Block encryption
    1.
    发明授权
    Block encryption 有权
    阻止加密

    公开(公告)号:US08767959B2

    公开(公告)日:2014-07-01

    申请号:US13307983

    申请日:2011-11-30

    IPC分类号: H04L9/18 H04L9/34

    CPC分类号: H04L9/0637 H04L9/0869

    摘要: Methods and systems for encrypting and decrypting data are described. In one embodiment, a computing system determines a first initialization vector (IV) from another IV and a sequence number of a block of information, and hashes the first IV to create a hash. The computing system then determines a first block from the first block of information and the first hash and enciphers the first block to generate a block of ciphertext. In another embodiment, the computing system deciphers the block of ciphertext to generate the first block, and determines the first IV from the other IV and a sequence number of a block of information. The computing system hashes the first IV to create a hash and determines a block of information corresponding to the first block of ciphertext from the first block and the hash.

    摘要翻译: 描述用于加密和解密数据的方法和系统。 在一个实施例中,计算系统从另一个IV和一个信息块的序列号确定第一初始化向量(IV),并且将第一个IV哈希建立一个散列。 然后,计算系统从第一个信息块和第一个散列确定第一个块,并加密该第一个块以产生一个密文块。 在另一个实施例中,计算系统解密密文块以产生第一块,并从另一个IV确定第一个IV和一个信息块的序列号。 计算系统对第一个IV进行散列以创建散列,并从第一个块和散列中确定与第一个密文块对应的信息块。

    Providing network security services for multiple requesters
    2.
    发明授权
    Providing network security services for multiple requesters 有权
    为多个请求者提供网络安全服务

    公开(公告)号:US08266262B2

    公开(公告)日:2012-09-11

    申请号:US12627876

    申请日:2009-11-30

    申请人: Robert Relyea

    发明人: Robert Relyea

    IPC分类号: G06F15/177

    CPC分类号: H04L63/10

    摘要: A security initialization system receives a first initialization request from a first requester to access a first database storing security data and stores context data for the first initialization request that identifies an initialization operation associated with the first database. The security initialization system receives a second initialization request from a second requester to access a second database storing security data and updates the context data to identify an initialization operation associated with the second database. The security initialization system receives a shut down request from one of the requesters, where the shut down request includes data for identifying a corresponding initialization operation in the context data. The security initialization system updates the context data to show that the corresponding initialization operation has a shut down request and determines whether a security module is to be shut down using the context data.

    摘要翻译: 安全初始化系统接收来自第一请求者的第一初始化请求以访问存储安全数据的第一数据库,并且存储用于识别与第一数据库相关联的初始化操作的第一初始化请求的上下文数据。 安全初始化系统从第二请求者接收第二初始化请求以访问存储安全数据的第二数据库,并更新上下文数据以识别与第二数据库相关联的初始化操作。 安全初始化系统从请求者之一接收关闭请求,其中关闭请求包括用于识别上下文数据中的对应的初始化操作的数据。 安全初始化系统更新上下文数据以示出相应的初始化操作具有关闭请求,并且确定是否使用上下文数据关闭安全模块。

    Methods and systems for secure shared smartcard access
    3.
    发明授权
    Methods and systems for secure shared smartcard access 有权
    用于安全共享智能卡访问的方法和系统

    公开(公告)号:US07992203B2

    公开(公告)日:2011-08-02

    申请号:US11439175

    申请日:2006-05-24

    申请人: Robert Relyea

    发明人: Robert Relyea

    CPC分类号: H04L63/0853

    摘要: An embodiment generally relates to a method of accessing a secure computer. The method includes capturing an authentication state of a security token in response to a verification of user authentication information. The method also includes providing the authentication state to at least one application requiring authentication with the security token and accessing the at least one application.

