METHOD, SYSTEM AND DEVICE FOR AUTHENTICATING A USER
    41.
    发明申请
    METHOD, SYSTEM AND DEVICE FOR AUTHENTICATING A USER 审中-公开
    用于认证用户的方法,系统和设备

    公开(公告)号:US20090282247A1

    公开(公告)日:2009-11-12

    申请号:US12500840

    申请日:2009-07-10

    IPC分类号: H04L9/00

    CPC分类号: G06F21/35 G06F21/34

    摘要: Embodiments described herein relate to a method and device for authenticating a user of a computer and a corresponding system using the method and device. The device is a handheld electronic device configured to receive a first authentication code and to generate a secure identification token. If the received first authentication code and the generated token match, a second authentication code is transmitted to a computer to unlock the computer.

    摘要翻译: 本文描述的实施例涉及一种用于认证计算机的用户和使用该方法和装置的相应系统的方法和装置。 该设备是被配置为接收第一认证码并生成安全识别令牌的手持电子设备。 如果接收到的第一认证码和生成的令牌匹配,则将第二认证码发送到计算机以解锁计算机。

    CERTIFICATE INFORMATION STORAGE SYSTEM AND METHOD
    43.
    发明申请
    CERTIFICATE INFORMATION STORAGE SYSTEM AND METHOD 有权
    证书信息存储系统和方法

    公开(公告)号:US20110271115A1

    公开(公告)日:2011-11-03

    申请号:US13043859

    申请日:2011-03-09

    IPC分类号: H04L9/32 H04L9/08 H04L9/00

    CPC分类号: H04L63/0823 G06F21/606

    摘要: A system and method of storing in a computer device digital certificate data from a digital certificate are provided. When a digital certificate is received at the computer device, it is determined whether the digital certificate data in the digital certificate is stored in a first memory store in the computer device. The digital certificate data is stored in the first memory store upon determining that the digital certificate data is not stored in the first memory store.

    摘要翻译: 提供了一种在计算机设备中存储来自数字证书的数字证书数据的系统和方法。 当在计算机设备处接收到数字证书时,确定数字证书中的数字证书数据是否存储在计算机设备中的第一存储器存储器中。 在确定数字证书数据未被存储在第一存储器存储器中时,数字证书数据被存储在第一存储器存储器中。

    System and method of owner application control of electronic devices
    44.
    发明授权
    System and method of owner application control of electronic devices 有权
    电子设备所有者应用控制的系统和方法

    公开(公告)号:US07815100B2

    公开(公告)日:2010-10-19

    申请号:US11118844

    申请日:2005-04-29

    IPC分类号: G06F9/45

    摘要: Systems and methods of owner application control of an electronic device are provided. Owner application control information is stored on the electronic device and/or one or more remote servers. Owner application control information is consulted to determine if one or more required applications are available for execution on the electronic device. If not, one or more required applications not available are downloaded and installed. This could be in a manner transparent to the user of the electronic device. If one or more required applications are not available on the electronic device, the device can be functionally disabled in whole, or in part, until one or more required applications are available.

    摘要翻译: 提供了电子设备的所有者应用控制的系统和方法。 所有者应用控制信息存储在电子设备和/或一个或多个远程服务器上。 咨询所有者应用程序控制信息以确定一个或多个所需应用程序是否可用于在电子设备上执行。 如果没有,则下载并安装一个或多个不可用的必需应用程序。 这可以以对电子设备的用户透明的方式。 如果一个或多个所需的应用程序在电子设备上不可用,则该设备可以在全部或部分功能上禁用,直到一个或多个所需的应用程序可用。

    System and method for registering entities for code signing services
    45.
    发明授权
    System and method for registering entities for code signing services 有权
    用于注册代码签名服务实体的系统和方法

    公开(公告)号:US07797545B2

    公开(公告)日:2010-09-14

    申请号:US11237727

    申请日:2005-09-29

    IPC分类号: H04L9/00

    摘要: A system and method for registering entities for code signing services. The entities may be software application developers or other individuals or entities that wish to have applications digitally signed. Signing of the applications may be required in order to enable the applications to access sensitive APIs and associated resources of a computing device when the applications are executed on the computing device. In one embodiment, a method of registering entities for code signing services will comprise the step of transmitting at least some account data to the registering individual or entity using an out-of-band communication system. This provides added security that the individual or entity registering for a code signing service is who that individual or entity purports to be.

    摘要翻译: 一种用于注册代码签名服务实体的系统和方法。 实体可以是软件应用程序开发人员或希望对应用进行数字签名的其他个人或实体。 可能需要签署应用程序,以便在应用程序在计算设备上执行时,使应用程序能够访问计算设备的敏感API和相关资源。 在一个实施例中,注册用于代码签名服务的实体的方法将包括使用带外通信系统将至少一些帐户数据发送到注册个人或实体的步骤。 这提供了增加的安全性,注册代码签名服务的个人或实体是个人或实体所声称的。

    SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS
    50.
    发明申请
    SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS 有权
    防止布鲁姆力量攻击的系统和方法

    公开(公告)号:US20080120504A1

    公开(公告)日:2008-05-22

    申请号:US11555030

    申请日:2006-10-31

    IPC分类号: H04L9/00

    摘要: In a system and method for authenticating a client device by an authentication device, the client device user is assigned a PIN generated by the authentication device. The user provides the PIN and a password to the client device, from which the client device generates a symmetric key and further generates a public/private key pair. The private key is encrypted using the symmetric key and stored in encrypted form only. The public key and a message authentication code generated from the PIN are provided to the authentication device, which stores the public key. Subsequently, when the user seeks to be authenticated, the user enters a password at the client device, which is used to generate a symmetric key to decrypt the encrypted private key. A message to the authentication device is signed using the resultant value. The authentication device uses the public key to verify the signature of the message.

    摘要翻译: 在用于通过认证设备认证客户端设备的系统和方法中,向客户端设备用户分配由认证设备产生的PIN。 用户向客户端设备提供PIN和密码,客户端设备从该设备生成对称密钥并进一步生成公钥/私钥对。 私钥使用对称密钥加密,仅以加密形式存储。 将公钥和从PIN生成的消息认证码提供给存储公钥的认证装置。 随后,当用户寻求认证时,用户在客户端设备处输入密码,用于生成对称密钥来解密加密的私钥。 使用结果值对认证设备的消息进行签名。 认证设备使用公钥验证消息的签名。