System and method for retrieving related certificates
    41.
    发明授权
    System and method for retrieving related certificates 有权
    检索相关证书的系统和方法

    公开(公告)号:US07631183B2

    公开(公告)日:2009-12-08

    申请号:US10931108

    申请日:2004-09-01

    摘要: A system and method for searching and retrieving certificates, which may be used in the processing of encoded messages. In one embodiment, a certificate synchronization application is programmed to perform certificate searches by querying one or more certificate servers for all certificate authority (CA) certificates and cross-certificates on the certificate servers. In another embodiment, all certificates related to an identified certificate are retrieved from the certificate servers automatically by the certificate synchronization application, where the related certificates comprise at least one of one or more CA certificates and one or more cross-certificates. Embodiments of the invention facilitate at least partial automation of the downloading and establishment of certificate chains, thereby minimizing the need for users to manually search for individual certificates.

    摘要翻译: 用于搜索和检索证书的系统和方法,其可以用于编码消息的处理。 在一个实施例中,证书同步应用程序被编程为通过在一个或多个证书服务器上查询证书服务器上的所有证书颁发机构(CA)证书和交叉证书来执行证书搜索。 在另一个实施例中,证书同步应用程序自动从证书服务器检索与所识别的证书相关的所有证书,其中相关证书包括一个或多个CA证书和一个或多个交叉证书中的至少一个。 本发明的实施例促进了证书链的下载和建立的至少部分自动化,从而最小化对用户手动搜索单个证书的需要。

    METHOD, SYSTEM AND DEVICE FOR AUTHENTICATING A USER
    42.
    发明申请
    METHOD, SYSTEM AND DEVICE FOR AUTHENTICATING A USER 审中-公开
    用于认证用户的方法,系统和设备

    公开(公告)号:US20090282247A1

    公开(公告)日:2009-11-12

    申请号:US12500840

    申请日:2009-07-10

    IPC分类号: H04L9/00

    CPC分类号: G06F21/35 G06F21/34

    摘要: Embodiments described herein relate to a method and device for authenticating a user of a computer and a corresponding system using the method and device. The device is a handheld electronic device configured to receive a first authentication code and to generate a secure identification token. If the received first authentication code and the generated token match, a second authentication code is transmitted to a computer to unlock the computer.

    摘要翻译: 本文描述的实施例涉及一种用于认证计算机的用户和使用该方法和装置的相应系统的方法和装置。 该设备是被配置为接收第一认证码并生成安全识别令牌的手持电子设备。 如果接收到的第一认证码和生成的令牌匹配,则将第二认证码发送到计算机以解锁计算机。

    APPARATUS AND METHOD FOR INTEGRATING AUTHENTICATION PROTOCOLS IN THE ESTABLISHMENT OF CONNECTIONS BETWEEN COMPUTING DEVICES
    43.
    发明申请
    APPARATUS AND METHOD FOR INTEGRATING AUTHENTICATION PROTOCOLS IN THE ESTABLISHMENT OF CONNECTIONS BETWEEN COMPUTING DEVICES 有权
    在建立计算机设备之间的连接时集成认证协议的装置和方法

    公开(公告)号:US20110167484A1

    公开(公告)日:2011-07-07

    申请号:US13046861

    申请日:2011-03-14

    IPC分类号: G06F21/20

    CPC分类号: H04L63/0815 G06F21/41

    摘要: An apparatus and method for integrating authentication protocols in the establishment of connections between a controlled-access first computing device and at least one second computing device. In one embodiment, network access user authentication data needed to access the at least one second computing device is transmitted to an authentication server automatically if the user has access to use the first computing device, thereby not requiring the user to manually enter the authentication data needed for such access at the first computing device. The network access user authentication data may be, for example, retrieved from a memory store of the first computing device and/or generated in accordance with an authentication data generating algorithm.

    摘要翻译: 一种用于将认证协议集成在控制访问第一计算设备与至少一个第二计算设备之间的连接建立中的装置和方法。 在一个实施例中,如果用户可以访问使用第一计算设备,则自动地将访问至少一个第二计算设备所需的网络访问用户认证数据传送到认证服务器,从而不要求用户手动输入所需的认证数据 用于在第一计算设备处的这种访问。 网络访问用户认证数据可以例如从第一计算设备的存储器存储器中检索和/或根据认证数据生成算法生成。

    APPARATUS AND METHOD FOR INTEGRATING AUTHENTICATION PROTOCOLS IN THE ESTABLISHMENT OF CONNECTIONS BETWEEN COMPUTING DEVICES
    44.
    发明申请
    APPARATUS AND METHOD FOR INTEGRATING AUTHENTICATION PROTOCOLS IN THE ESTABLISHMENT OF CONNECTIONS BETWEEN COMPUTING DEVICES 有权
    在建立计算机设备之间的连接时集成认证协议的装置和方法

    公开(公告)号:US20090077644A1

    公开(公告)日:2009-03-19

    申请号:US12274448

    申请日:2008-11-20

    IPC分类号: H04L9/32

    CPC分类号: H04L63/0815 G06F21/41

    摘要: An apparatus and method for integrating authentication protocols in the establishment of connections between a controlled-access first computing device and at least one second computing device. In one embodiment, network access user authentication data needed to access the at least one second computing device is transmitted to an authentication server automatically if the user has access to use the first computing device, thereby not requiring the user to manually enter the authentication data needed for such access at the first computing device. The network access user authentication data may be, for example, retrieved from a memory store of the first computing device and/or generated in accordance with an authentication data generating algorithm.