    摘要翻译: 实施例一般涉及访问安全计算机的方法。 该方法包括响应于用户认证信息的验证来捕获安全令牌的认证状态。 该方法还包括将认证状态提供给需要与安全令牌进行认证的至少一个应用程序并访问至少一个应用程序。

    Methods and systems for providing data objects on a token
    4.
    发明申请
    Methods and systems for providing data objects on a token 有权
    在令牌上提供数据对象的方法和系统

    公开(公告)号:US20070282881A1

    公开(公告)日:2007-12-06

    申请号:US11447180

    申请日:2006-06-06

    申请人: Robert Relyea

    发明人: Robert Relyea

    IPC分类号: G06F17/00

    CPC分类号: H03M7/30

    摘要: A computer system, method and/or computer-readable medium provide independent data objects to a token in compressed form. The independent data objects are representative of security information associated with the token. The system includes an interface operable to communicate with a token, and a processor cooperatively operable with the interface. The processor is configured to determine a set of independent data objects that are associated with the token, and to aggregate the set of independent data objects associated with the token into a group. Also, the processor is configured for compressing the group into a unit of contiguous data, and writing the unit of contiguous data to the token via the interface.

    摘要翻译: 计算机系统,方法和/或计算机可读介质以压缩形式向令牌提供独立的数据对象。 独立数据对象代表与令牌相关联的安全信息。 该系统包括可操作以与令牌通信的接口以及与该接口协作地可操作的处理器。 处理器被配置为确定与令牌相关联的一组独立数据对象,并将与令牌相关联的一组独立数据对象聚合成一组。 此外,处理器被配置为将组压缩成连续数据的单位,并且经由接口将连续数据的单元写入令牌。

    Methods and systems for providing data objects on a token
    6.
    发明授权
    Methods and systems for providing data objects on a token 有权
    在令牌上提供数据对象的方法和系统

    公开(公告)号:US08762350B2

    公开(公告)日:2014-06-24

    申请号:US13419274

    申请日:2012-03-13

    申请人: Robert Relyea

    发明人: Robert Relyea

    IPC分类号: G06F7/00

    CPC分类号: H03M7/30

    摘要: A computer system, method and/or computer-readable medium provide independent data objects to a token in compressed form. The independent data objects are representative of security information associated with the token. The system includes an interface operable to communicate with a token, and a processor cooperatively operable with the interface. The processor is configured to determine a set of independent data objects that are associated with the token, and to aggregate the set of independent data objects associated with the token into a group. Also, the processor is configured for compressing the group into a unit of contiguous data, and writing the unit of contiguous data to the token via the interface.

    摘要翻译: 计算机系统,方法和/或计算机可读介质以压缩形式向令牌提供独立的数据对象。 独立数据对象代表与令牌相关联的安全信息。 该系统包括可操作以与令牌通信的接口以及与该接口协作地可操作的处理器。 处理器被配置为确定与令牌相关联的一组独立数据对象,并将与令牌相关联的一组独立数据对象聚合成一组。 此外,处理器被配置为将组压缩成连续数据的单位,并且经由接口将连续数据的单元写入令牌。

    USING A PKCS MODULE FOR OPENING MULTIPLE DATABASES
    7.
    发明申请
    USING A PKCS MODULE FOR OPENING MULTIPLE DATABASES 有权
    使用PKCS模块打开多个数据库

    公开(公告)号:US20110131407A1

    公开(公告)日:2011-06-02

    申请号:US12627865

    申请日:2009-11-30

    申请人: Robert Relyea

    发明人: Robert Relyea

    IPC分类号: H04L29/06

    摘要: A security initialization system obtains load data that identifies a first database storing security data to be opened. The initialization system determines that a PKCS-based module for opening the first database is already initialized, where the PKCS-based module is already initialized from previously opening a second database. The initialization system causes the PKCS-based module to create a slot to open the first database, without shutting down the PKCS-based module, in response to determining that the PKCS-based module is already initialized.

