System and Method for Distributed Security
    2.
    发明申请
    System and Method for Distributed Security 有权
    分布式安全系统与方法

    公开(公告)号:US20140365764A1

    公开(公告)日:2014-12-11

    申请号:US14263844

    申请日:2014-04-28

    Inventor: Mark BUER

    Abstract: A security architecture in which a security module is integrated in a client machine, wherein the client machine includes a local host that is untrusted. The security module performs encryption and decryption algorithms, authentication, and public key processing. The security module also includes separate key caches for key encryption keys and application keys. A security module can also interface a cryptographic accelerator through an application key cache. The security module can authorize a public key and an associated key server. That public key can subsequently be used to authorize additional key servers. Any of the authorized key servers can use their public keys to authorize the public keys of additional key servers. Secure authenticated communications can then transpire between the client and any of these key servers. Such a connection is created by a secure handshake process that takes place between the client and the key server. A time value can be sent from the key server to the client, allowing for secure revocation of keys. In addition, secure configuration messages can be sent to the security module.

    Abstract translation: 安全模块集成在客户端计算机中的安全架构,其中客户端计算机包括不受信任的本地主机。 安全模块执行加密和解密算法,认证和公钥处理。 安全模块还包括用于密钥加密密钥和应用密钥的单独的密钥高速缓存。 安全模块还可以通过应用密钥高速缓存来连接密码加速器。 安全模块可以授权公钥和相关联的密钥服务器。 该公钥随后可用于授权其他密钥服务器。 任何授权的密钥服务器都可以使用其公钥来授权其他密钥服务器的公钥。 然后可以在客户端和任何这些密钥服务器之间发现安全认证的通信。 这种连接是通过在客户端和密钥服务器之间发生的安全握手过程创建的。 时间值可以从密钥服务器发送到客户端,允许安全地撤销密钥。 此外,可以将安全配置消息发送到安全模块。

    DETERMINING APPLICATION USAGE RELATIVE TO A PARTICULAR LOCATION
    3.
    发明申请
    DETERMINING APPLICATION USAGE RELATIVE TO A PARTICULAR LOCATION 审中-公开
    确定与特定位置相关的应用程序

    公开(公告)号:US20130122857A1

    公开(公告)日:2013-05-16

    申请号:US13734351

    申请日:2013-01-04

    CPC classification number: H04W4/24 H04W4/029 H04W4/23

    Abstract: A mobile device collects information about application usage and associates collected application information with a location of the mobile device and a time that the application is accessed. The application is stored on the mobile device or on an external device and accessed via a network. The application information, location of the mobile device and time the application is accessed are communicated to another device and stored in a storage device which may be operated or managed by a service provider or another entity. The application information may comprise identification of a website, a network device or URL, the application and/or data that is input and/or output from the application. The location of the mobile device and/or the time, are determined utilizing a GNSS receiver and/or utilizing information from a network device. The application information, the location of the mobile device and/or the time may be utilized for targeted advertising.

    Abstract translation: 移动设备收集关于应用使用的信息,并将收集的应用信息与移动设备的位置和应用访问的时间相关联。 应用程序存储在移动设备或外部设备上,并通过网络访问。 将应用信息,移动设备的位置和应用访问的时间传送到另一设备,并将其存储在可由服务提供商或另一实体操作或管理的存储设备中。 应用信息可以包括网站的标识,网络设备或URL,从应用输入和/或输出的应用和/或数据。 使用GNSS接收器和/或利用来自网络设备的信息确定移动设备的位置和/或时间。 应用信息,移动设备的位置和/或时间可以用于有针对性的广告。

    Anti-Replay Protected Flash
    4.
    发明申请
    Anti-Replay Protected Flash 有权
    防重放保护闪存

    公开(公告)号:US20150006789A1

    公开(公告)日:2015-01-01

    申请号:US13931653

    申请日:2013-06-28

    Inventor: Mark BUER

    CPC classification number: G06F21/79 G06F21/44 G06F2221/2107

    Abstract: Embodiments of the present disclosure describe a system and method for providing anti-replay protection. One embodiment describes a system comprising: a security device; and an anti-replay protected flash device comprising: a flash memory array; an authentication unit; and a secure memory, wherein the authentication unit and the secure memory are disposed in a security boundary.

    Abstract translation: 本公开的实施例描述了用于提供反重放保护的系统和方法。 一个实施例描述了一种系统,包括:安全设备; 以及防重放保护的闪存设备,包括:闪存阵列; 认证单元; 和安全存储器,其中认证单元和安全存储器设置在安全边界中。

    User Authentication System
    5.
    发明申请
    User Authentication System 有权
    用户认证系统

    公开(公告)号:US20140245007A1

    公开(公告)日:2014-08-28

    申请号:US14270120

    申请日:2014-05-05

    Abstract: Techniques are provided for users to authenticate themselves to components in a system. The users may securely and efficiently enter credentials into the components. These credentials may be provided to a server in the system with strong authentication that the credentials originate from secure components. The server may then automatically build a network by securely distributing keys to each secure component to which a user presented credentials.

