Challenge response-based device authentication system and method
    53.
    发明授权
    Challenge response-based device authentication system and method 有权
    基于挑战响应的设备认证系统和方法

    公开(公告)号:US07603556B2

    公开(公告)日:2009-10-13

    申请号:US10996369

    申请日:2004-11-26

    IPC分类号: H04L9/32

    摘要: A challenge response scheme authenticates a requesting device by an authenticating device. The authenticating device generates and issues a challenge to the requesting device. The requesting device combines the challenge with a hash of a password provided by a user, and the combination is further hashed in order to generate a requesting encryption key used to encrypt the user supplied password. The encrypted user supplied password is sent to the authenticating device as a response to the issued challenge. The authenticating device generates an authenticating encryption key by generating the hash of a combination of the challenge and a stored hash of an authenticating device password. The authenticating encryption key is used to decrypt the response in order to retrieve the user-supplied password. If the user-supplied password hash matches the stored authenticating device password hash, the requesting device is authenticated and the authenticating device is in possession of the password.

    摘要翻译: 挑战响应方案通过认证设备认证请求设备。 认证设备生成并向请求设备发出质询。 请求设备将挑战与由用户提供的密码的散列相结合,并且组合进一步进行散列,以便生成用于加密用户提供的密码的请求加密密钥。 加密的用户提供的密码作为对发布的挑战的响应被发送到认证设备。 认证设备通过生成质询的组合和存储的认证设备密码的哈希的散列来生成认证加密密钥。 认证加密密钥用于解密响应,以便检索用户提供的密码。 如果用户提供的密码哈希与存储的认证设备密码散列匹配,则请求设备被认证,认证设备拥有密码。

    METHOD AND APPARATUS FOR PROVIDING INTELLIGENT ERROR MESSAGING
    54.
    发明申请
    METHOD AND APPARATUS FOR PROVIDING INTELLIGENT ERROR MESSAGING 有权
    用于提供智能错误消息的方法和装置

    公开(公告)号:US20090187796A1

    公开(公告)日:2009-07-23

    申请号:US12407834

    申请日:2009-03-20

    IPC分类号: G06F11/07 H04L9/32 G06F15/16

    摘要: A method and apparatus for providing intelligent error messaging is disclosed wherein a user of a mobile communications device is provided with descriptive error messaging information to assist the user in overcoming errors associated with the processing of electronic messages and data. For example, when the mobile device is being used to decrypt a cryptographically secured electronic message, and a problem is encountered, program logic of the device provides the user with (1) an indication of exactly what problem is preventing opening of the message, for example, a required cryptographic key is not available; (2) an indication of exactly what may be done to overcome the problem, for example, what utilities should be run on the device; and (3) exactly what data, if any, needs to be downloaded to the device, for example, what cryptographic keys should be downloaded.

    摘要翻译: 公开了一种用于提供智能错误消息的方法和装置,其中向移动通信设备的用户提供描述性错误消息信息,以帮助用户克服与电子消息和数据的处理相关的错误。 例如,当移动设备被用于解密密码保护的电子消息并且遇到问题时,该设备的程序逻辑向用户提供(1)正确地指示什么问题阻止该消息打开的指示,用于 例如,所需的加密密钥不可用; (2)可以确切地说明什么可以做以克服这个问题,例如什么实用程序应该在设备上运行; 和(3)需要什么数据(如果有的话)需要下载到设备,例如什么加密密钥应该被下载。

    Challenge response-based device authentication system and method
    56.
    发明授权
    Challenge response-based device authentication system and method 有权
    基于挑战响应的设备认证系统和方法

    公开(公告)号:US08074072B2

    公开(公告)日:2011-12-06

    申请号:US12428170

    申请日:2009-04-22

    IPC分类号: H04L9/32

    摘要: A challenge response scheme authenticates a requesting device by an authenticating device. The authenticating device generates and issues a challenge to the requesting device. The requesting device combines the challenge with a hash of a password provided by a user, and the combination is further hashed in order to generate a requesting encryption key used to encrypt the user supplied password. The encrypted user supplied password is sent to the authenticating device as a response to the issued challenge. The authenticating device generates an authenticating encryption key by generating the hash of a combination of the challenge and a stored hash of an authenticating device password. The authenticating encryption key is used to decrypt the response in order to retrieve the user-supplied password. If the user-supplied password hash matches the stored authenticating device password hash, the requesting device is authenticated and the authenticating device is in possession of the password.

