Challenge response-based device authentication system and method
    45.
    发明授权
    Challenge response-based device authentication system and method 有权
    基于挑战响应的设备认证系统和方法

    公开(公告)号:US07603556B2

    公开(公告)日:2009-10-13

    申请号:US10996369

    申请日:2004-11-26

    IPC分类号: H04L9/32

    摘要: A challenge response scheme authenticates a requesting device by an authenticating device. The authenticating device generates and issues a challenge to the requesting device. The requesting device combines the challenge with a hash of a password provided by a user, and the combination is further hashed in order to generate a requesting encryption key used to encrypt the user supplied password. The encrypted user supplied password is sent to the authenticating device as a response to the issued challenge. The authenticating device generates an authenticating encryption key by generating the hash of a combination of the challenge and a stored hash of an authenticating device password. The authenticating encryption key is used to decrypt the response in order to retrieve the user-supplied password. If the user-supplied password hash matches the stored authenticating device password hash, the requesting device is authenticated and the authenticating device is in possession of the password.

    摘要翻译: 挑战响应方案通过认证设备认证请求设备。 认证设备生成并向请求设备发出质询。 请求设备将挑战与由用户提供的密码的散列相结合,并且组合进一步进行散列,以便生成用于加密用户提供的密码的请求加密密钥。 加密的用户提供的密码作为对发布的挑战的响应被发送到认证设备。 认证设备通过生成质询的组合和存储的认证设备密码的哈希的散列来生成认证加密密钥。 认证加密密钥用于解密响应,以便检索用户提供的密码。 如果用户提供的密码哈希与存储的认证设备密码散列匹配,则请求设备被认证,认证设备拥有密码。

    METHOD AND APPARATUS FOR PROVIDING INTELLIGENT ERROR MESSAGING
    46.
    发明申请
    METHOD AND APPARATUS FOR PROVIDING INTELLIGENT ERROR MESSAGING 有权
    用于提供智能错误消息的方法和装置

    公开(公告)号:US20090187796A1

    公开(公告)日:2009-07-23

    申请号:US12407834

    申请日:2009-03-20

    IPC分类号: G06F11/07 H04L9/32 G06F15/16

    摘要: A method and apparatus for providing intelligent error messaging is disclosed wherein a user of a mobile communications device is provided with descriptive error messaging information to assist the user in overcoming errors associated with the processing of electronic messages and data. For example, when the mobile device is being used to decrypt a cryptographically secured electronic message, and a problem is encountered, program logic of the device provides the user with (1) an indication of exactly what problem is preventing opening of the message, for example, a required cryptographic key is not available; (2) an indication of exactly what may be done to overcome the problem, for example, what utilities should be run on the device; and (3) exactly what data, if any, needs to be downloaded to the device, for example, what cryptographic keys should be downloaded.

    摘要翻译: 公开了一种用于提供智能错误消息的方法和装置,其中向移动通信设备的用户提供描述性错误消息信息,以帮助用户克服与电子消息和数据的处理相关的错误。 例如,当移动设备被用于解密密码保护的电子消息并且遇到问题时,该设备的程序逻辑向用户提供(1)正确地指示什么问题阻止该消息打开的指示,用于 例如,所需的加密密钥不可用; (2)可以确切地说明什么可以做以克服这个问题,例如什么实用程序应该在设备上运行; 和(3)需要什么数据(如果有的话)需要下载到设备,例如什么加密密钥应该被下载。

    Challenge response-based device authentication system and method
    48.
    发明授权
    Challenge response-based device authentication system and method 有权
    基于挑战响应的设备认证系统和方法

    公开(公告)号:US08074072B2

    公开(公告)日:2011-12-06

    申请号:US12428170

    申请日:2009-04-22

    IPC分类号: H04L9/32

    摘要: A challenge response scheme authenticates a requesting device by an authenticating device. The authenticating device generates and issues a challenge to the requesting device. The requesting device combines the challenge with a hash of a password provided by a user, and the combination is further hashed in order to generate a requesting encryption key used to encrypt the user supplied password. The encrypted user supplied password is sent to the authenticating device as a response to the issued challenge. The authenticating device generates an authenticating encryption key by generating the hash of a combination of the challenge and a stored hash of an authenticating device password. The authenticating encryption key is used to decrypt the response in order to retrieve the user-supplied password. If the user-supplied password hash matches the stored authenticating device password hash, the requesting device is authenticated and the authenticating device is in possession of the password.

    摘要翻译: 挑战响应方案通过认证设备认证请求设备。 认证设备生成并向请求设备发出质询。 请求设备将挑战与由用户提供的密码的散列相结合,并且组合进一步进行散列,以便生成用于加密用户提供的密码的请求加密密钥。 加密的用户提供的密码作为对发布的挑战的响应被发送到认证设备。 认证设备通过生成质询的组合和存储的认证设备密码的哈希的散列来生成认证加密密钥。 认证加密密钥用于解密响应,以便检索用户提供的密码。 如果用户提供的密码哈希与存储的认证设备密码散列匹配,则请求设备被认证,认证设备拥有密码。

    System and method to force a mobile device into a secure state
    50.
    发明授权
    System and method to force a mobile device into a secure state 有权
    强制移动设备进入安全状态的系统和方法

    公开(公告)号:US08042189B2

    公开(公告)日:2011-10-18

    申请号:US11614561

    申请日:2006-12-21

    IPC分类号: G06F21/00 G06F21/22

    摘要: Embodiments relate to systems and methods for implementation on a mobile device to force the mobile device into a secure state upon detection or determination of a triggering event. Once it is determined that a triggering event has occurred, each application operating on the mobile device is caused to immediately unreference sensitive objects and a secure garbage collection operation is performed upon the unreferenced sensitive objects to render data associated therewith unreadable. The mobile device is then caused to enter a secure state, in which the mobile device cannot be accessed without authorization. A microprocessor within the mobile device is configured to determine the existence of the triggering event according to a configuration data structure and to perform the secure garbage collection.

    摘要翻译: 实施例涉及用于在移动设备上实现的系统和方法,以在检测或确定触发事件时强制移动设备进入安全状态。 一旦确定已经发生触发事件,则导致在移动设备上操作的每个应用程序立即不敏感的对象,并且对未引用的敏感对象执行安全的垃圾回收操作,以使与其相关联的数据不可读。 然后使移动设备进入安全状态,在该状态下移动设备无法在未经授权的情况下被访问。 移动设备内的微处理器被配置为根据配置数据结构确定触发事件的存在并执行安全垃圾收集。