Method and apparatus for trusted federated identity
    6.
    发明授权
    Method and apparatus for trusted federated identity 有权
    可信联合身份的方法和装置

    公开(公告)号:US08533803B2

    公开(公告)日:2013-09-10

    申请号:US13023985

    申请日:2011-02-09

    IPC分类号: G06F7/04 H04L29/06 G06F17/30

    摘要: A trusted computing environment, such as a smartcard, UICC, Java card, global platform, or the like may be used as a local host trust center and a proxy for a single-sign on (SSO) provider. This may be referred to as a local SSO provider (OP). This may be done, for example, to keep authentication traffic local and to prevent over the air communications, which may burden an operator network. To establish the OP proxy in the trusted environment, the trusted environment may bind to the SSO provider in a number of ways. For example, the SSO provider may interoperate with UICC-based UE authentication or GBA. In this way, user equipment may leverage the trusted environment in order to provide increased security and reduce over the air communications and authentication burden on the OP or operator network.

    摘要翻译: 可以使用诸如智能卡,UICC,Java卡,全球平台等的可信计算环境作为本地主机信任中心和用于单点登录(SSO)提供商的代理。 这可以被称为本地SSO提供商(OP)。 这可以被实现,例如,保持认证流量本地并且防止空中通信,这可能会对运营商网络造成负担。 要在受信任的环境中建立OP代理,可信环境可以通过多种方式绑定到SSO提供者。 例如,SSO提供商可以与基于UICC的UE认证或GBA进行互操作。 以这种方式,用户设备可以利用可信环境来提供增加的安全性并减少OP或运营商网络上的空中通信和认证负担。

    SYSTEM OF MULTIPLE DOMAINS AND DOMAIN OWNERSHIP
    7.
    发明申请
    SYSTEM OF MULTIPLE DOMAINS AND DOMAIN OWNERSHIP 有权
    多域和域所有权系统

    公开(公告)号:US20110099605A1

    公开(公告)日:2011-04-28

    申请号:US12763827

    申请日:2010-04-20

    IPC分类号: G06F15/173 G06F21/00

    CPC分类号: H04W12/06 H04L63/20 H04W12/04

    摘要: Methods and instrumentalities are disclosed that enable one or more domains on one or more devices to be owned or controlled by one or more different local or remote owners, while providing a level of system-wide management of those domains. Each domain may have a different owner, and each owner may specify policies for operation of its domain and for operation of its domain in relation to the platform on which the domain resides, and other domains. A system-wide domain manager may be resident on one of the domains. The system-wide domain manager may enforce the policies of the domain on which it is resident, and it may coordinate the enforcement of the other domains by their respective policies in relation to the domain in which the system-wide domain manager resides. Additionally, the system-wide domain manager may coordinate interaction among the other domains in accordance with their respective policies.

    摘要翻译: 公开了使一个或多个设备上的一个或多个域由一个或多个不同的本地或远程所有者拥有或控制的方法和手段,同时提供这些域的系统范围管理级别。 每个域可以具有不同的所有者,并且每个所有者可以指定用于其域的操作的策略以及关于域所在的平台以及其他域的其域的操作。 系统范围的域管理员可能驻留在其中一个域上。 全系统域管理员可以强制执行其驻留的域的策略,并且可以通过其相关于与全系统域管理员所在的域相关的策略来协调其他域的强制。 另外,系统范围的域管理器可以根据各自的策略协调其他域之间的交互。

    Method And Apparatus For Trusted Federated Identity
    8.
    发明申请
    Method And Apparatus For Trusted Federated Identity 有权
    用于可信联合身份的方法和装置

    公开(公告)号:US20120072979A1

    公开(公告)日:2012-03-22

    申请号:US13023985

    申请日:2011-02-09

    IPC分类号: H04L9/32 G06F21/00

    摘要: A trusted computing environment, such as a smartcard, UICC, Java card, global platform, or the like may be used as a local host trust center and a proxy for a single-sign on (SSO) provider. This may be referred to as a local SSO provider (OP). This may be done, for example, to keep authentication traffic local and to prevent over the air communications, which may burden an operator network. To establish the OP proxy in the trusted environment, the trusted environment may bind to the SSO provider in a number of ways. For example, the SSO provider may interoperate with UICC-based UE authentication or GBA. In this way, user equipment may leverage the trusted environment in order to provide increased security and reduce over the air communications and authentication burden on the OP or operator network.

    摘要翻译: 可以使用诸如智能卡,UICC,Java卡,全球平台等的可信计算环境作为本地主机信任中心和用于单点登录(SSO)提供商的代理。 这可以被称为本地SSO提供商(OP)。 这可以被实现,例如,保持认证流量本地并且防止空中通信,这可能会对运营商网络造成负担。 要在受信任的环境中建立OP代理,可信环境可以通过多种方式绑定到SSO提供者。 例如,SSO提供商可以与基于UICC的UE认证或GBA进行互操作。 以这种方式,用户设备可以利用可信环境来提供增加的安全性并减少OP或运营商网络上的空中通信和认证负担。