TECHNOLOGIES FOR PREVENTING HOOK-SKIPPING ATTACKS USING PROCESSOR VIRTUALIZATION FEATURES
    41.
    发明申请
    TECHNOLOGIES FOR PREVENTING HOOK-SKIPPING ATTACKS USING PROCESSOR VIRTUALIZATION FEATURES 有权
    使用处理器虚拟化功能防止跳槽攻击的技术

    公开(公告)号:US20150379263A1

    公开(公告)日:2015-12-31

    申请号:US14318215

    申请日:2014-06-27

    IPC分类号: G06F21/56

    CPC分类号: G06F21/79 G06F21/62

    摘要: Technologies for monitoring system API calls include a computing device with hardware virtualization support. The computing device establishes a default memory view and a security memory view to define physical memory maps and permissions. The computing device executes an application in the default memory view and executes a default inline hook in response to a call to an API function. The default inline hook switches to the security memory view using hardware support without causing a virtual machine exit. The security inline hook calls a security callback function to validate the API function call in the security memory view. Hook-skipping attacks may be prevented by padding the default inline hook with no-operation instructions, by designating memory pages of the API function as non-executable in the default memory view, or by designating memory pages of the application as non-executable in the security memory view. Other embodiments are described and claimed.

    摘要翻译: 用于监视系统API调用的技术包括具有硬件虚拟化支持的计算设备。 计算设备建立默认内存视图和安全内存视图来定义物理内存映射和权限。 计算设备在默认存储器视图中执行应用程序,并响应于对API函数的调用执行默认内联钩子。 默认内联挂钩将使用硬件支持切换到安全内存视图,而不会导致虚拟机退出。 安全内联钩调用安全回调函数来验证安全内存视图中的API函数调用。 通过将默认内存视图中的不可执行的API函数的内存页指定为不可执行的内存页,或者通过将应用程序的内存页指定为不可执行的方式,可以通过使用无操作指令填充默认内联钩来防止跳钩攻击 安全内存视图。 描述和要求保护其他实施例。

    LANGUAGE TRANSLATOR MODULE IN THE MIDDLEWARE TOOL PROCESS INTEGRATION
    42.
    发明申请
    LANGUAGE TRANSLATOR MODULE IN THE MIDDLEWARE TOOL PROCESS INTEGRATION 审中-公开
    语言翻译模块在中间件工具集成

    公开(公告)号:US20150012259A1

    公开(公告)日:2015-01-08

    申请号:US13934124

    申请日:2013-07-02

    IPC分类号: G06F17/28

    CPC分类号: G06F17/289

    摘要: A process integration system to interface between a sender system and a receiver system is described. The process integration system has a sender adapter, an integration engine, a receiver adapter, and a language converter module. The sender adapter receives a communication in a first language from the sender system. The communication is in a first format of the sender system. The sender adapter converts the communication into a second format of the process integration system, and the integration engine identifies the receiver system from the communication in the second format. The receiver adapter converts the communication from the second format to a third format of the receiver system, and sends the communication in the third format and in a second language to the receiver system. The language converter module translates the communication in the third format to the second language associated with the receiver system.

    摘要翻译: 描述了在发送方系统和接收方系统之间进行接口的过程集成系统。 过程集成系统具有发送器适配器,集成引擎,接收器适配器和语言转换器模块。 发送者适配器从发送者系统接收第一语言的通信。 通信是发送方系统的第一种格式。 发送者适配器将通信转换为过程集成系统的第二格式,并且集成引擎以第二格式从通信中识别接收机系统。 接收机适配器将来自第二格式的通信转换成接收机系统的第三格式,并将第三格式和第二种语言的通信发送到接收机系统。 语言转换器模块将第三格式的通信转换为与接收机系统相关联的第二语言。

    Method and apparatus for identifying referenced content within an online presentation environment
    43.
    发明授权
    Method and apparatus for identifying referenced content within an online presentation environment 有权
    用于在线呈现环境中识别参考内容的方法和装置

    公开(公告)号:US08510427B1

    公开(公告)日:2013-08-13

    申请号:US13229176

    申请日:2011-09-09

    IPC分类号: G06F15/173

    摘要: A method and apparatus for identifying referenced content within an online presentation environment. Upon entry of a statement related to specific content being presented within the online presentation environment, the method and apparatus identify the specific content within the presentation and, upon subsequent selection of the statement, display the specific content.

    摘要翻译: 一种用于在在线呈现环境中识别参考内容的方法和装置。 在与在线呈现环境中呈现的特定内容的陈述相关联时,该方法和装置识别呈现内的特定内容,并且在随后选择该陈述时显示特定内容。

    Transferring money using a mobile electronic device
    44.
    发明授权
    Transferring money using a mobile electronic device 有权
    使用移动电子设备转账

    公开(公告)号:US08315945B1

    公开(公告)日:2012-11-20

    申请号:US13244778

    申请日:2011-09-26

    申请人: Vikas Gupta

    发明人: Vikas Gupta

    IPC分类号: G06Q40/00

    摘要: A check service provider enables users to make and receive payments from a financial account via a mobile electronic device, such as a smartphone or tablet computer. The device includes a check module and a camera. A user can capture an image of a check using the camera and the check module deciphers information, such as an account number, bank routing number, and information regarding the account holder, from the image of the check. The user can then make payments from and receive payments into the financial account associated with the imaged check via the check module without having the physically write or deposit a check. The check service provider interacts with the ACH to settle payments directly between the user's accounts without handling the money. Users can be notified of pending payments via text, voice, and e-mail messaging.

