SYSTEM AND METHOD FOR SEARCHING AND RETRIEVING CERTIFICATES
    81.
    发明申请
    SYSTEM AND METHOD FOR SEARCHING AND RETRIEVING CERTIFICATES 有权
    用于搜索和检索证书的系统和方法

    公开(公告)号:US20120239927A1

    公开(公告)日:2012-09-20

    申请号:US13483216

    申请日:2012-05-30

    IPC分类号: H04L29/06

    摘要: A system and method for searching and retrieving certificates, which may be used in the processing of encoded messages. In one broad aspect, a method is provided in which a certificate search request is received, a search of one or more certificate servers for certificates satisfying the request is performed, located certificates are retrieved and processed at a first computing device to determine data that uniquely identifies each located certificate, and search result data comprising the determined data is communicated to a second device (e.g. a mobile device) for use in determining whether each located certificate is already stored on the second device.

    摘要翻译: 用于搜索和检索证书的系统和方法,其可以用于编码消息的处理。 在一个广泛的方面,提供了一种方法,其中接收到证书搜索请求,执行对满足请求的证书的一个或多个证书服务器的搜索,定位的证书在第一计算设备处被检索和处理以确定唯一的数据 识别每个定位的证书,并且包括确定的数据的搜索结果数据被传送到第二设备(例如移动设备),以用于确定每个定位的证书是否已经存储在第二设备上。

    Policy proxy
    82.
    发明授权
    Policy proxy 有权
    策略代理

    公开(公告)号:US08261338B2

    公开(公告)日:2012-09-04

    申请号:US12058684

    申请日:2008-03-29

    IPC分类号: H04L29/06

    摘要: In a system with a policy server, a first device able to communicate with the policy server and a second device able to communicate with the first device and unable to communicate with the policy server, the first device is to act as a policy proxy. The policy server may push to the first device a policy for the second device, and the first device may push the policy to the second device.

    摘要翻译: 在具有策略服务器的系统中,能够与策略服务器通信的第一设备和能够与第一设备进行通信并且无法与策略服务器通信的第二设备,第一设备将用作策略代理。 策略服务器可以向第一设备推送第二设备的策略,并且第一设备可以将策略推送到第二设备。

    System and method for managing items in a list shared by a group of mobile devices
    83.
    发明授权
    System and method for managing items in a list shared by a group of mobile devices 有权
    用于管理由一组移动设备共享的列表中的项目的系统和方法

    公开(公告)号:US08254890B2

    公开(公告)日:2012-08-28

    申请号:US12756807

    申请日:2010-04-08

    IPC分类号: H04L12/58

    摘要: A method and system are provided for sharing data amongst a group of a plurality of mobile devices without requiring a database or server to centrally store the shared data. The shared data is instead stored by each group member individually while controlling the manner in which the shared data is updated. The shared data can be used to manage tasks in a group project. To manage updates, the shared data is atomized such that individual databases in the shared data are separated or otherwise delineated into one or more records, each record having associated therewith, a value. To maintain a common copy of the shared data at each device, any update is sent to all group members using an intermediate message exchange service that is capable of transmitting a sent message to more than one recipient if necessary. In this way, the updates are multicast to the group. To manage the content of the shared data, each update comprises one or more changes to a current copy of a corresponding record.

    摘要翻译: 提供了一种方法和系统,用于在一组多个移动设备之间共享数据,而不需要数据库或服务器来集中存储共享数据。 每个组成员分别存储共享数据,同时控制更新共享数据的方式。 共享数据可用于管理组项目中的任务。 为了管理更新,共享数据被雾化,使得共享数据中的各个数据库被分离或以其他方式描绘成一个或多个记录,每个记录与其相关联,一个值。 为了在每个设备上维护共享数据的共同副本,使用能够在必要时将发送的消息发送到多于一个接收者的中间消息交换服务来向所有组成员发送任何更新。 以这种方式,更新是组播到组。 为了管理共享数据的内容,每个更新包括对相应记录的当前副本的一个或多个更改。

    System and method of mobile lightweight cryptographic directory access
    84.
    发明授权
    System and method of mobile lightweight cryptographic directory access 有权
    移动轻量级加密目录访问的系统和方法

    公开(公告)号:US08239675B2

    公开(公告)日:2012-08-07

    申请号:US12881523

    申请日:2010-09-14

    IPC分类号: H04L29/06

    摘要: A system for handling an LDAP service request to an LDAP server for an LDAP service comprises a client program executable on a client system and a handler program executable on a handler system. The client program is operable to generate LDAP service request data corresponding to the LDAP service and provide the LDAP service request data for transmission from the client system, and further operable to receive LDAP service reply data in response to the LDAP service request data. The handler program is operable to receive the LDAP service request data transmitted from the client system and execute the LDAP service request to the LDAP server, receive LDAP service reply data from the LDAP server during one or more passes, and upon completion of the LDAP service, provide the LDAP service reply data for transmission to the client system in a single pass.