    Abstract translation: 为用户提供了技术来对系统中的组件进行身份验证。 用户可以安全有效地将凭据输入到组件中。 这些凭证可以被提供给具有认证的系统中的服务器,证书来自安全组件。 然后,服务器可以通过将密钥安全地分发给用户呈现证书的每个安全组件来自动构建网络。

    Method and System for Location-Based Dynamic Radio Selection
    6.
    发明申请
    Method and System for Location-Based Dynamic Radio Selection 有权
    基于位置的动态无线电选择方法与系统

    公开(公告)号:US20140066076A1

    公开(公告)日:2014-03-06

    申请号:US14010010

    申请日:2013-08-26

    CPC classification number: H04W36/32 H04W36/30 H04W48/18

    Abstract: A multi-radio mobile device comprises a plurality of different radios. When a location update occurs, the multi-radio mobile device, at a specific location, acquires location-based radio information from a remote location server. The multi-radio mobile device selects a radio for use in the specific location based on the acquired location-based radio information comprising available radios in the specific location and radio weights. The radio is selected from the available radios based on the radio weights in the specific location. Transmissions of a desired service are received in the specific location utilizing the selected radio. Location-based radio measurements reports to the remote location server are generated utilizing signal strength measurements for the received signals. Radio quality information of the available radios is calculated by the location server utilizing location-based radio measurement reports from associated users. The radio weights of the available radios are determined based on the calculated radio quality information.

    Abstract translation: 多无线电移动设备包括多个不同的无线电。 当发生位置更新时,在特定位置的多无线电移动设备从远程位置服务器获取基于位置的无线电信息。 多无线电移动设备基于所获取的基于位置的无线电信息选择在特定位置使用的无线电,所述无线电信息包括在特定位置和无线电权重中的可用无线电。 基于特定位置的无线电权重从可用的无线电中选择无线电。 使用所选择的无线电在特定位置接收期望业务的传输。 利用对接收信号的信号强度测量,产生到远程位置服务器的基于位置的无线电测量报告。 可用无线电的无线电质量信息由位置服务器利用来自相关用户的基于位置的无线电测量报告来计算。 可用无线电的无线电权重基于所计算的无线电质量信息来确定。

    Hardware Isolated Secure Processing System Within A Secure Element
    7.
    发明申请
    Hardware Isolated Secure Processing System Within A Secure Element 有权
    安全元件内的硬件隔离安全处理系统

    公开(公告)号:US20160078223A1

    公开(公告)日:2016-03-17

    申请号:US14949306

    申请日:2015-11-23

    Abstract: Systems and methods are provided that allow a secure processing system (SPS) to be implemented as a hard macro, thereby isolating the SPS from a peripheral processing system (PPS). The SPS and the PPS, combination, may form a secure element that can be used in conjunction with a host device and a connectivity device to allow the host device to engage in secure transactions, such as mobile payment over a near field communications (NFC) connection. As a result of the SPS being implemented as a hard macro isolated from the PPS, the SPS may be certified once, and re-used in other host devices without necessitating re-certification.

    Abstract translation: 提供了允许将安全处理系统(SPS)实现为硬宏的系统和方法,从而将SPS与外围处理系统(PPS)隔离。 SPS和PPS的组合可以形成可以与主机设备和连接设备结合使用的安全元件,以允许主机设备进行安全交易,例如通过近场通信(NFC)的移动支付, 连接。 由于SPS被作为与PPS隔离的硬宏实现,SPS可以被认证一次,并且在其他主机设备中重新使用,而不需要重新认证。

    Systems and Methods for Detecting and Preventing Optical Attacks
    9.
    发明申请
    Systems and Methods for Detecting and Preventing Optical Attacks 有权
    检测和防止光学攻击的系统和方法

    公开(公告)号:US20150364433A1

    公开(公告)日:2015-12-17

    申请号:US14715208

    申请日:2015-05-18

    Abstract: The present disclosure outlines various systems and methods for detecting an optical fault injection within an electronic device and/or preventing the optical fault injection from introducing an exploitable abnormality within the electronic device. These various systems and methods can include systems and methods that can detect or prevent laser injection attacks, which can include one or more small footprint complementary metal oxide silicon (CMOS) light detection circuits, or structures that can shield one or more transistors from a bottom side laser injection attack.

    Abstract translation: 本公开概述了用于检测电子设备内的光学故障注入和/或防止光学故障注入在电子设备内引入可利用的异常的各种系统和方法。 这些各种系统和方法可以包括可以检测或防止激光注入攻击的系统和方法,其可以包括一个或多个小尺寸互补的金属氧化物硅(CMOS)光检测电路或可以从底部屏蔽一个或多个晶体管的结构 侧面激光注射攻击。

    Universal Authentication Token
    10.
    发明申请

    公开(公告)号:US20140344160A1

    公开(公告)日:2014-11-20

    申请号:US14285228

    申请日:2014-05-22

    Inventor: Mark BUER

    Abstract: A universal authentication token is configured to securely acquire security credentials from other authentication tokens and/or devices. In this manner, a single universal authentication token can store the authentication credentials required to access a variety of resources, services and applications for a user. The universal authentication token includes a user interface, memory for storing a plurality of authentication records for a user, and a secure processor. The secure processor provides the required cryptographic operations to encrypt, decrypt, and/or authenticate data that is sent or received by universal token. For example, secure processor may be used to generate authentication data from seed information stored in memory.

Patent Agency Ranking