Method and apparatus for providing trusted single sign-on access to applications and internet-based services
    1.
    发明授权
    Method and apparatus for providing trusted single sign-on access to applications and internet-based services 有权
    用于提供对应用程序和基于互联网的服务的可信单点登录访问的方法和装置

    公开(公告)号:US08707409B2

    公开(公告)日:2014-04-22

    申请号:US11843517

    申请日:2007-08-22

    IPC分类号: G06F7/04

    摘要: A method and apparatus for password management and single sign-on (SSO) access based on trusted computing (TC) technology. The methods implement the Trusted Computing Group (TCG)'s trusted platform module (TPM), which interacts with both proxy SSO unit and web-accessing applications to provide a secure, trusted mechanism to generate, store, and retrieve passwords and SSO credentials. The various embodiments of the present invention allow a user to hop securely and transparently from one site to another that belong to a pre-identified group of sites, after signing on just once to a secured proxy residing at the user's device.

    摘要翻译: 一种基于可信计算(TC)技术的密码管理和单点登录(SSO)访问的方法和装置。 该方法实施了可信计算组(TCG)的可信平台模块(TPM),该平台模块与代理SSO单元和Web访问应用程序进行交互,以提供安全可靠的机制来生成,存储和检索密码和SSO凭据。 本发明的各种实施例允许用户在仅驻留在用户设备上的安全代理器一次登录之后,从属于预先识别的站点组的一个站点到另一站点安全地和透明地跳转。

    SUPPORT OF PHYSICAL LAYER SECURITY IN WIRELESS LOCAL AREA NETWORKS
    4.
    发明申请
    SUPPORT OF PHYSICAL LAYER SECURITY IN WIRELESS LOCAL AREA NETWORKS 有权
    在无线局域网中支持物理层安全

    公开(公告)号:US20100131751A1

    公开(公告)日:2010-05-27

    申请号:US12499530

    申请日:2009-07-08

    IPC分类号: H04L29/06 H04L12/26

    摘要: A method and an apparatus for performing physical layer security operation are disclosed. A physical layer performs measurements continuously, and reports the measurements to a medium access control (MAC) layer. The MAC layer processes the measurements, and sends a security alert to a security manager upon detection of an abnormal condition based on the measurements. The security manager implements a counter-measure upon receipt of the security alert. The measurements include channel impulse response (CIR), physical medium power measurement, automatic gain control (AGC) value and status, automatic frequency control (AFC) gain and status, analog-to-digital converter (ADC) gain, Doppler spread estimate, and/or short preamble matched filter output. The security manager may switch a channel, switch a channel hopping policy, change a back-off protocol, or change a beamforming vector upon reception of the security alert.

    摘要翻译: 公开了一种用于执行物理层安全操作的方法和装置。 物理层连续执行测量,并将测量结果报告给介质访问控制(MAC)层。 MAC层处理测量,并且在基于测量检测到异常状况时向安全管理器发送安全警报。 安全管理员在收到安全警报后实施对抗措施。 测量包括信道脉冲响应(CIR),物理介质功率测量,自动增益控制(AGC)值和状态,自动频率控制(AFC)增益和状态,模数转换器(ADC)增益,多普勒扩展估计, 和/或短前同步码匹配滤波器输出。 在接收到安全警报时,安全管理器可以切换信道,切换信道跳变策略,改变退避协议或改变波束形成向量。

    METHOD AND APPARATUS FOR ENABLING PHYSICAL LAYER SECRET KEY GENERATION
    5.
    发明申请
    METHOD AND APPARATUS FOR ENABLING PHYSICAL LAYER SECRET KEY GENERATION 有权
    用于启动物理层秘密密钥生成的方法和装置

    公开(公告)号:US20090141900A1

    公开(公告)日:2009-06-04

    申请号:US12266435

    申请日:2008-11-06

    IPC分类号: H04L9/00

    摘要: A method and apparatus for generating physical layer security keys is provided. Channel impulse response (CIR) measurements are recorded. Each CIR measurement is associated with a time-stamp. Where possible, the time-stamps are paired with time-stamps that are associated with another plurality of CIR measurements. The CIR data associated with the paired time-stamps is aggregated. Each of the aggregated CIR measurements is aligned, and at least one CIR measurement is selected for use in secret key generation.

    摘要翻译: 提供了一种用于生成物理层安全密钥的方法和装置。 记录通道脉冲响应(CIR)测量。 每个CIR测量都与时间戳相关联。 在可能的情况下,时间戳与与另一多个CIR测量相关联的时间戳配对。 与配对的时间戳相关联的CIR数据被聚合。 每个聚合的CIR测量被对齐,并且选择至少一个CIR测量用于秘密密钥生成。

    ENHANCED SECURITY FOR DIRECT LINK COMMUNICATIONS
    7.
    发明申请
    ENHANCED SECURITY FOR DIRECT LINK COMMUNICATIONS 有权
    直接链接通信的增强安全性

    公开(公告)号:US20100153727A1

    公开(公告)日:2010-06-17

    申请号:US12639293

    申请日:2009-12-16

    IPC分类号: H04L9/32

    摘要: A method for secure direct link communications between multiple wireless transmit/receive units (WTRUs). The WTRUs exchange nonces that are used for generating a common nonce. A group identification information element (GIIE) is generated from at least the common nonce and is forwarded to an authentication server. The authentication server generates a group direct link master key (GDLMK) from the GIIE to match WTRUs as part of a key agreement group. Group key encryption key (GKEK) and a group key confirmation key (GKCK) are also generated based on the common nonce and are used to encrypt and sign the GDLMK so that base stations do not have access to the GDLMK. Also disclosed is a method for selecting a key management suite (KMS) to generate temporal keys. A KMS index (KMSI) may be set according to a selected KMS, transmitted to another WTRU and used to establish a direct link.

    摘要翻译: 一种用于多个无线发射/接收单元(WTRU)之间的安全直接链路通信的方法。 WTRU交换用于生成公共随机数的随机数。 从至少公共随机数生成组标识信息元素(GIIE),并将其转发给认证服务器。 认证服务器从GIIE生成组直接链路主密钥(GDLMK),作为密钥协商组的一部分匹配WTRU。 组密钥加密密钥(GKEK)和组密钥确认密钥(GKCK)也是基于通用随机数生成的,用于对GDLMK进行加密和签名,以使基站无法访问GDLMK。 还公开了一种用于选择密钥管理套件(KMS)以生成时间密钥的方法。 可以根据所选择的KMS设置KMS索引(KMSI),发送到另一个WTRU并用于建立直接链路。