VALIDATION AND/OR AUTHENTICATION OF A DEVICE FOR COMMUNICATION WITH NETWORK
    52.
    发明申请
    VALIDATION AND/OR AUTHENTICATION OF A DEVICE FOR COMMUNICATION WITH NETWORK 有权
    用于与网络通信的设备的验证和/或认证

    公开(公告)号:US20140129815A9

    公开(公告)日:2014-05-08

    申请号:US12760690

    申请日:2010-04-15

    IPC分类号: G06F21/02 G06F9/445

    CPC分类号: H04W12/10 H04L63/123

    摘要: A device may include a trusted component. The trusted component may be verified by a trusted third party and may have a certificate of verification stored therein based on the verification by the trusted third party. The trusted component may include a root of trust that may provide secure code and data storage and secure application execution. The root of trust may also be configured to verify an integrity of the trusted component via a secure boot and to prevent access to the certain information in the device if the integrity of the trusted component may not be verified.

    摘要翻译: 设备可以包括可信组件。 受信任的组件可以由受信任的第三方验证,并且可以基于可信赖的第三方的验证来存储其中的验证证书。 受信任的组件可以包括可以提供安全代码和数据存储以及安全应用执行的信任根。 还可以配置信任根以通过安全引导来验证可信组件的完整性,并且如果可信组件的完整性可能未被验证,则阻止访问设备中的某些信息。

    Secure session key generation
    53.
    发明授权
    Secure session key generation 有权
    安全会话密钥生成

    公开(公告)号:US08510559B2

    公开(公告)日:2013-08-13

    申请号:US12419798

    申请日:2009-04-07

    IPC分类号: H04L9/00

    摘要: A method and apparatus for securing the interface between a Universal Integrated Circuit Card (UICC) and a Terminal in wireless communications is disclosed. The security of Authentication and Key Agreement (AKA) and application level generic bootstrapping architecture (GBA) with UICC-based enhancements (GBA_U) procedures is improved. A secure shared session key is used to encrypt communications between the UICC and the Terminal. The secure shared session key generated using authenticating or non-authenticating procedures.

    摘要翻译: 公开了一种在无线通信中用于固定通用集成电路卡(UICC)和终端之间的接口的方法和装置。 基于UICC的增强(GBA_U)程序的身份验证和密钥协商(AKA)和应用级通用引导体系结构(GBA)的安全性得到了改进。 安全的共享会话密钥用于加密UICC和终端之间的通信。 使用验证或非验证过程产生的安全共享会话密钥。

    Trust evaluation for a mobile software agent on a trusted computing platform
    55.
    发明授权
    Trust evaluation for a mobile software agent on a trusted computing platform 有权
    对可信计算平台上的移动软件代理进行信任评估

    公开(公告)号:US08015408B2

    公开(公告)日:2011-09-06

    申请号:US11733536

    申请日:2007-04-10

    IPC分类号: H04L9/32

    CPC分类号: H04W12/10 H04L63/12 H04W12/12

    摘要: A method and system for performing trust evaluation for a mobile software agent on a trusted computing platform are disclosed. A sending entity, which includes a mobile software agent, verifies if a receiving entity is trustworthy before transferring the mobile software agent to the receiving entity. The receiving entity may verify the state and details of the mobile software agent and/or the state of the sending entity, and receive the mobile software agent if the state of the mobile software agent and the sending entity are trustworthy. The mobile software agent may include its own virtual trusted platform module (TPM) which is tied to an agent's identity. The agent's virtual TPM is part of the agent and transferred along with the mobile code when the mobile code is transferred.

