Methods and systems for secure remote wake, boot, and login to a computer from a mobile device
    41.
    发明授权
    Methods and systems for secure remote wake, boot, and login to a computer from a mobile device 有权
    用于从移动设备安全远程唤醒,引导和登录到计算机的方法和系统

    公开(公告)号:US08375220B2

    公开(公告)日:2013-02-12

    申请号:US12753591

    申请日:2010-04-02

    IPC分类号: H04L29/06

    摘要: Methods and systems to allow an authorized user to remotely awaken, boot, and login to a computer in a secure manner. The user and computer may communicate using a short message service. (SMS). The user may communicate with the computer using a mobile device, such as a smart phone. The user may initially provide a wake-up message to the computer, which may then respond by asking for one or more boot passwords. In an embodiment, these boot passwords may be basic input/output system (BIOS) passwords that are required for the loading and operations of the computer's BIOS. The user may then provide these one or more passwords to the computer. The computer may further request an operating system (OS) login password. The user may then provide this password to the computer. In an embodiment, all passwords may be provided to the computer in encrypted form. Moreover, authentication measures may be used to provide assurance that the user is legitimate.

    摘要翻译: 允许授权用户以安全的方式远程唤醒,引导和登录计算机的方法和系统。 用户和计算机可以使用短消息服务进行通信。 (短信)。 用户可以使用诸如智能电话的移动设备与计算机进行通信。 用户可以最初向计算机提供唤醒消息,该消息然后可以通过询问一个或多个引导密码来进行响应。 在一个实施例中,这些启动密码可以是加载和操作计算机的BIOS所需的基本输入/输出系统(BIOS)密码。 然后,用户可以向计算机提供这些一个或多个密码。 计算机可以进一步请求操作系统(OS)登录密码。 然后,用户可以向计算机提供该密码。 在一个实施例中,所有密码可以以加密形式提供给计算机。 此外,可以使用认证措施来提供用户是合法的保证。

    Secure subscriber identity module service
    42.
    发明授权
    Secure subscriber identity module service 有权
    安全的用户身份模块服务

    公开(公告)号:US08171529B2

    公开(公告)日:2012-05-01

    申请号:US12653709

    申请日:2009-12-17

    IPC分类号: G06F7/04

    摘要: A method, apparatus, system, and computer program product for a secure subscriber identity module service. Communication via a mobile network is activated in response to receiving a request to activate communication service for the system by a secure partition of the system. In response to receiving the request, a key is retrieved for a permit service from storage accessible only by the secure partition. The key is included in a permit requesting to activate the communication service, and the permit is sent to a service provider for the communication service. The service provider communicates with the permit service to obtain a digital signature for the permit. The secure partition receives a signed permit from the service provider, confirms that the signed permit contains the digital signature by the permit service, and activates the communication service for the system in response to confirming that the signed permit contains the digital signature.

    摘要翻译: 一种用于安全用户识别模块服务的方法,装置,系统和计算机程序产品。 响应于通过系统的安全分区来接收为系统激活通信服务的请求而激活通过移动网络的通信。 响应于接收到请求,从仅由安全分区访问的存储中检索用于许可服务的密钥。 密钥被包括在请求激活通信服务的许可证中,并且许可证被发送到用于通信服务的服务提供商。 服务提供者与许可证服务人员进行通信,以获得许可证的数字签名。 安全分区从服务提供商接收签名的许可证,确认签名的许可证包含许可服务的数字签名,并且响应于确认签署的许可证包含数字签名,激活系统的通信服务。

    Using chipset-based protected firmware for host software tamper detection and protection
    43.
    发明申请
    Using chipset-based protected firmware for host software tamper detection and protection 有权
    使用基于芯片组的保护固件进行主机软件篡改检测和保护

    公开(公告)号:US20110078791A1

    公开(公告)日:2011-03-31

    申请号:US12586705

    申请日:2009-09-25

    IPC分类号: G06F21/00 G06F17/30

    摘要: A method, system, and computer program product for a host software tamper detection and protection service. A secure partition that is isolated from a host operating system of the host system, which may be implemented by firmware of a chipset of the host system, obtains file metadata from the host system and uses the file metadata to identify a first file for examination for tampering. The secure partition obtains data blocks for the first file, communicates with a service via an out-of-band communication channel, and uses information obtained from the service and the data blocks to determine whether the first file has been corrupted. The secure partition obtains the file metadata and the data blocks for the first file without invoking an operating system or file system of the host system.

    摘要翻译: 用于主机软件篡改检测和保护服务的方法,系统和计算机程序产品。 与主机系统的芯片组的固件实现的与主机系统的主机操作系统隔离的安全分区从主机系统获取文件元数据,并使用该文件元数据来识别第一文件以便检查 篡改。 安全分区获取第一文件的数据块,经由带外通信信道与服务通信,并使用从服务和数据块获得的信息来确定第一文件是否已被破坏。 安全分区在不调用主机系统的操作系统或文件系统的情况下获得文件元数据和第一文件的数据块。

    SECURITY ENGINE FOR A SECURE OPERATING ENVIRONMENT

    公开(公告)号:US20190188394A1

    公开(公告)日:2019-06-20

    申请号:US16269829

    申请日:2019-02-07

    摘要: The presenting invention relates to techniques for implementing a secure operating environment for the execution of applications on a computing devices (e.g., a mobile phone). In The secure operating environment may provide a trusted environment with dedicated computing resources to manage security and integrity of processing and data for the applications. The applications may be provided with a variety of security services and/or functions to meet different levels of security demanded by an application. The secure operating environment may include a security engine that enumerates and/or determines the security capabilities of the secure operating environment and the computing device, e.g., the hardware, the software, and/or the firmware of the computing device. The security engine may provide security services desired by applications by choosing from the security capabilities that are supported by the secure operating environment and the computing device.