    摘要翻译: 用于处理针对LDAP服务的LDAP服务器的LDAP服务请求的系统包括在客户机系统上可执行的客户端程序和可在处理程序系统上执行的处理程序。 所述客户机程序可操作地生成与所述LDAP服务相对应的LDAP服务请求数据,并提供所述LDAP服务请求数据以从所述客户端系统传输,并且还可操作以响应于所述LDAP服务请求数据接收LDAP服务应答数据。 处理程序可操作用于接收从客户端系统发送的LDAP服务请求数据,并向LDAP服务器执行LDAP服务请求,在一次或多次传递期间从LDAP服务器接收LDAP服务回复数据,以及LDAP服务完成后 提供LDAP服务回复数据,以便单次传送到客户端系统。

    Multiple-stage system and method for processing encoded messages
    85.
    发明授权
    Multiple-stage system and method for processing encoded messages 有权
    用于处理编码消息的多阶段系统和方法

    公开(公告)号:US08194857B2

    公开(公告)日:2012-06-05

    申请号:US10493507

    申请日:2002-10-24

    IPC分类号: H04L29/06

    摘要: System and methods for processing encoded messages at a message receiver are described. Encoded message processing is performed in multiple stages. In a first stage, a new received message is at least partially decoded by performing any decoding operations that require no user input and a resulting context object is stored in memory, before a user is notified that the new message has been received. When the user accesses the new message, any further required decoding operations are performed on the stored context object in a second stage of processing. The message can subsequently be displayed or otherwise processed relatively quickly, without repeating the first stage decoding operations. Decoding operations may include signature verification, decryption, other types of decoding, or some combination thereof.

    摘要翻译: 描述了在消息接收机处理编码消息的系统和方法。 编码消息处理在多个阶段执行。 在第一阶段中,在通知用户已经接收到新消息之前,通过执行不需要用户输入的任何解码操作,并且所得到的上下文对象被存储在存储器中,至少部分解码新的接收到的消息。 当用户访问新消息时,在第二阶段的处理中对存储的上下文对象执行任何进一步的所需解码操作。 随后可以相对快速地显示或以其他方式处理消息,而不重复第一级解码操作。 解码操作可以包括签名验证,解密,其他类型的解码,或其某些组合。

    DISPLAY OF SECURE MESSAGES ON A MOBILE COMMUNICATION DEVICE
    86.
    发明申请
    DISPLAY OF SECURE MESSAGES ON A MOBILE COMMUNICATION DEVICE 有权
    在移动通信设备上显示安全消息

    公开(公告)号:US20120122425A1

    公开(公告)日:2012-05-17

    申请号:US12946632

    申请日:2010-11-15

    IPC分类号: H04L12/58

    CPC分类号: H04L51/14 H04L51/06 H04L51/38

    摘要: A mobile communications device for the display of an incrementally received message includes a message viewer application for scanning the received portions of the message. On determination that the received portion of the message includes a first displayable portion of the message content, the system signals to a message server to halt the message server from forwarding further portions of the message content. The system provides a mechanism for the user of the mobile communications device to cause the mobile communications device to further signal the message server to recommence the forwarding of further portions of the secure message content to permit the verification of the e-mail based on the further portions of the secure message content.

    摘要翻译: 用于显示递增接收消息的移动通信设备包括用于扫描消息的接收部分的消息查看器应用程序。 在确定消息的接收部分包括消息内容的第一可显示部分的情况下,系统向消息服务器发信号,以停止消息服务器转发消息内容的其他部分。 该系统为移动通信设备的用户提供一种机制,使得移动通信设备进一步向该消息服务器发信号以重新发送安全消息内容的其他部分的转发,以允许基于更进一步的电子邮件来验证该电子邮件 部分安全消息内容。

    Systems, devices, and methods for securely transmitting a security parameter to a computing device

    公开(公告)号:US08171292B2

    公开(公告)日:2012-05-01

    申请号:US12420387

    申请日:2009-04-08

    摘要: Embodiments of the systems, devices, and methods described herein generally facilitate the secure transmittal of security parameters. In accordance with at least one embodiment, a representation of first data comprising a password is generated at the first computing device as an image or audio signal. The image or audio signal is transmitted from the first computing device to the second computing device. The password is determined from the image or audio signal at the second computing device. A key exchange is performed between the first computing device and the second computing device wherein a key is derived at each of the first and second computing devices. In at least one embodiment, one or more security parameters (e.g. one or more public keys) are exchanged between the first and second computing devices, and techniques for securing the exchange of security parameters or authenticating exchanged security parameters are generally disclosed herein.