    摘要翻译: 公开了一种用于对可信计算平台上的移动软件代理执行信任评估的方法和系统。 包括移动软件代理的发送实体在将移动软件代理传送到接收实体之前验证接收实体是否可信任。 接收实体可以验证移动软件代理的状态和细节和/或发送实体的状态,并且如果移动软件代理和发送实体的状态是可信赖的,则接收移动软件代理。 移动软件代理可以包括其自己的虚拟可信平台模块(TPM),其与代理的身份相关联。 代理商的虚拟TPM是代理商的一部分,并在移动代码被传输时与移动代码一起传输。

    METHOD AND APPARATUS FOR SECURE TRUSTED TIME TECHNIQUES
    56.
    发明申请
    METHOD AND APPARATUS FOR SECURE TRUSTED TIME TECHNIQUES 有权
    用于安全实时技术的方法和装置

    公开(公告)号:US20100011214A1

    公开(公告)日:2010-01-14

    申请号:US12389088

    申请日:2009-02-19

    IPC分类号: H04L9/00

    摘要: A method and apparatus to establish a trustworthy local time based on trusted computing methods are described. The concepts are scaling because they may be graded by the frequency and accuracy with which a reliable external time source is available for correction and/or reset, and how trustworthy this external source is in a commercial scenario. The techniques also take into account that the number of different paths and number of hops between the device and the trusted external time source may vary. A local clock related value which is protected by a TPM securely bound to an external clock. A system of Accuracy Statements (AS) is added to introduce time references to the audit data provided by other maybe cheaper sources than the time source providing the initial time.

    摘要翻译: 描述了基于可信计算方法建立可靠的本地时间的方法和装置。 概念是缩放,因为它们可以通过可靠的外部时间源可用于校正和/或重置的频率和准确度进行分级,并且在商业场景中该外部源是如何可信赖的。 这些技术还考虑到设备与受信任的外部时间源之间的不同路径和跳数的数量可能会有所不同。 由TPM保护的本地时钟相关值安全地绑定到外部时钟。 添加准确性声明(AS)的系统来引入时间参考,以提供其他可能比提供初始时间的时间源更便宜的源提供的审计数据。

    SECURE SESSION KEY GENERATION
    57.
    发明申请
    SECURE SESSION KEY GENERATION 有权
    安全会话密钥生成

    公开(公告)号:US20090313472A1

    公开(公告)日:2009-12-17

    申请号:US12419798

    申请日:2009-04-07

    IPC分类号: H04L9/00 H04L29/06

    摘要: A method and apparatus for securing the interface between a Universal Integrated Circuit Card (UICC) and a Terminal in wireless communications is disclosed. The security of Authentication and Key Agreement (AKA) and application level generic bootstrapping architecture (GBA) with UICC-based enhancements (GBA_U) procedures is improved. A secure shared session key is used to encrypt communications between the UICC and the Terminal. The secure shared session key generated using authenticating or non-authenticating procedures.

    摘要翻译: 公开了一种在无线通信中用于固定通用集成电路卡(UICC)和终端之间的接口的方法和装置。 基于UICC的增强(GBA_U)程序的身份验证和密钥协商(AKA)和应用级通用引导体系结构(GBA)的安全性得到了改进。 安全的共享会话密钥用于加密UICC和终端之间的通信。 使用验证或非验证过程产生的安全共享会话密钥。

    APPARATUS AND METHOD FOR PERFORMING TRUSTED COMPUTING INTEGRITY MEASUREMENT REPORTING
    58.
    发明申请
    APPARATUS AND METHOD FOR PERFORMING TRUSTED COMPUTING INTEGRITY MEASUREMENT REPORTING 有权
    用于执行有意义的计算机一体化测量报告的装置和方法

    公开(公告)号:US20090307487A1

    公开(公告)日:2009-12-10

    申请号:US12297966

    申请日:2007-04-23

    IPC分类号: H04L9/00

    CPC分类号: G06F21/57

    摘要: The present application discloses a method and apparatus for using trusted platform modules (TPM) for integrity measurements of multiple subsystems. The state of the platform configuration registers (PCR) after boot up are stored as the base state of the system. Base state in this context is defined as the state of the system when the startup of the system is complete and can only be changed when new software is loaded at the kernel level. This state itself can be reported to challengers who are interested in verifying the integrity of the operating system. Also disclosed is a method where the application that is to be verified, requests that its state be extended from the base state of the system. When such a request is received, the state of the system is extended directly from the base state PCR contents and not from the system state.