    摘要翻译: 挑战响应方案通过认证设备认证请求设备。 认证设备生成并向请求设备发出质询。 请求设备将挑战与由用户提供的密码的散列相结合,并且组合进一步进行散列,以便生成用于加密用户提供的密码的请求加密密钥。 加密的用户提供的密码作为对发布的挑战的响应被发送到认证设备。 认证设备通过生成质询的组合和存储的认证设备密码的哈希的散列来生成认证加密密钥。 认证加密密钥用于解密响应,以便检索用户提供的密码。 如果用户提供的密码哈希与存储的认证设备密码散列匹配,则请求设备被认证,认证设备拥有密码。

    CERTIFICATE INFORMATION STORAGE SYSTEM AND METHOD
    58.
    发明申请
    CERTIFICATE INFORMATION STORAGE SYSTEM AND METHOD 有权
    证书信息存储系统和方法

    公开(公告)号:US20110271115A1

    公开(公告)日:2011-11-03

    申请号:US13043859

    申请日:2011-03-09

    IPC分类号: H04L9/32 H04L9/08 H04L9/00

    CPC分类号: H04L63/0823 G06F21/606

    摘要: A system and method of storing in a computer device digital certificate data from a digital certificate are provided. When a digital certificate is received at the computer device, it is determined whether the digital certificate data in the digital certificate is stored in a first memory store in the computer device. The digital certificate data is stored in the first memory store upon determining that the digital certificate data is not stored in the first memory store.

    摘要翻译: 提供了一种在计算机设备中存储来自数字证书的数字证书数据的系统和方法。 当在计算机设备处接收到数字证书时,确定数字证书中的数字证书数据是否存储在计算机设备中的第一存储器存储器中。 在确定数字证书数据未被存储在第一存储器存储器中时,数字证书数据被存储在第一存储器存储器中。

    System and method of owner application control of electronic devices
    59.
    发明授权
    System and method of owner application control of electronic devices 有权
    电子设备所有者应用控制的系统和方法

    公开(公告)号:US07815100B2

    公开(公告)日:2010-10-19

    申请号:US11118844

    申请日:2005-04-29

    IPC分类号: G06F9/45

    摘要: Systems and methods of owner application control of an electronic device are provided. Owner application control information is stored on the electronic device and/or one or more remote servers. Owner application control information is consulted to determine if one or more required applications are available for execution on the electronic device. If not, one or more required applications not available are downloaded and installed. This could be in a manner transparent to the user of the electronic device. If one or more required applications are not available on the electronic device, the device can be functionally disabled in whole, or in part, until one or more required applications are available.

    摘要翻译: 提供了电子设备的所有者应用控制的系统和方法。 所有者应用控制信息存储在电子设备和/或一个或多个远程服务器上。 咨询所有者应用程序控制信息以确定一个或多个所需应用程序是否可用于在电子设备上执行。 如果没有,则下载并安装一个或多个不可用的必需应用程序。 这可以以对电子设备的用户透明的方式。 如果一个或多个所需的应用程序在电子设备上不可用,则该设备可以在全部或部分功能上禁用,直到一个或多个所需的应用程序可用。

    System and method for registering entities for code signing services
    60.
    发明授权
    System and method for registering entities for code signing services 有权
    用于注册代码签名服务实体的系统和方法

    公开(公告)号:US07797545B2

    公开(公告)日:2010-09-14

    申请号:US11237727

    申请日:2005-09-29

    IPC分类号: H04L9/00

    摘要: A system and method for registering entities for code signing services. The entities may be software application developers or other individuals or entities that wish to have applications digitally signed. Signing of the applications may be required in order to enable the applications to access sensitive APIs and associated resources of a computing device when the applications are executed on the computing device. In one embodiment, a method of registering entities for code signing services will comprise the step of transmitting at least some account data to the registering individual or entity using an out-of-band communication system. This provides added security that the individual or entity registering for a code signing service is who that individual or entity purports to be.

    摘要翻译: 一种用于注册代码签名服务实体的系统和方法。 实体可以是软件应用程序开发人员或希望对应用进行数字签名的其他个人或实体。 可能需要签署应用程序,以便在应用程序在计算设备上执行时,使应用程序能够访问计算设备的敏感API和相关资源。 在一个实施例中,注册用于代码签名服务的实体的方法将包括使用带外通信系统将至少一些帐户数据发送到注册个人或实体的步骤。 这提供了增加的安全性,注册代码签名服务的个人或实体是个人或实体所声称的。