SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS
    63.
    发明申请
    SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS 有权
    防止布鲁姆力量攻击的系统和方法

    公开(公告)号:US20080120504A1

    公开(公告)日:2008-05-22

    申请号:US11555030

    申请日:2006-10-31

    IPC分类号: H04L9/00

    摘要: In a system and method for authenticating a client device by an authentication device, the client device user is assigned a PIN generated by the authentication device. The user provides the PIN and a password to the client device, from which the client device generates a symmetric key and further generates a public/private key pair. The private key is encrypted using the symmetric key and stored in encrypted form only. The public key and a message authentication code generated from the PIN are provided to the authentication device, which stores the public key. Subsequently, when the user seeks to be authenticated, the user enters a password at the client device, which is used to generate a symmetric key to decrypt the encrypted private key. A message to the authentication device is signed using the resultant value. The authentication device uses the public key to verify the signature of the message.

    摘要翻译: 在用于通过认证设备认证客户端设备的系统和方法中,向客户端设备用户分配由认证设备产生的PIN。 用户向客户端设备提供PIN和密码,客户端设备从该设备生成对称密钥并进一步生成公钥/私钥对。 私钥使用对称密钥加密,仅以加密形式存储。 将公钥和从PIN生成的消息认证码提供给存储公钥的认证装置。 随后,当用户寻求认证时,用户在客户端设备处输入密码,用于生成对称密钥来解密加密的私钥。 使用结果值对认证设备的消息进行签名。 认证设备使用公钥验证消息的签名。

    System and method for protecting a password against brute force attacks
    65.
    发明授权
    System and method for protecting a password against brute force attacks 有权
    保护密码免受暴力攻击的系统和方法

    公开(公告)号:US08838975B2

    公开(公告)日:2014-09-16

    申请号:US11555030

    申请日:2006-10-31

    IPC分类号: H04L29/06

    摘要: In a system and method for authenticating a client device by an authentication device, the client device user is assigned a PIN generated by the authentication device. The user provides the PIN and a password to the client device, from which the client device generates a symmetric key and further generates a public/private key pair. The private key is encrypted using the symmetric key and stored in encrypted form only. The public key and a message authentication code generated from the PIN are provided to the authentication device, which stores the public key. Subsequently, when the user seeks to be authenticated, the user enters a password at the client device, which is used to generate a symmetric key to decrypt the encrypted private key. A message to the authentication device is signed using the resultant value. The authentication device uses the public key to verify the signature of the message.

    摘要翻译: 在用于通过认证设备认证客户端设备的系统和方法中,向客户端设备用户分配由认证设备产生的PIN。 用户向客户端设备提供PIN和密码,客户端设备从该设备生成对称密钥并进一步生成公钥/私钥对。 私钥使用对称密钥加密,仅以加密形式存储。 将公钥和从PIN生成的消息认证码提供给存储公钥的认证装置。 随后,当用户寻求认证时,用户在客户端设备处输入密码,用于生成对称密钥来解密加密的私钥。 使用结果值对认证设备的消息进行签名。 认证设备使用公钥验证消息的签名。

    System and Method of Owner Application Control of Electronic Devices
    67.
    发明申请
    System and Method of Owner Application Control of Electronic Devices 有权
    电子设备所有者应用控制系统与方法

    公开(公告)号:US20110010705A1

    公开(公告)日:2011-01-13

    申请号:US12885281

    申请日:2010-09-17

    IPC分类号: G06F9/445 H04L9/32

    摘要: Systems and methods of owner application control of an electronic device are provided. Owner application control information is stored on the electronic device and/or one or more remote servers. Owner application control information is consulted to determine if one or more required applications are available for execution on the electronic device. If not, one or more required applications not available are downloaded and installed. This could be in a manner transparent to the user of the electronic device. If one or more required applications are not available on the electronic device, the device can be functionally disabled in whole, or in part, until one or more required applications are available.

    摘要翻译: 提供了电子设备的所有者应用控制的系统和方法。 所有者应用控制信息存储在电子设备和/或一个或多个远程服务器上。 咨询所有者应用程序控制信息以确定一个或多个所需应用程序是否可用于在电子设备上执行。 如果没有,则下载并安装一个或多个不可用的必需应用程序。 这可以以对电子设备的用户透明的方式。 如果一个或多个所需的应用程序在电子设备上不可用,则该设备可以在全部或部分功能上禁用,直到一个或多个所需的应用程序可用。

    System and method for providing an indication of randomness quality of random number data generated by a random data service
    70.
    发明授权
    System and method for providing an indication of randomness quality of random number data generated by a random data service 有权
    用于提供由随机数据服务生成的随机数数据的随机性质量指示的系统和方法

    公开(公告)号:US08340289B2

    公开(公告)日:2012-12-25

    申请号:US11237723

    申请日:2005-09-29

    IPC分类号: H04L9/00

    摘要: A system and method for providing an indication of randomness quality of random number data generated by a random data service. The random data service may provide random number data to one or more applications adapted to generate key pairs used in code signing applications, for example. In one aspect, the method comprises the steps of: retrieving random number data from the random data service; applying one or more randomness tests to the retrieved random number data to compute at least one indicator of the randomness quality of the random number data; associating the at least one indicator with at least one state represented by a color; and displaying the color associated with the at least one indicator to a user. The color may be displayed in a traffic light icon, for example.

    摘要翻译: 一种用于提供由随机数据服务产生的随机数数据的随机性质量指示的系统和方法。 随机数据服务可以向例如适用于生成在代码签名应用中使用的密钥对的一个或多个应用提供随机数字数据。 一方面,该方法包括以下步骤:从随机数据服务中检索随机数字数据; 对所检索的随机数数据应用一个或多个随机性测试以计算所述随机数数据的随机性质量的至少一个指示符; 将所述至少一个指示符与由颜色表示的至少一个状态相关联; 以及将与所述至少一个指示符相关联的颜色显示给用户。 例如,颜色可以显示在交通灯图标中。