Secure Card Reader
    41.
    发明申请
    Secure Card Reader 有权
    安全读卡器

    公开(公告)号:US20080164320A1

    公开(公告)日:2008-07-10

    申请号:US10591267

    申请日:2005-02-18

    Abstract: A secure card reader (1) includes several security measures. Access to the reader's main circuitry is prevented by an enclosure (9) whose walls contain embedded i conductive paths (18a, 18b, 18c). Breaking or grounding of one of these paths can be detected electronically. A similar arrangement of conductive paths prevent enlarging of a card receiving slot (9c) If tampering is detected using the embedded conductive paths (18a, 18b, 18c), the reader's memory (69) is wiped. The enclosure (9) has apertures (20) in its walls and is held in place by a potting material that extends into the apertures. Means (31, 35) is also provided to detect attempts to probe behind a keypad membrane (7). The contacts (42) for the chip of a chip card are arranged so that their leads all extend away from the card insertion slot.

    Abstract translation: 安全读卡器(1)包括几种安全措施。 通过其墙壁包含嵌入式i导电路径(18a,18b,18c)的外壳(9)防止对读取器的主电路的访问。 可以电子检测这些路径之一的断路或接地。 导电路径的类似布置防止卡接收槽的扩大(9c)如果使用嵌入式导电路径(18a,18b,18c)检测到篡改,则读取器的存储器(69)被擦除。 外壳(9)在其壁中具有孔(20),并通过延伸到孔中的灌封材料保持就位。 还提供了装置(31,35)以检测在键盘隔膜(7)后面探测的尝试。 用于芯片卡的芯片的触点(42)布置成使得它们的引线全部从卡插入槽延伸。

    Tetrahydroquinolones and Aza-Analogues Thereof for Use as Dpp-IV Inhibitors in the Treatment of Diabetes
    42.
    发明申请
    Tetrahydroquinolones and Aza-Analogues Thereof for Use as Dpp-IV Inhibitors in the Treatment of Diabetes 审中-公开
    用于治疗糖尿病的Dpp-IV抑制剂的四氢喹诺酮类及其氮杂类似物

    公开(公告)号:US20080009512A1

    公开(公告)日:2008-01-10

    申请号:US11569943

    申请日:2005-06-14

    CPC classification number: C07D215/38 C07D215/60 C07D471/04

    Abstract: Compound of formula (I) or a pharmaceutically-acceptable salt thereof, formula (I) wherein Ar is optionally substituted phenyl; R1 is selected from: formula a) or b) (wherein is a single or double bond); R5, R6, R7 and R8 are for or alkyl; R4 is selected from hydrogen, (3-4C)cycloalkyl and optionally substituted (1-4C)alkyl; R10 is for example selected from hydrogen, (1-4C)alkyl, (3-6C)cycloalkyl(1-4C)alkyl, hydroxy(1-4C)alkyl, (1-4C)alkoxy, aryl(1-4C)alkyl; Y is carbon and Ring A is optionally substituted phenylene; or each Y may independently be carbon or nitrogen and Ring A is optionally substituted 5- or 6-membered, heteroarylene ring; R11 is selected from hydrogen and optionally substituted phenyl; p is independently at each occurrence 0, 1 or 2; are described. Processes for making such compounds and their use as DPP-IV inhibitors in the treatment of diabetes are also described.

    Abstract translation: 式(I)化合物或其药学上可接受的盐,式(I)其中Ar是任选取代的苯基; R 1选自:式a)或b)(其中是单键或双键); R 5,R 6,R 7和R 8是用于或烷基的; R 4选自氢,(3-4C)环烷基和任选取代的(1-4C)烷基; R 1是例如选自氢,(1-4C)烷基,(3-6C)环烷基(1-4C)烷基,羟基(1-4C)烷基,(1-4C)烷氧基 ,芳基(1-4C)烷基; Y是碳,环A是任选取代的亚苯基; 或每个Y可以独立地为碳或氮,并且环A为任选取代的5或6元杂亚芳环; R 11选自氢和任选取代的苯基; p在每次出现时独立地为0,1或2; 被描述。 还描述了制备这些化合物的方法及其作为DPP-IV抑制剂在治疗糖尿病中的用途。

    Self-attaching nut
    43.
    发明申请
    Self-attaching nut 审中-公开
    自连接螺母

    公开(公告)号:US20070207006A1

    公开(公告)日:2007-09-06

    申请号:US11784829

    申请日:2007-04-10

    CPC classification number: F16B37/062

    Abstract: A self-attaching nut having a central pilot portion projecting from an end face of the body portion, an annular groove in the end face generally surrounding the pilot portion. The annular groove includes an inner side wall adjacent the pilot portion, a bottom wall and an outer side wall, wherein the bottom wall includes a first plurality of circumferentially spaced anti-rotation elements adjacent the inner side wall each having a planar inclined top face and a second plurality of circumferentially spaced anti-rotation elements adjacent the outer side wall each having a planar inclined top face and wherein the outer side wall of the annular groove includes a plurality of circumferentially spaced notches.