    摘要翻译: 一种用于将认证协议集成在控制访问第一计算设备与至少一个第二计算设备之间的连接建立中的装置和方法。 在一个实施例中,如果用户可以访问使用第一计算设备,则自动地将访问至少一个第二计算设备所需的网络访问用户认证数据传送到认证服务器,从而不要求用户手动输入所需的认证数据 用于在第一计算设备处的这种访问。 网络访问用户认证数据可以例如从第一计算设备的存储器存储器中检索和/或根据认证数据生成算法生成。

    Apparatus and method for integrating authentication protocols in the establishment of connections between computing devices
    45.
    发明授权
    Apparatus and method for integrating authentication protocols in the establishment of connections between computing devices 有权
    用于在确定计算设备之间的连接的情况下集成认证协议的装置和方法

    公开(公告)号:US07921209B2

    公开(公告)日:2011-04-05

    申请号:US12274448

    申请日:2008-11-20

    IPC分类号: G06F15/173

    CPC分类号: H04L63/0815 G06F21/41

    摘要: An apparatus and method for integrating authentication protocols in the establishment of connections between a controlled-access first computing device and at least one second computing device. In one embodiment, network access user authentication data needed to access the at least one second computing device is transmitted to an authentication server automatically if the user has access to use the first computing device, thereby not requiring the user to manually enter the authentication data needed for such access at the first computing device. The network access user authentication data may be, for example, retrieved from a memory store of the first computing device and/or generated in accordance with an authentication data generating algorithm.

    摘要翻译: 一种用于将认证协议集成在控制访问第一计算设备与至少一个第二计算设备之间的连接建立中的装置和方法。 在一个实施例中,如果用户可以访问使用第一计算设备,则自动地将访问至少一个第二计算设备所需的网络访问用户认证数据传送到认证服务器,从而不要求用户手动输入所需的认证数据 用于在第一计算设备处的这种访问。 网络访问用户认证数据可以例如从第一计算设备的存储器存储器中检索和/或根据认证数据生成算法生成。

    Apparatus and method for integrating authentication protocols in the establishment of connections between computing devices
    46.
    发明授权
    Apparatus and method for integrating authentication protocols in the establishment of connections between computing devices 有权
    用于在确定计算设备之间的连接的情况下集成认证协议的装置和方法

    公开(公告)号:US07469291B2

    公开(公告)日:2008-12-23

    申请号:US10945950

    申请日:2004-09-22

    IPC分类号: G06F15/173

    CPC分类号: H04L63/0815 G06F21/41

    摘要: An apparatus and method for integrating authentication protocols in the establishment of connections between a controlled-access first computing device and at least one second computing device. In one embodiment of the invention, network access user authentication data needed to access the at least one second computing device is transmitted to an authentication server automatically if the user has access to use the first computing device, thereby not requiring the user to manually enter the authentication data needed for such access at the first computing device. The network access user authentication data may be, for example, retrieved from a memory store of the first computing device and/or generated in accordance with an authentication data generating algorithm.

    摘要翻译: 一种用于将认证协议集成在控制访问第一计算设备与至少一个第二计算设备之间的连接建立中的装置和方法。 在本发明的一个实施例中,如果用户有权访问使用第一计算设备,则自动地将访问至少一个第二计算设备所需的网络访问用户认证数据自动发送到认证服务器,从而不要求用户手动进入 在第一计算设备处的这种访问所需的认证数据。 网络访问用户认证数据可以例如从第一计算设备的存储器存储器中检索和/或根据认证数据生成算法生成。

    SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS
    50.
    发明申请
    SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS 有权
    防止布鲁姆力量攻击的系统和方法

    公开(公告)号:US20080120504A1

    公开(公告)日:2008-05-22

    申请号:US11555030

    申请日:2006-10-31

    IPC分类号: H04L9/00

    摘要: In a system and method for authenticating a client device by an authentication device, the client device user is assigned a PIN generated by the authentication device. The user provides the PIN and a password to the client device, from which the client device generates a symmetric key and further generates a public/private key pair. The private key is encrypted using the symmetric key and stored in encrypted form only. The public key and a message authentication code generated from the PIN are provided to the authentication device, which stores the public key. Subsequently, when the user seeks to be authenticated, the user enters a password at the client device, which is used to generate a symmetric key to decrypt the encrypted private key. A message to the authentication device is signed using the resultant value. The authentication device uses the public key to verify the signature of the message.

    摘要翻译: 在用于通过认证设备认证客户端设备的系统和方法中,向客户端设备用户分配由认证设备产生的PIN。 用户向客户端设备提供PIN和密码,客户端设备从该设备生成对称密钥并进一步生成公钥/私钥对。 私钥使用对称密钥加密,仅以加密形式存储。 将公钥和从PIN生成的消息认证码提供给存储公钥的认证装置。 随后,当用户寻求认证时,用户在客户端设备处输入密码,用于生成对称密钥来解密加密的私钥。 使用结果值对认证设备的消息进行签名。 认证设备使用公钥验证消息的签名。