备上的加密形式的数据可用于数据访问应用。

    Adaptive synchronization of service data
    26.
    发明授权
    Adaptive synchronization of service data 有权
    服务数据的自适应同步

    公开(公告)号:US08412805B2

    公开(公告)日:2013-04-02

    申请号:US11872633

    申请日:2007-10-15

    IPC分类号: G06F15/177

    摘要: Techniques are disclosed for synchronizing service data between a data store and a device using the service data. These synchronization techniques may be used with a synchronization method and device that adaptively adjust synchronization parameters, such as the synchronization interval and quantity of synchronized data, on a per-end-user basis in response to actual end-user behavior. In particular, heavy users of service data are rewarded with improved synchronization parameters, such as a combination of shorter synchronization intervals and increased synchronization data quantities, which provides closer to “direct access” performance. Light users of service, on the other hand, are assigned lower cost synchronization parameters, such as longer synchronization intervals and/or decreased synchronization data quantities.

    摘要翻译: 公开了用于使用服务数据在数据存储和设备之间同步服务数据的技术。 这些同步技术可以与同步方法和装置一起使用,该同步方法和装置响应于实际的最终用户行为,在每个终端用户的基础上自适应地调整同步参数,诸如同步数据的同步间隔和数量。 特别地,服务数据的大量用户通过改进的同步参数(诸如更短的同步间隔和增加的同步数据量的组合)得到奖励,其提供更接近直接访问性能。 另一方面,轻的服务用户被分配较低的成本同步参数,诸如更长的同步间隔和/或减少的同步数据量。

    Methods and apparatus for anonymising user data by aggregation
    27.
    发明授权
    Methods and apparatus for anonymising user data by aggregation 有权
    通过聚合匿名化用户数据的方法和装置

    公开(公告)号:US09489530B2

    公开(公告)日:2016-11-08

    申请号:US13299304

    申请日:2011-11-17

    摘要: In one aspect of a method of anonymizing user data by aggregation, at least one server-side device receives an anonymous aggregation command from a user client device. The anonymous aggregation command includes a specification of a set of users and an action to be taken. A list of users who meet the specification in the anonymous aggregation command is generated. The list of users who meet the specification is validated as meeting at least one criterion for anonymous aggregation. The action in the anonymous aggregation command is triggered to be taken in respect of the validated list of users who meet the specification.

    摘要翻译: 在通过聚合匿名化用户数据的方法的一个方面中,至少一个服务器侧设备从用户客户端设备接收匿名聚合命令。 匿名聚合命令包括一组用户的规范和要采取的操作。 生成在匿名聚合命令中符合规范的用户列表。 满足规范的用户列表被验证为满足匿名聚合的至少一个标准。 针对满足规范的用户的验证列表,将触发匿名聚合命令中的操作。

    SECURE COMMUNICATION CHANNELS
    28.
    发明申请
    SECURE COMMUNICATION CHANNELS 审中-公开
    安全通信渠道

    公开(公告)号:US20160315923A1

    公开(公告)日:2016-10-27

    申请号:US15103998

    申请日:2014-12-11

    IPC分类号: H04L29/06

    摘要: A method and system for negotiating a secure device-to-device communications channel between a first computing device and a second computing device, wherein the first computing device is associated with a first user and the second computing device is associated with a second user. The method comprises receiving, at a server, a first connection request comprising first address data and a first cryptographic key associated with the first computing device, the first connection request being received over a first secure communications channel, and receiving, at the server, a second connection request comprising second address data and a second cryptographic key associated with the second computing device, the second connection request being received over a second secure communications channel.

    摘要翻译: 一种用于在第一计算设备和第二计算设备之间协商安全设备到设备通信信道的方法和系统,其中所述第一计算设备与第一用户相关联,并且所述第二计算设备与第二用户相关联。 该方法包括在服务器处接收包括第一地址数据和与第一计算设备相关联的第一密码密钥的第一连接请求,所述第一连接请求是通过第一安全通信信道接收的,并且在服务器处接收 第二连接请求包括第二地址数据和与第二计算设备相关联的第二密码密钥,第二连接请求通过第二安全通信信道被接收。

    System and method for providing secured access to services
    29.
    发明授权
    System and method for providing secured access to services 有权
    提供安全访问服务的系统和方法

    公开(公告)号:US09350708B2

    公开(公告)日:2016-05-24

    申请号:US12791749

    申请日:2010-06-01

    IPC分类号: H04L29/06 H04W92/02

    摘要: A system and method for providing authenticated access to an initiating terminal in relation to the services provided by a terminating terminal via a communications network are disclosed. In one aspect, a global server comprises a communications module, which receives and processes a key exchange initiation message from the initiating terminal so as to establish an encrypted communications channel with the terminating terminal. The communications module, responsive to a received key exchange initiation message, performs an encrypted communication establishment process in respect of the received key exchange initiation message. The encrypted communication establishment process comprises authenticating the initiating terminal, and in the event that the initiating terminal is successfully authenticated, transmitting keying data corresponding to the received key exchange initiation message to the terminating terminal. The keying data is identified on the basis of data associated with the initiating terminal.

    摘要翻译: 公开了一种用于经由通信网络提供与由终端提供的服务有关的对发起终端的认证访问的系统和方法。 一方面,全局服务器包括通信模块,其从发起终端接收和处理密钥交换发起消息,以便与终接终端建立加密的通信信道。 所述通信模块响应于所接收的密钥交换发起消息,针对所接收的密钥交换发起消息执行加密的通信建立处理。 加密通信建立过程包括认证发起终端,并且在发起终端成功认证的情况下,将与所接收的密钥交换发起消息相对应的密钥数据传送到终接终端。 基于与发起终端相关联的数据来识别密钥数据。