Auditing Application Activities
    51.
    发明申请
    Auditing Application Activities 有权
    审计申请活动

    公开(公告)号:US20080046886A1

    公开(公告)日:2008-02-21

    申请号:US11465820

    申请日:2006-08-21

    IPC分类号: G06F17/30 G06F15/173 G06F9/46

    CPC分类号: G06F21/577

    摘要: A compiled application may be audited by analyzing the compiled application to identify methods that may be called during execution of the compiled application. The identified methods may be correlated with controllable activities, i.e., those activities facilitated by public APIs. An audit report may be used to report to a user or administrator indications that the compiled application may attempt certain activities.

    摘要翻译: 可以通过分析编译的应用来识别编译的应用,以识别在编译的应用的执行期间可能被调用的方法。 所识别的方法可以与可控活动相关联,即由公共API促进的那些活动。 可以使用审计报告向用户或管理员报告编译的应用程序可能会尝试某些活动。

    SYSTEM AND METHOD FOR PROCESSING CERTIFICATES LOCATED IN A CERTIFICATE SEARCH
    53.
    发明申请
    SYSTEM AND METHOD FOR PROCESSING CERTIFICATES LOCATED IN A CERTIFICATE SEARCH 有权
    在证书搜索中处理证书的系统和方法

    公开(公告)号:US20130007446A1

    公开(公告)日:2013-01-03

    申请号:US13615046

    申请日:2012-09-13

    IPC分类号: G06F21/00

    摘要: A system and method for processing certificates located in a certificate search. Certificates located in a certificate search are processed at a data server (e.g. a mobile data server) coupled to a computing device (e.g. a mobile device) to determine status data that can be used to indicate the status of those certificates to a user of the computing device, without having to download those certificates to the computing device in their entirety. The data server is further adapted to transmit the status data to the computing device. In one embodiment, at least one status property of the certificates is verified at the data server in determining the status data. In another embodiment, additional certificate data is determined and transmitted to the computing device, which can be used by the computing device to verify, at the computing device, at least one other status property of the certificates.

    摘要翻译: 用于处理位于证书搜索中的证书的系统和方法。 位于证书搜索中的证书在耦合到计算设备(例如,移动设备)的数据服务器(例如移动数据服务器)处理,以确定可用于向用户指示这些证书的状态的状态数据 计算设备,而无需将这些证书全部下载到计算设备。 数据服务器还适于将状态数据发送到计算设备。 在一个实施例中,在确定状态数据时,在数据服务器处验证证书的至少一个状态属性。 在另一个实施例中,确定附加证书数据并将其发送到计算设备,计算设备可以由计算设备在计算设备处验证证书的至少一个其他状态属性。

    System and method for securing data
    54.
    发明授权
    System and method for securing data 有权
    用于保护数据的系统和方法

    公开(公告)号:US08130957B2

    公开(公告)日:2012-03-06

    申请号:US10984331

    申请日:2004-11-09

    IPC分类号: H04K1/00

    摘要: In accordance with the teachings described herein, systems and methods are provided for securing data for transmission to a wireless device. The disclosed systems and methods may include an electronic messaging system used to send and receive data over a first network and also used to forward data to a wireless device operable in a second network. The electronic messaging system may receive an electronic message encrypted with a first encryption algorithm and addressed to a message recipient in the first network, the message recipient having an associated wireless device operable in the second network. The electronic messaging system may determine that the electronic message is to be transported across the second network to the wireless device, and in response to determining that the electronic message is to be transported across the second network, encrypt the electronic message using a second encryption algorithm and transmit the encrypted message over the second network to the wireless device, with the second encryption algorithm being a stronger encryption algorithm than the first encryption algorithm.

    摘要翻译: 根据本文所描述的教导,提供了用于保护用于传输到无线设备的数据的系统和方法。 所公开的系统和方法可以包括用于通过第一网络发送和接收数据的电子消息系统,并且还用于将数据转发到在第二网络中可操作的无线设备。 电子消息传送系统可以接收利用第一加密算法加密并且寻址到第一网络中的消息接收者的电子消息,消息接收者具有可在第二网络中操作的相关联的无线设备。 电子消息系统可以确定电子消息将通过第二网络传输到无线设备,并且响应于确定电子消息要跨越第二网络传输,使用第二加密算法对电子消息进行加密 并且通过第二网络将加密的消息发送到无线设备,其中第二加密算法是比第一加密算法更强的加密算法。

    APPARATUS AND METHOD FOR INTEGRATING AUTHENTICATION PROTOCOLS IN THE ESTABLISHMENT OF CONNECTIONS BETWEEN COMPUTING DEVICES
    55.
    发明申请
    APPARATUS AND METHOD FOR INTEGRATING AUTHENTICATION PROTOCOLS IN THE ESTABLISHMENT OF CONNECTIONS BETWEEN COMPUTING DEVICES 有权
    在建立计算机设备之间的连接时集成认证协议的装置和方法

    公开(公告)号:US20110167484A1

    公开(公告)日:2011-07-07

    申请号:US13046861

    申请日:2011-03-14

    IPC分类号: G06F21/20

    CPC分类号: H04L63/0815 G06F21/41

    摘要: An apparatus and method for integrating authentication protocols in the establishment of connections between a controlled-access first computing device and at least one second computing device. In one embodiment, network access user authentication data needed to access the at least one second computing device is transmitted to an authentication server automatically if the user has access to use the first computing device, thereby not requiring the user to manually enter the authentication data needed for such access at the first computing device. The network access user authentication data may be, for example, retrieved from a memory store of the first computing device and/or generated in accordance with an authentication data generating algorithm.

