METHOD AND APPARATUS FOR PROVIDING SECURE SOFTWARE EXECUTION ENVIRONMENT BASED ON DOMAIN SEPARATION
    1.
    发明申请
    METHOD AND APPARATUS FOR PROVIDING SECURE SOFTWARE EXECUTION ENVIRONMENT BASED ON DOMAIN SEPARATION 审中-公开
    基于域分离提供安全软件执行环境的方法和装置

    公开(公告)号:US20130042297A1

    公开(公告)日:2013-02-14

    申请号:US13476998

    申请日:2012-05-21

    IPC分类号: G06F21/00

    CPC分类号: G06F21/53

    摘要: An apparatus for providing a secure environment of software execution in a terminal device includes a normal service domain and a secure service domain into which a domain of the software is divided based on virtualization. The normal service domain executes a normal service on elements of the software, and the secure service domain executes a security service on elements of the software in response to a request for a security service of the software elements from the normal service domain.

    摘要翻译: 用于在终端设备中提供软件执行的安全环境的装置包括:正常服务域和安全服务域,基于虚拟化将软件的域划分到其中。 正常服务域在软件的元件上执行正常服务,并且安全服务域响应于来自正常服务域的软件元件的安全服务的请求,对该软件的元件执行安全服务。

    Block cipher aria substitution apparatus and method
    2.
    发明授权
    Block cipher aria substitution apparatus and method 有权
    块密码替换装置和方法

    公开(公告)号:US08345865B2

    公开(公告)日:2013-01-01

    申请号:US12176649

    申请日:2008-07-21

    IPC分类号: H04K1/10

    摘要: A block cipher ARIA substitution apparatus, the apparatus includes a first Sbox operation unit for performing operations of a substitution box S1 and a substitution box S1−1; a second Sbox operation unit for performing operations of a substitution box S2 and a substitution box S2−1; and a control unit for determining modes of the first Sbox operation unit and the second Sbox operation unit. The first Sbox operation unit has a first inverse affine transformation unit for performing an inverse affine operation for obtaining S1−1; a finite field inverse element operation unit for computing an inverse element of GF(28) or a result value of the first inverse affine transformation unit; a first affine transformation unit for performing an affine operation for obtaining S1; and a first and a second multiplexer.

    摘要翻译: 一种分组密码ARIA替代装置,该装置包括用于执行替代框S1和替换框S1-1的操作的第一Sbox操作单元; 用于执行替代框S2和替代框S2-1的操作的第二Sbox操作单元; 以及用于确定第一Sbox操作单元和第二Sbox操作单元的模式的控制单元。 第一Sbox操作单元具有用于执行用于获得S1-1的反向仿射操作的第一反向仿射变换单元; 用于计算GF(28)的逆元素或第一反仿像变换单元的结果值的有限域逆元素运算单元; 用于执行用于获得S1的仿射运算的第一仿射变换单元; 以及第一和第二多路复用器。

    DATABASE ENCRYPTION AND QUERY METHOD KEEPING ORDER WITHIN BUCKET PARTIALLY
    6.
    发明申请
    DATABASE ENCRYPTION AND QUERY METHOD KEEPING ORDER WITHIN BUCKET PARTIALLY 审中-公开
    数据库加密和查询方法保存在BUCKET部分

    公开(公告)号:US20090316887A1

    公开(公告)日:2009-12-24

    申请号:US12136809

    申请日:2008-06-11

    IPC分类号: H04L9/00

    CPC分类号: G06F21/6227 G06F16/2458

    摘要: A database encryption and query method keeping an order within a bucket partially, which encrypts and stores numeric data in a database, includes calculating a relative value of a plaintext within a bucket to which the plaintext is allocated; generating a first key value by producing a random number within the bucket; generating a second key value for defining a function having a bucket range of the bucket as an input; and changing the relative value based on the first and the second key value with keeping an order of the relative value partially to store the changed relative value. The first key value may be a value of separating order informations on the relative value. Further, the second key value may be a resultant value obtained by applying a mod 2 operation to the bucket size of the bucket.