    Abstract translation: 具有从主体部分的端面突出的中心引导部分的自连接螺母,在端面中的大致围绕引导部分的环形槽。 所述环形槽包括与所述先导部分相邻的内侧壁,底壁和外侧壁,其中所述底壁包括邻近所述内侧壁的第一多个周向间隔开的防旋转元件,每一个具有平坦的倾斜顶面, 邻近所述外侧壁的第二多个周向间隔的防旋转元件,每个所述外旋转元件具有平坦的倾斜顶面,并且其中所述环形槽的外侧壁包括多个周向间隔开的凹口。

    Isolation of application-specific data within a user account
    46.
    发明申请
    Isolation of application-specific data within a user account 有权
    隔离用户帐户中的应用程序特定数据

    公开(公告)号:US20070033638A1

    公开(公告)日:2007-02-08

    申请号:US11274023

    申请日:2005-11-15

    CPC classification number: G06F21/6227 G06F2221/2147

    Abstract: A mechanism is provided for isolating application-specific data in an environment where multiple applications share a same user account. This mechanism enables data specific to an application to be accessed only by the application. When an application requests application-specific data, the data is loaded and a handle to the data is returned to the application. Access to the data is allowed only though the handle. Therefore, only the application possessing the handle can access the data. A counter may be associated with the loaded data. The counter's value is incremented whenever a handle is created for the data and decremented whenever a handle for the data is terminated. When the value of the counter reaches zero, the data is automatically unloaded.

    Abstract translation: 提供了一种机制,用于在多个应用程序共享相同用户帐户的环境中隔离应用程序特定数据。 该机制使得应用程序特有的数据只能由应用程序访问。 当应用程序请求特定于应用程序的数据时,将加载数据,并将数据的句柄返回给应用程序。 只有手柄才允许访问数据。 因此,只有具有句柄的应用程序才能访问数据。 计数器可能与加载的数据相关联。 每当为数据创建句柄时,计数器的值都会递增,每当数据句柄终止时,计数器的值递减。 当计数器的值达到零时,数据将自动卸载。

    Providing user on computer operating system with full privileges token and limited privileges token
    47.
    发明申请
    Providing user on computer operating system with full privileges token and limited privileges token 有权
    在计算机操作系统上为用户提供完全权限令牌和有限权限令牌

    公开(公告)号:US20070005961A1

    公开(公告)日:2007-01-04

    申请号:US11171744

    申请日:2005-06-30

    CPC classification number: G06F21/62 G06F2221/2145 G06F2221/2149

    Abstract: An operating system for a computing device has a first session for a user that includes a first base process that has a first privileges token attached thereto. The first privileges token includes substantially a full set of privileges of the user on the operating system. The operating system also has a second session for the user that includes a second base process that has a second privileges token attached thereto. The second privileges token is derived from the first privileges token and includes only a minimum set of privileges of the user on the operating system. Thus, the second, limited token does not have all privileges associated with the first, full token but instead has a limited set of privileges and not extra privileges that could be employed to take actions that would be harmful, deceptive, or malicious.

    Abstract translation: 用于计算设备的操作系统具有用于用户的第一会话,所述第一会话包括具有连接到其的第一权限令牌的第一基本进程。 第一权限令牌在操作系统上基本上包括用户的一整套特权。 操作系统还具有用户的第二会话,其包括具有附加到其的第二权限令牌的第二基本进程。 第二个权限令牌是从第一个权限令牌导出的,并且仅包含操作系统上用户的一组最小权限。 因此,第二个有限令牌不具有与第一个完整令牌相关联的所有权限,而是具有一组有限的权限,而不是可以用于采取有害,欺骗性或恶意行为的额外权限。

    Creating secure process objects
    48.
    发明申请
    Creating secure process objects 失效
    创建安全的进程对象

    公开(公告)号:US20060259487A1

    公开(公告)日:2006-11-16

    申请号:US11129872

    申请日:2005-05-16

    CPC classification number: G06F21/57 G06F21/51

    Abstract: A secure process may be created which does not allow code to be injected into it, does not allow modification of its memory or inspection of its memory. The resources protected in a secure process include all the internal state and threads running in the secure process. Once a secure process is created, the secure process is protected from access by non-secure processes. Process creation occurs atomically in kernel mode. Creating the infrastructure of a process in kernel mode enables security features to be applied that are difficult or impossible to apply in user mode. By moving setup actions previously occurring in user mode (such as creating the initial thread, allocating the stack, initialization of the parameter block, environment block and context record) into kernel mode, the need of the caller for full access rights to the created process is removed. Instead, enough state is passed from the caller to the kernel with the first system call so that the kernel is able to perform the actions previously performed using a number of calls back and forth between caller and kernel. When the kernel returns the handle to the set-up process, some of the access rights accompanying the handle are not returned. Specifically, those access rights that enable the caller to inject threads, read/write virtual memory, and interrogate or modify state of the threads of the process are not returned to the caller.