    摘要翻译: 本申请公开了一种使用可信平台模块(TPM)进行多个子系统的完整性测量的方法和装置。 启动后的平台配置寄存器(PCR)的状态作为系统的基本状态存储。 在此上下文中的基本状态被定义为系统启动完成时系统的状态,只有在内核级别加载新软件时才能更改该状态。 该状态本身可以向有兴趣验证操作系统完整性的挑战者报告。 还公开了一种方法,其中待验证的应用程序请求其状态从系统的基本状态扩展。 当接收到这样的请求时,系统的状态直接从基本状态PCR内容扩展,而不是从系统状态扩展。

    Access point operating with a smart antenna in a WLAN and associated methods
    59.
    发明授权
    Access point operating with a smart antenna in a WLAN and associated methods 失效
    WLAN中的智能天线接入点和相关方法

    公开(公告)号:US07366464B2

    公开(公告)日:2008-04-29

    申请号:US11144113

    申请日:2005-06-03

    IPC分类号: H04B7/14

    摘要: An access point operates in an 802.11 wireless communication network communicating with a client station, and includes a smart antenna for generating directional antenna beams and an omni-directional antenna beam. An antenna steering algorithm scans the directional antenna beams and the omni-directional antenna beam for receiving signals from the client station. The signals received via each scanned antenna beam are measured, and one of the antenna beams is selected based upon the measuring for communicating with the client station. The selected antenna beam is preferably a directional antenna beam. Once the directional antenna beam has been selected, there are several usage rules for exchanging data with the client station. The usage rules are directed to an active state of the access point, which includes a data transmission mode and a data reception mode.

    摘要翻译: 接入点在与客户站通信的802.11无线通信网络中操作,并且包括用于生成定向天线波束的智能天线和全向天线波束。 天线导向算法扫描定向天线波束和全向天线波束,用于从客户端接收信号。 测量经由每个扫描天线波束接收到的信号,并且基于与客户站进行通信的测量来选择天线波束之一。 所选择的天线波束优选地是定向天线波束。 一旦选择了定向天线波束,就有几种与客户端交换数据的使用规则。 使用规则被引导到接入点的活动状态,其包括数据传输模式和数据接收模式。

    METHOD AND SYSTEM FOR ENHANCING CRYPTOGRAPHIC CAPABILITIES OF A WIRELESS DEVICE USING BROADCASTED RANDOM NOISE
    60.
    发明申请
    METHOD AND SYSTEM FOR ENHANCING CRYPTOGRAPHIC CAPABILITIES OF A WIRELESS DEVICE USING BROADCASTED RANDOM NOISE 有权
    使用广播随机噪声增强无线设备的可视化能力的方法和系统

    公开(公告)号:US20080089518A1

    公开(公告)日:2008-04-17

    申请号:US11871683

    申请日:2007-10-12

    IPC分类号: H04L9/20

    摘要: A secret stream of bits begins by receiving a public random stream contained in a wireless communication signal at a transmit/receive unit. The public random stream is sampled and specific bits are extracted according to a shared common secret. These extracted bits are used to create a longer secret stream. The shared common secret may be generated using JRNSO techniques, or provided to the transmit/receive units prior to the communication session. Alternatively, one of the transmit/receive unit is assumed to be more powerful than any potential eavesdropper. In this situation, the powerful transmit/receive unit may broadcast and store a public random stream. The weaker transmit/receive unit selects select random bits of the broadcast for creating a key. The weaker transmit/receive unit sends the powerful transmit/receive unit the selected bit numbers, and powerful transmit/receive unit uses the random numbers to produce the key created by the weaker transmit/receive unit.

    摘要翻译: 秘密的比特流开始于在发送/接收单元处接收包含在无线通信信号中的公共随机流。 公共随机流被采样,并且根据共享的公共秘密提取特定位。 这些提取的比特用于创建更长的秘密流。 可以使用JRNSO技术生成共享公用秘密,或者在通信会话之前提供给发送/接收单元。 或者,假设发射/接收单元之一比任何潜在的窃听者更强大。 在这种情况下,强大的发送/接收单元可以广播和存储公共随机流。 较弱的发送/接收单元选择用于创建密钥的广播的选择随机比特。 较弱的发射/接收单元发送强大的发射/接收单元所选择的位号,强大的发射/接收单元使用随机数产生由较弱发射/接收单元产生的密钥。