    SYSTEM AND METHOD OF PROTECTING DATA ON A COMMUNICATION DEVICE
    88.
    发明申请
    SYSTEM AND METHOD OF PROTECTING DATA ON A COMMUNICATION DEVICE 有权
    在通信设备上保护数据的系统和方法

    公开(公告)号:US20120072722A1

    公开(公告)日:2012-03-22

    申请号:US13303214

    申请日:2011-11-23

    IPC分类号: H04L9/00

    摘要: A system and method of protecting data on a communication device are provided. Data received when the communication device is in a first operational state is encrypted using a first cryptographic key and algorithm. When the communication device is in a second operational state, received data is encrypted using a second cryptographic key and algorithm. Received data is stored on the communication device in encrypted form.

    摘要翻译: 提供了一种在通信设备上保护数据的系统和方法。 当通信设备处于第一操作状态时接收到的数据使用第一加密密钥和算法进行加密。 当通信设备处于第二操作状态时,使用第二加密密钥和算法来加密接收的数据。 接收到的数据以加密形式存储在通信设备上。

    System and method for remote reset of password and encryption key
    89.
    发明授权
    System and method for remote reset of password and encryption key 有权
    用于远程重设密码和加密密钥的系统和方法

    公开(公告)号:US08074078B2

    公开(公告)日:2011-12-06

    申请号:US11383369

    申请日:2006-05-15

    IPC分类号: G06F11/30

    摘要: A method for securing data and resetting a password using a content protection key is provided, in which the content protection key itself is protected by a password. A content protection key is also protected at a data storage device with a key encryption key generated in collaboration with an additional device such as a server. The server stores a private key required to regenerate the key encryption key, but this private key is not provided from the server to the data storage device; rather, a public key derived from the private key is provided by the server. The data storage device combines the received public key and a further private key to derive the key encryption key; the further private key itself is not stored by the data storage device, but rather its matching public key is stored. The content protection key is then encrypted using a password and the derived key encryption key. If the password is lost, data from the server and from the data storage device may be combined to recreate the key encryption key.

    摘要翻译: 提供了一种使用内容保护密钥保护数据和重置密码的方法,其中内容保护密钥本身由密码保护。 在数据存储设备上还保护内容保护密钥,其中使用与诸如服务器的附加设备协作生成的密钥加密密钥。 服务器存储重新生成密钥加密密钥所需的专用密钥,但该私钥没有从服务器提供给数据存储设备; 相反,由私钥导出的公钥由服务器提供。 数据存储装置将接收到的公开密钥和另外的私钥组合以导出密钥加密密钥; 另外的私钥本身不被数据存储设备存储,而是存储其匹配的公钥。 然后使用密码和派生密钥加密密钥对内容保护密钥进行加密。 如果密码丢失,则来自服务器和数据存储设备的数据可以被组合以重新创建密钥加密密钥。

    Selectively wiping a remote device
    90.
    发明授权
    Selectively wiping a remote device 有权
    选择性地擦拭远程设备

    公开(公告)号:US08056143B2

    公开(公告)日:2011-11-08

    申请号:US12016723

    申请日:2008-01-18

    摘要: A system and method for selectively securing data from unauthorized access on a client device storing a plurality of data types with reference to an authorization level indicated in a command. A command is received at a client device comprising an authorization level indicator. Based on at least one predefined rule, which may be implemented in an IT policy stored at the client device, each of the plurality of data types to be secured is determined, and then the data corresponding to those types is secured. The data may be secured by encrypting and/or deleting the data at the client device. The predefined rules associated with each authorization level may be configured by a user or administrator having an authorization level that exceeds the associated authorization level. The system and method thus provide a method for securing only selected data types, depending on the authorization level of the issuer of the command.

    摘要翻译: 一种系统和方法,用于参考命令中指示的授权级别选择性地保护存储多种数据类型的客户机设备上的未授权访问的数据。 在包括授权级别指示符的客户端设备处接收到命令。 基于可以在存储在客户端设备的IT策略中实现的至少一个预定规则,确定要保护的多个数据类型中的每一个,然后确保与这些类型对应的数据。 可以通过在客户端设备处加密和/或删除数据来保护数据。 与每个授权级别相关联的预定义规则可以由具有超过相关授权级别的授权级别的用户或管理员配置。 因此,系统和方法提供了一种仅根据命令的发行者的授权级别来保护所选择的数据类型的方法。