System and method for encrypted smart card pin entry
    61.
    发明申请
    System and method for encrypted smart card pin entry 有权
    用于加密智能卡引脚输入的系统和方法

    公开(公告)号:US20070028118A1

    公开(公告)日:2007-02-01

    申请号:US11196340

    申请日:2005-08-04

    IPC分类号: H04L9/00 H04K1/00

    摘要: A smart card, system, and method for securely authorizing a user or user device using the smart card is provided. The smart card is configured to provide, upon initialization or a request for authentication, a public key to the user input device such that the PIN or password entered by the user is encrypted before transmission to the smart card via a smart card reader. The smart card then decrypts the PIN or password to authorize the user. Preferably, the smart card is configured to provide both a public key and a nonce to the user input device, which then encrypts a concatenation or other combination of the nonce and the user-input PIN or password before transmission to the smart card. The smart card reader thus never receives a copy of the PIN or password in the clear, allowing the smart card to be used with untrusted smart card readers.

    摘要翻译: 提供了一种使用智能卡安全授权用户或用户设备的智能卡,系统和方法。 智能卡被配置为在初始化或请求验证时向用户输入设备提供公共密钥,使得在经由智能卡读卡器传输到智能卡之前,由用户输入的PIN或密码被加密。 智能卡然后解密PIN或密码以授权用户。 优选地,智能卡被配置为向用户输入设备提供公开密钥和随机数,该用户输入设备然后在发送到智能卡之前加密随机数和用户输入的PIN或密码的级联或其他组合。 因此,智能卡读卡器从未收到PIN或密码的副本,允许智能卡与不可信的智能卡读卡器一起使用。

    System and method for retrieving certificates associated with senders of digitally signed messages
    62.
    发明申请
    System and method for retrieving certificates associated with senders of digitally signed messages 有权
    用于检索与数字签名消息的发送者相关联的证书的系统和方法

    公开(公告)号:US20060112419A1

    公开(公告)日:2006-05-25

    申请号:US10975987

    申请日:2004-10-29

    IPC分类号: H04L9/32

    摘要: A system and method for retrieving certificates and/or verifying the revocation status of certificates. In one embodiment, when a user opens a digitally signed message, a certificate that is required to verify the digital signature on the message may be automatically retrieved if it is not stored on the user's computing device (e.g. a mobile device), eliminating the need for users to initiate the task manually. Verification of the digital signature may also be automatically performed by the application after the certificate is retrieved. Verification of the revocation status of a certificate may also be automatically performed if it is determined that the time that has elapsed since the status was last updated exceeds a pre-specified limit.

    摘要翻译: 用于检索证书和/或验证证书的撤销状态的系统和方法。 在一个实施例中,当用户打开数字签名的消息时,如果消息中没有存储在用户的计算设备(例如,移动设备)上,则可以自动检索需要验证消息上的数字签名的证书,从而消除了需要 为用户手动启动任务。 检索证书后,应用程序也可以自动执行数字签名的验证。 如果确定自上次更新状态以来已经过去的时间超过预定限制,则也可以自动执行证书的撤销状态的验证。

    System and method for enabling bulk retrieval of certificates
    65.
    发明申请
    System and method for enabling bulk retrieval of certificates 有权
    允许批量检索证书的系统和方法

    公开(公告)号:US20060036848A1

    公开(公告)日:2006-02-16

    申请号:US10913693

    申请日:2004-08-09

    IPC分类号: H04L9/00

    摘要: A system and method for searching and retrieving certificates, which may be used in the processing of encoded messages. In one embodiment, a certificate synchronization application is programmed to perform certificate searches by querying one or more certificate servers for all of the certificates on those certificate servers. If all of the certificates on a certificate server cannot be successfully retrieved using a single search query, due to a search quota on the certificate server being exceeded for example, the search is re-performed through multiple queries, each corresponding to a narrower subsearch. The invention enables users to large amounts of certificates to be automatically searched for and retrieved from certificate servers, thereby minimizing the need for users to manually search for individual certificates.