    摘要翻译: 一种数据库加密和查询方法,其部分地保持桶内的订单,该数据库加密和查询方法在数据库中加密和存储数字数据,包括计算明文分配到的桶内的明文的相对值; 通过在桶内产生随机数来产生第一密钥值; 生成用于定义具有所述存储桶的存储桶范围的功能作为输入的第二密钥值; 并且基于第一和第二键值改变相对值,同时保持相对值的顺序以存储改变的相对值。 第一个键值可以是对相对值分离订单信息的值。 此外,第二键值可以是通过对铲斗的铲斗大小应用mod 2操作而获得的合成值。

    Method of storing data in a non-volatile memory and apparatus therefor
    7.
    发明授权
    Method of storing data in a non-volatile memory and apparatus therefor 有权
    将数据存储在非易失性存储器中的方法及其装置

    公开(公告)号:US06970970B2

    公开(公告)日:2005-11-29

    申请号:US10348711

    申请日:2003-01-22

    摘要: Provided is a method of storing data in a non-volatile memory, including generating and storing logs including data to be stored and an address of the non-volatile memory in response to a data-writing request, and comparing addresses of the logs and storing data corresponding to the same page by the unit of page in a corresponding area of the non-volatile memory. The method makes it possible to minimize delay in storing data, reduce the number of accesses to the non-volatile memory and uniformly write data in the whole non-volatile memory, thereby minimizing a response time of the non-volatile memory and increasing the lifetime of the non-volatile memory.

    摘要翻译: 提供了一种在非易失性存储器中存储数据的方法,包括响应于数据写入请求而生成和存储包括要存储的数据和非易失性存储器的地址的日志,以及比较日志的地址和存储 通过非易失性存储器的对应区域中的页面单元对应于同一页面的数据。 该方法使得可以最小化存储数据的延迟,减少对非易失性存储器的访问次数并且将数据均匀地写入整个非易失性存储器中,从而最小化非易失性存储器的响应时间并增加寿命 的非易失性存储器。

    Security management server and image data managing method thereof
    8.
    发明授权
    Security management server and image data managing method thereof 有权
    安全管理服务器及其图像数据管理方法

    公开(公告)号:US08364956B2

    公开(公告)日:2013-01-29

    申请号:US12775029

    申请日:2010-05-06

    IPC分类号: H04L29/06 G06F11/30

    CPC分类号: H04N7/185 H04N7/181

    摘要: A security management server includes an input unit for receiving image data from at least one network camera; a control unit for assigning an access authority level to each image data received via the input unit; and a storage unit for storing therein the image data along with the access authority levels assigned by the control unit. When receiving a request for a specific image data among the image data stored in the storage unit from a user having a user access authority level, the control unit compares the user access authority level and the access authority level assigned to the specific image data, and based on comparison result thereof, selectively provides the specific image data to the user.

    摘要翻译: 安全管理服务器包括用于从至少一个网络摄像机接收图像数据的输入单元; 控制单元,用于将访问权限级别分配给经由所述输入单元接收的每个图像数据; 以及存储单元,用于在其中存储图像数据以及由控制单元分配的访问权限级别。 当从具有用户访问权限级别的用户接收到存储在存储单元中的图像数据中的特定图像数据的请求时,控制单元比较分配给特定图像数据的用户访问权限级别和访问权限级别,以及 基于其比较结果,选择性地向用户提供特定图像数据。

    SECURITY MANAGEMENT SERVER AND IMAGE DATA MANAGING METHOD THEREOF
    10.
    发明申请
    SECURITY MANAGEMENT SERVER AND IMAGE DATA MANAGING METHOD THEREOF 有权
    安全管理服务器和图像数据管理方法

    公开(公告)号:US20110145574A1

    公开(公告)日:2011-06-16

    申请号:US12775029

    申请日:2010-05-06

    CPC分类号: H04N7/185 H04N7/181

    摘要: A security management server includes an input unit for receiving image data from at least one network camera; a control unit for assigning an access authority level to each image data received via the input unit; and a storage unit for storing therein the image data along with the access authority levels assigned by the control unit. When receiving a request for a specific image data among the image data stored in the storage unit from a user having a user access authority level, the control unit compares the user access authority level and the access authority level assigned to the specific image data, and based on comparison result thereof, selectively provides the specific image data to the user.

    摘要翻译: 安全管理服务器包括用于从至少一个网络摄像机接收图像数据的输入单元; 控制单元,用于将访问权限级别分配给经由所述输入单元接收的每个图像数据; 以及存储单元,用于在其中存储图像数据以及由控制单元分配的访问权限级别。 当从具有用户访问权限级别的用户接收到存储在存储单元中的图像数据中的特定图像数据的请求时,控制单元比较分配给特定图像数据的用户访问权限级别和访问权限级别,以及 基于其比较结果,选择性地向用户提供特定图像数据。