    METHOD AND SYSTEM FOR UTILIZING SECURE PROFILES IN EVENT DETECTION

    公开(公告)号:US20180107828A1

    公开(公告)日:2018-04-19

    申请号:US15828042

    申请日:2017-11-30

    摘要: The presenting invention relates to techniques for implementing a secure operating environment for the execution of applications on a computing devices (e.g., a mobile phone). In The secure operating environment may provide a trusted environment with dedicated computing resources to manage security and integrity of processing and data for the applications. The applications may be provided with a variety of security services and/or functions to meet different levels of security demanded by an application. The secure operating environment may include a security engine that enumerates and/or determines the security capabilities of the secure operating environment and the computing device, e.g., the hardware, the software, and/or the firmware of the computing device. The security engine may provide security services desired by applications by choosing from the security capabilities that are supported by the secure operating environment and the computing device.

    SECURE BINDING OF SOFTWARE APPLICATION TO COMMUNICATION DEVICE
    47.
    发明申请
    SECURE BINDING OF SOFTWARE APPLICATION TO COMMUNICATION DEVICE 审中-公开
    软件应用于通信设备的安全绑定

    公开(公告)号:US20170063975A1

    公开(公告)日:2017-03-02

    申请号:US14841202

    申请日:2015-08-31

    IPC分类号: H04L29/08 G06F9/48 H04L29/06

    摘要: Techniques for securely binding a software application to a communication device may include sending a set of device identifiers associated with the computing device to a server, receiving a server-generated dynamic device identifier that is generated based on the set of device identifiers; and storing the server-generated dynamic device identifier during initialization of the application. During runtime execution of the application, the application may receive a request to execute an application specific task. In response to receiving the request, the application may generate a runtime dynamic device identifier, determine whether the runtime dynamic device identifier matches the server-generated dynamic device identifier, execute the application specific task when the runtime dynamic device identifier matches the server-generated dynamic device identifier; and prevent the application specific task from being executed when the runtime dynamic device identifier does not match the server-generated dynamic device identifier.

    摘要翻译: 用于将软件应用程序安全地绑定到通信设备的技术可以包括向服务器发送与计算设备相关联的一组设备标识符,接收基于该设备标识符集合生成的服务器生成的动态设备标识符; 以及在应用的初始化期间存储服务器生成的动态设备标识符。 在运行时执行应用程序期间,应用程序可以接收执行特定于应用程序的任务的请求。 响应于接收到请求,应用可以生成运行时动态设备标识符,确定运行时动态设备标识符是否与服务器生成的动态设备标识符匹配,当运行时动态设备标识符与服务器生成的动态 设备标识符 并且当运行时动态设备标识符与服务器生成的动态设备标识符不匹配时,防止应用程序特定任务被执行。

    SECURITY ENGINE FOR A SECURE OPERATING ENVIRONMENT
    48.
    发明申请
    SECURITY ENGINE FOR A SECURE OPERATING ENVIRONMENT 审中-公开
    安全运行环境安全发动机

    公开(公告)号:US20160335441A1

    公开(公告)日:2016-11-17

    申请号:US15220290

    申请日:2016-07-26

    IPC分类号: G06F21/60 G06F21/62

    摘要: The presenting invention relates to techniques for implementing a secure operating environment for the execution of applications on a computing devices (e.g., a mobile phone). In The secure operating environment may provide a trusted environment with dedicated computing resources to manage security and integrity of processing and data for the applications. The applications may be provided with a variety of security services and/or functions to meet different levels of security demanded by an application. The secure operating environment may include a security engine that enumerates and/or determines the security capabilities of the secure operating environment and the computing device, e.g., the hardware, the software, and/or the firmware of the computing device. The security engine may provide security services desired by applications by choosing from the security capabilities that are supported by the secure operating environment and the computing device.

    摘要翻译: 本发明涉及用于实现用于在计算设备(例如,移动电话)上执行应用的安全操作环境的技术。 在安全的操作环境中,可以为受信任的环境提供专用的计算资源来管理应用程序的处理和数据的安全性和完整性。 应用可以被提供有各种安全服务和/或功能以满足应用所要求的不同级别的安全性。 安全操作环境可以包括枚举和/或确定安全操作环境和计算设备(例如计算设备的硬件,软件和/或固件)的安全能力的安全引擎。 安全引擎可以通过从由安全操作环境和计算设备支持的安全功能中进行选择来提供应用所期望的安全服务。

    MOBILE DEVICE WITH SCANNABLE IMAGE INCLUDING DYNAMIC DATA
    49.
    发明申请
    MOBILE DEVICE WITH SCANNABLE IMAGE INCLUDING DYNAMIC DATA 有权
    具有可扫描图像的移动设备,包括动态数据

    公开(公告)号:US20160042263A1

    公开(公告)日:2016-02-11

    申请号:US14823567

    申请日:2015-08-11

    IPC分类号: G06K19/06

    摘要: A mobile phone is disclosed. The mobile phone may receive a first request to generate an initial scannable image, and a second request to generate modified scannable image. The modified scannable image can include a static portion that corresponds to a static portion of the initial scannable image. The modified scannable image may also include another portion that has a different appearance than a corresponding portion of the initial scannable image.

    摘要翻译: 公开了一种移动电话。 移动电话可以接收生成初始可扫描图像的第一请求,以及生成修改的可扫描图像的第二请求。 修改的可扫描图像可以包括对应于初始可扫描图像的静态部分的静态部分。 修改的可扫描图像还可以包括具有与初始可扫描图像的对应部分不同的外观的另一部分。