    摘要翻译: 用于搜索和检索证书的系统和方法,其可以用于编码消息的处理。 在一个实施例中,证书同步应用程序被编程为通过向一个或多个证书服务器查询那些证书服务器上的所有证书来执行证书搜索。 如果证书服务器上的所有证书都无法使用单个搜索查询成功检索,因为例如超过了证书服务器上的搜索配额,则通过多个查询重新执行搜索,每个查询对应于较窄的子搜索。 本发明使用户能够从证书服务器自动搜索和检索大量的证书,从而最小化用户手动搜索单个证书的需要。

    System and method for handling message receipt notification
    67.
    发明申请
    System and method for handling message receipt notification 有权
    处理消息收据通知的系统和方法

    公开(公告)号:US20050282525A1

    公开(公告)日:2005-12-22

    申请号:US11158104

    申请日:2005-06-21

    CPC分类号: H04W4/12 H04L51/30 H04L51/38

    摘要: Systems and methods for operation upon a wireless mobile device to handle message notifications. A method can include receiving a message by the wireless mobile device over a wireless communications network. The received message is processed so that at least a portion of the sender's message is displayed to a user of the wireless mobile device before a signed receipt is provided to the sender.

    摘要翻译: 在无线移动设备上操作消息通知的系统和方法。 一种方法可以包括通过无线通信网络由无线移动设备接收消息。 处理所接收的消息,使得在将签名的收据提供给发送者之前,发送者的消息的至少一部分被显示给无线移动设备的用户。

    System and method for application authorization
    68.
    发明申请
    System and method for application authorization 有权
    系统和应用程序授权方法

    公开(公告)号:US20050256878A1

    公开(公告)日:2005-11-17

    申请号:US10996406

    申请日:2004-11-26

    IPC分类号: G06F12/14 G06F17/30 G06F21/00

    摘要: A method and system for authorization of applications executing on a device having a key store. Applications obtain an application-level ticket to permit access to one or more key values located in the key store. Each ticket is securely associated with an application and being generated on the determination that the application is a trusted application. Tickets are potentially associated with one key value in the key store, with a subset of key values in the key store, or with all key values in the key store. Access to key values by an application is possible independently of a user providing a password for each such access.

    摘要翻译: 一种用于在具有密钥存储的设备上执行的应用的授权的方法和系统。 应用程序获得一个应用程序级票证,以允许访问位于密钥存储区中的一个或多个密钥值。 每个票据与应用程序安全地相关联,并且在确定应用程序是可信应用程序时生成。 门票可能与密钥库中的一个密钥值相关联,密钥存储中的密钥值的子集或密钥存储中的所有密钥值。 可以独立于为每个这样的访问提供密码的用户访问应用的密钥值。

    Wireless communication device with duress password protection and related method
    69.
    发明申请
    Wireless communication device with duress password protection and related method 有权
    无线通信设备具有胁迫密码保护及相关方法

    公开(公告)号:US20050245229A1

    公开(公告)日:2005-11-03

    申请号:US10835260

    申请日:2004-04-30

    摘要: A wireless communication device (and its related method of operation) includes, if invoked, password protected access to data stored therewithin and/or to normal device operations and further includes duress password checking logic that automatically causes a duress message to be sent if a duress password has been entered. The duress message is preferably sent without maintaining any user accessible indication of such sending. It is also preferred that the password checking logic automatically cause an end-of-duress message to be sent if a normal password is entered after a duress password has been entered. A plurality of different duress passwords may be entered into a duress password portion of data memory in the device.

    摘要翻译: 无线通信设备(及其相关操作方法)如果被调用,则包含密码保护对其中存储的数据和/或正常设备操作的访问,并且还包括胁迫密码检查逻辑,如果胁迫则自动导致胁迫消息被发送 密码已输入。 优先发送胁迫消息,而不保持这种发送的任何用户可访问的指示。 如果在输入胁迫密码之后输入正常密码,则密码检查逻辑也优选地自动导致发送结束消息。 可以将多个不同的胁迫密码输入到设备中的数据存储器的胁迫密码部分。

    Answer To Reset (ATR) Pushing
    70.
    发明申请
    Answer To Reset (ATR) Pushing 有权
    应答复位(ATR)推

    公开(公告)号:US20120160909A1

    公开(公告)日:2012-06-28

    申请号:US13409053

    申请日:2012-02-29

    IPC分类号: G06F17/00

    摘要: A smart card reader receives an Answer to Reset (ATR) from a smart card and transmits the ATR over a communication link to a computing device without waiting for an ATR request from the computing device. The computing device may cache the ATR and use it for subsequent communication sessions with the smart card.

    摘要翻译: 智能卡读卡器从智能卡接收应答复位(ATR),并通过通信链路将ATR发送到计算设备,而不必等待来自计算设备的ATR请求。 计算设备可以缓存ATR并将其用于与智能卡的后续通信会话。