    Abstract translation: 可以创建不允许将代码注入其中的安全过程,不允许修改其存储器或检查其存储器。 在安全进程中保护的资源包括在安全进程中运行的所有内部状态和线程。 一旦创建了一个安全的进程,安全进程便受到非安全进程的访问保护。 进程创建在内核模式下以原子方式发生。 在内核模式下创建进程的基础架构可以应用在用户模式下难以应用的安全功能。 通过将先前发生在用户模式(如创建初始线程,分配堆栈,初始化参数块,环境块和上下文记录)的设置操作移动到内核模式,调用者需要对创建的进程进行完全访问权限 被删除。 相反,通过第一次系统调用,足够的状态从调用者传递到内核,以便内核能够使用调用者和内核之间的多个呼叫执行先前执行的操作。 当内核返回设置过程的句柄时,不会返回伴随句柄的一些访问权限。 具体来说,那些使呼叫者能够注入线程,读取/写入虚拟内存以及查询或修改进程的线程状态的访问权限不会返回给调用者。

    System and Method of Proxy Authentication in a Secured Network
    49.
    发明申请
    System and Method of Proxy Authentication in a Secured Network 有权
    安全网络中代理验证的系统和方法

    公开(公告)号:US20060225132A1

    公开(公告)日:2006-10-05

    申请号:US11424517

    申请日:2006-06-15

    CPC classification number: G06F21/33 Y10S707/99939

    Abstract: A method of controlling access to network services enables an authorized proxy client to access a service on behalf of a user. To permit the client to function as a proxy, the user registers proxy authorization information with a trusted security server. The proxy authorization information identifies the proxy client and specifies the extent of proxy authority granted to the proxy client. When the proxy client wants to access a target service on behalf of the user, it sends a proxy request to the trusted security server. The trusted security server checks the proxy authorization information of the user to verify whether the request is within the proxy authority granted to the proxy client. If so, the trusted security server returns to the proxy client a data structure containing information recognizable by the target service to authenticate the proxy client for accessing the target service on behalf of the user.

    Abstract translation: 控制对网络服务的访问的方法使得授权代理客户端能够代表用户访问服务。 为了允许客户端作为代理,用户使用可信赖的安全服务器注册代理授权信息。 代理授权信息标识代理客户端,并指定授予代理客户端的代理授权的范围。 当代理客户端想要代表用户访问目标服务时,它向可信安全服务器发送代理请求。 受信任的安全服务器检查用户的代理授权信息,以验证请求是否在授予代理客户端的代理授权内。 如果是这样,则可信赖安全服务器向代理客户端返回包含目标服务可识别的信息的数据结构,以便代表用户验证代理客户端来访问目标服务。

    SELECTABLE TAP INDUCTION COIL
    50.
    发明申请
    SELECTABLE TAP INDUCTION COIL 有权
    可选择TAP感应线圈

    公开(公告)号:US20060192561A1

    公开(公告)日:2006-08-31

    申请号:US11307673

    申请日:2006-02-16

    CPC classification number: G01V3/28

    Abstract: An electromagnetic logging tool includes a support configured for disposal in a well; at least one antenna mounted on the support; and a plurality of coils mounted on the support proximate the at least one antenna, wherein the plurality of the coils are configured for selective connection with the at least one antenna. A methods for balancing an induction array on an electromagnetic logging tool includes measuring a mutual coupling between a transmitter and a receiver on the electromagnetic logging tool; and selectively connecting a subset of a plurality of coils on the electromagnetic logging tool to the transmitter or the receiver based on the measured mutual coupling.

    Abstract translation: 电磁测井工具包括配置成在井中处置的支撑件; 安装在所述支撑件上的至少一个天线; 以及安装在靠近所述至少一个天线的所述支撑件上的多个线圈,其中所述多个线圈被配置为与所述至少一个天线的选择性连接。 用于平衡电磁测井工具上的感应阵列的方法包括测量电磁测井工具上的发射器和接收器之间的相互耦合; 以及基于所测量的互耦合,将电磁测井工具上的多个线圈的子集选择性地连接到发射器或接收器。

Patent Agency Ranking