    摘要翻译: 安全初始化系统获得标识存储要打开的安全数据的第一数据库的负载数据。 初始化系统确定用于打开第一数据库的基于PKCS的模块已被初始化,其中基于PKCS的模块已经从先前打开第二数据库初始化。 响应于确定基于PKCS的模块已被初始化,初始化系统使得基于PKCS的模块创建一个插槽来打开第一个数据库,而不关闭基于PKCS的模块。

    METHODS AND SYSTEMS FOR ASSIGNING ROLES ON A TOKEN
    8.
    发明申请
    METHODS AND SYSTEMS FOR ASSIGNING ROLES ON A TOKEN 有权
    方法和系统用于在一个TOKEN上分配角度

    公开(公告)号:US20080209225A1

    公开(公告)日:2008-08-28

    申请号:US11680200

    申请日:2007-02-28

    IPC分类号: H04L9/00

    CPC分类号: G06F21/77

    摘要: An embodiment relates generally to a method of assigning roles to a token. The method includes determining a first role for a first participant on a token and providing exclusive access to a first section of the token for the first participant base on the first role. The method also includes determining a second role for a second participant on the token and providing exclusive access to a second section of the token for the second participant based on the second role.

    摘要翻译: 实施例一般涉及将角色分配给令牌的方法。 该方法包括为令牌上的第一参与者确定第一角色,并且基于第一角色提供针对第一参与者的令牌的第一部分的独占访问。 该方法还包括为令牌上的第二参与者确定第二角色,并基于第二角色向第二参与者的令牌的第二部分提供独占访问。

    Method and Apparatus for Organizing an Extensible Table for Storing Cryptographic Objects
    9.
    发明申请
    Method and Apparatus for Organizing an Extensible Table for Storing Cryptographic Objects 有权
    用于组织用于存储加密对象的可扩展表的方法和装置

    公开(公告)号:US20080133514A1

    公开(公告)日:2008-06-05

    申请号:US11566640

    申请日:2006-12-04

    申请人: Robert Relyea

    发明人: Robert Relyea

    IPC分类号: G06F17/30

    CPC分类号: G06F21/34 G06F21/602

    摘要: Embodiments of the present invention provide a method and apparatus, including a client and security token, for managing cryptographic objects, such as public key cryptography standard (PKCS)#11 objects, in a computer system. A storage table for the cryptographic objects is established including rows for the cryptographic objects and columns corresponding to available attributes capable of being associated with the cryptographic objects. Actual attributes of the cryptographic objects are stored in ones of the plurality of columns corresponding to respective ones of the available attributes. The storage table is extensible such that additional columns are added corresponding to new attributes capable of being associated with the cryptographic objects.

    摘要翻译: 本发明的实施例提供了一种用于管理计算机系统中诸如公共密钥加密标准(PKCS)#11对象之类的加密对象的客户端和安全令牌的方法和装置。 建立用于加密对象的存储表,其包括用于密码对象的列和对应于能够与密码对象相关联的可用属性的列。 密码对象的实际属性被存储在对应于可用属性中的相应属性的多个列中的一个列中。 存储表是可扩展的,使得对应于能够与加密对象相关联的新属性添加附加列。

    METHODS, APPARATUS AND SYSTEMS FOR TIME-BASED FUNCTION BACK-OFF
    10.
    发明申请
    METHODS, APPARATUS AND SYSTEMS FOR TIME-BASED FUNCTION BACK-OFF 有权
    方法,基于时间的功能反馈的装置和系统

    公开(公告)号:US20080072283A1

    公开(公告)日:2008-03-20

    申请号:US11466691

    申请日:2006-08-23

    IPC分类号: H04L9/32

    CPC分类号: H04L63/0853 G06F21/31

    摘要: An embodiment generally relates to a method of increasing user convenience The method includes displaying a log-in user interface and receiving an authentication attempt in the log-in user interface. The method also includes determining a status of the authentication attempt and delaying a completion of an authentication attempt by a time-based function in response to a status being a failed authentication attempt

    摘要翻译: 一个实施方案通常涉及增加用户便利性的方法。该方法包括在登录用户界面中显示登录用户界面并接收认证尝试。 该方法还包括:通过基于时间的功能来确定认证尝试的状态并延迟认证尝试的完成,以响应于身份验证尝试失败的身份验证