    摘要翻译: 检查服务提供商使用户能够通过诸如智能电话或平板电脑的移动电子设备从金融账户发送和接收付款。 该装置包括检查模块和照相机。 用户可以使用相机拍摄支票的图像,并且检查模块从支票的图像中解密信息,例如帐号,银行路由号码和关于账户持有人的信息。 然后,用户可以通过支票模块从付款和接收与成像支票相关联的金融账户,而无需物理写入或存入支票。 检查服务提供商与ACH进行交互,直接在用户帐户之间解决支付,而无需处理该款项。 可以通过文本,语音和电子邮件消息通知用户待付款。

    Transaction processing system that applies user-specified rules to divide payment amounts among multiple payment instruments
    46.
    发明授权
    Transaction processing system that applies user-specified rules to divide payment amounts among multiple payment instruments 有权
    交易处理系统,适用用户指定的规则,在多个付款工具之间划分支付金额

    公开(公告)号:US08099361B1

    公开(公告)日:2012-01-17

    申请号:US10634135

    申请日:2003-08-04

    IPC分类号: G06Q40/00

    摘要: A network-based transaction processing system allows online users to flexibly and efficiently make payments using a combination of different payment instruments. The system includes a user interface through which each user can define one or more personal payment plans. Each such payment plan specifies a plurality of payment instruments, and includes rules that specify how the monetary amount associated with a transaction is to be divided among these payment instruments. These rules may be non-transaction-specific, such that a user can re-use a payment plan over time to complete multiple transactions. In one embodiment, a user can specify an order in which the payment instruments are to be applied, and can specify per-transaction maximum monetary amounts to be charged to specific instruments.

    摘要翻译: 基于网络的交易处理系统允许在线用户使用不同支付工具的组合灵活有效地进行支付。 该系统包括用户界面,每个用户可以通过该界面来定义一个或多个个人支付计划。 每个这样的支付计划指定多个支付工具,并且包括指定如何在这些支付工具之间划分与交易相关联的金额的规则。 这些规则可以是非交易特定的,使得用户可以随着时间重新使用支付计划来完成多个交易。 在一个实施例中,用户可以指定要应用支付工具的顺序,并且可以指定要向特定工具收取的每个交易的最大金额。

    Performing automatically authorized programmatic transactions
    48.
    发明授权
    Performing automatically authorized programmatic transactions 有权
    执行自动授权的程序化交易

    公开(公告)号:US07962415B2

    公开(公告)日:2011-06-14

    申请号:US12543374

    申请日:2009-08-18

    IPC分类号: G06F21/00

    摘要: Techniques are described for facilitating interactions between computing systems, such as by performing transactions between parties that are automatically authorized via a third-party transaction authorization system. In some situations, the transactions are programmatic transactions involving the use of fee-based Web services by executing application programs, with the transaction authorization system authorizing and/or providing payments in accordance with private authorization instructions previously specified by the parties. The authorization instructions may include predefined instruction rule sets that regulate conditions under which a potential transaction can be authorized, with the instruction rule sets each referenced by an associated reference token. After one or more of the parties to a potential transaction supply reference tokens for the parties, the transaction authorization system can determine whether to authorize the transaction based on whether the instruction rule sets associated with the reference tokens are compatible or otherwise satisfied.

    摘要翻译: 描述了用于促进计算系统之间的交互的技术,例如通过执行经由第三方交易授权系统自动授权的各方之间的交易。 在某些情况下,交易是涉及通过执行应用程序使用基于费用的Web服务的程序交易,交易授权系统根据双方以前指定的私人授权指令授权和/或提供付款。 授权指令可以包括预定义的指令规则集,其规定可以授权潜在事务的条件,每个指令规则集都由相关联的引用令牌引用。 在潜在交易的一方或多方提供参考各方的代理人之后,交易授权系统可以基于与引用令牌相关联的指令规则集是兼容还是满足来确定是否授权交易。

    PERFORMING AUTOMATICALLY AUTHORIZED PROGRAMMATIC TRANSACTIONS
    50.
    发明申请
    PERFORMING AUTOMATICALLY AUTHORIZED PROGRAMMATIC TRANSACTIONS 有权
    执行自动授权的编程交易

    公开(公告)号:US20080177663A1

    公开(公告)日:2008-07-24

    申请号:US12058638

    申请日:2008-03-28

    IPC分类号: G06Q20/00

    摘要: Techniques are described for facilitating interactions between computing systems, such as by performing transactions between parties that are automatically authorized via a third-party transaction authorization system. In some situations, the transactions are programmatic transactions involving the use of fee-based Web services by executing application programs, with the transaction authorization system authorizing and/or providing payments in accordance with private authorization instructions previously specified by the parties. The authorization instructions may include predefined instruction rule sets that regulate conditions under which a potential transaction can be authorized, with the instruction rule sets each referenced by an associated reference token. After one or more of the parties to a potential transaction supply reference tokens for the parties, the transaction authorization system can determine whether to authorize the transaction based on whether the instruction rule sets associated with the reference tokens are compatible or otherwise satisfied.

    摘要翻译: 描述了用于促进计算系统之间的交互的技术,例如通过执行经由第三方交易授权系统自动授权的各方之间的交易。 在某些情况下,交易是涉及通过执行应用程序使用基于费用的Web服务的程序交易,交易授权系统根据双方以前指定的私人授权指令授权和/或提供付款。 授权指令可以包括预定义的指令规则集,其规定可以授权潜在事务的条件,每个指令规则集都由相关联的引用令牌引用。 在潜在交易的一方或多方提供参考各方的代理人之后,交易授权系统可以基于与引用令牌相关联的指令规则集是兼容还是满足来确定是否授权交易。