    摘要翻译: 一种用于将认证协议集成在控制访问第一计算设备与至少一个第二计算设备之间的连接建立中的装置和方法。 在一个实施例中,如果用户可以访问使用第一计算设备,则自动地将访问至少一个第二计算设备所需的网络访问用户认证数据传送到认证服务器,从而不要求用户手动输入所需的认证数据 用于在第一计算设备处的这种访问。 网络访问用户认证数据可以例如从第一计算设备的存储器存储器中检索和/或根据认证数据生成算法生成。

    Wireless communication device with duress password protection and related method
    56.
    发明授权
    Wireless communication device with duress password protection and related method 有权
    无线通信设备具有胁迫密码保护及相关方法

    公开(公告)号:US07948938B2

    公开(公告)日:2011-05-24

    申请号:US10835260

    申请日:2004-04-30

    IPC分类号: H04Q7/00

    摘要: A wireless communication device (and its related method of operation) includes, if invoked, password protected access to data stored therewithin and/or to normal device operations and further includes duress password checking logic that automatically causes a duress message to be sent if a duress password has been entered. The duress message is preferably sent without maintaining any user accessible indication of such sending. It is also preferred that the password checking logic automatically cause an end-of-duress message to be sent if a normal password is entered after a duress password has been entered. A plurality of different duress passwords may be entered into a duress password portion of data memory in the device.

    摘要翻译: 无线通信设备(及其相关操作方法)如果被调用,则包含密码保护对其中存储的数据和/或正常设备操作的访问,并且还包括胁迫密码检查逻辑,如果胁迫则自动导致胁迫消息被发送 密码已输入。 优先发送胁迫消息,而不保持这种发送的任何用户可访问的指示。 如果在输入胁迫密码之后输入正常密码,则密码检查逻辑也优选地自动导致发送结束消息。 可以将多个不同的胁迫密码输入到设备中的数据存储器的胁迫密码部分。

    System and method for application authorization
    57.
    发明授权
    System and method for application authorization 有权
    系统和应用程序授权方法

    公开(公告)号:US07805755B2

    公开(公告)日:2010-09-28

    申请号:US10996406

    申请日:2004-11-26

    摘要: A method and system for authorization of applications executing on a device having a key store. Applications obtain an application-level ticket to permit access to one or more key values located in the key store. Each ticket is securely associated with an application and being generated on the determination that the application is a trusted application. Tickets are potentially associated with one key value in the key store, with a subset of key values in the key store, or with all key values in the key store. Access to key values by an application is possible independently of a user providing a password for each such access.

    摘要翻译: 一种用于在具有密钥存储的设备上执行的应用的授权的方法和系统。 应用程序获得一个应用程序级票证,以允许访问位于密钥存储区中的一个或多个密钥值。 每个票据与应用程序安全地相关联,并且在确定应用程序是可信应用程序时生成。 门票可能与密钥库中的一个密钥值相关联,密钥存储中的密钥值的子集或密钥存储中的所有密钥值。 可以独立于为每个这样的访问提供密码的用户访问应用的密钥值。

    SYSTEM AND METHOD FOR RETRIEVING RELATED CERTIFICATES
    58.
    发明申请
    SYSTEM AND METHOD FOR RETRIEVING RELATED CERTIFICATES 有权
    检索相关证书的系统和方法

    公开(公告)号:US20100082976A1

    公开(公告)日:2010-04-01

    申请号:US12632217

    申请日:2009-12-07

    摘要: A system and method for searching and retrieving certificates, which may be used in the processing of encoded messages. In one embodiment, a certificate synchronization application is programmed to perform certificate searches by querying one or more certificate servers for all certificate authority (CA) certificates and cross-certificates on the certificate servers. In another embodiment, all certificates related to an identified certificate are retrieved from the certificate servers automatically by the certificate synchronization application, where the related certificates comprise at least one of one or more CA certificates and one or more cross-certificates. Embodiments of the invention facilitate at least partial automation of the downloading and establishment of certificate chains, thereby minimizing the need for users to manually search for individual certificates.

    摘要翻译: 用于搜索和检索证书的系统和方法,其可以用于编码消息的处理。 在一个实施例中,证书同步应用程序被编程为通过在一个或多个证书服务器上查询证书服务器上的所有证书颁发机构(CA)证书和交叉证书来执行证书搜索。 在另一个实施例中,证书同步应用程序自动从证书服务器检索与所识别的证书相关的所有证书,其中相关证书包括一个或多个CA证书和一个或多个交叉证书中的至少一个。 本发明的实施例促进了证书链的下载和建立的至少部分自动化,从而最小化对用户手动搜索单个证书的需要。

    Method, system and device for authenticating a user
    59.
    发明授权
    Method, system and device for authenticating a user 有权
    用于认证用户的方法,系统和设备

    公开(公告)号:US07562218B2

    公开(公告)日:2009-07-14

    申请号:US10919320

    申请日:2004-08-17

    IPC分类号: H04L9/00

    CPC分类号: G06F21/35 G06F21/34

    摘要: Preferred embodiments of the invention relate to a method and device for authenticating a user of a computer and a corresponding system using the method and device. The device is a handheld electronic device having accessible thereto a first authentication code of the user. The handheld electronic device requires a second authentication code for enabling use thereof. In order to authenticate the user to the computer, the handheld electronic device is configured to transmit the first authentication code to the computer over a communication link between the computer and the handheld electronic device.

    摘要翻译: 本发明的优选实施例涉及一种用于认证计算机的用户和使用该方法和装置的对应系统的方法和装置。 该设备是可访问用户的第一认证码的手持式电子设备。 手持电子设备需要第二认证码以使其能够使用。 为了将用户认证给计算机,手持电子设备被配置为通过计算机和手持电子设备之间的通信链路将第一认证码发送到计算机。