Hashing prefix-free values in a signature scheme

    公开(公告)号:US09698993B2

    公开(公告)日:2017-07-04

    申请号:US14477073

    申请日:2014-09-04

    Applicant: Certicom Corp.

    CPC classification number: H04L9/3252 H04L9/3242 H04L9/3268

    Abstract: Methods, systems, and computer programs for producing hash values are disclosed. A prefix-free value is obtained based on input data. The prefix-free value can be based on an implicit certificate, a message to be signed, a message to be verified, or other suitable information. A hash value is obtained by applying a hash function to the prefix-free value. The hash value is used in a cryptographic scheme. In some instances, a public key or a private key is generated based on the hash value. In some instances, a digital signature is generated based on the hash value, or a digital signature is verified based on the hash value, as appropriate.

    AUTHENTICATED ENCRYPTION METHOD USING WORKING BLOCKS
    4.
    发明申请
    AUTHENTICATED ENCRYPTION METHOD USING WORKING BLOCKS 有权
    使用工作块的认证加密方法

    公开(公告)号:US20140146964A1

    公开(公告)日:2014-05-29

    申请号:US13793810

    申请日:2013-03-11

    CPC classification number: H04L9/30 H04L9/0637 H04L9/0643 H04L2209/125

    Abstract: A computer-implemented authenticated encryption method for converting a plaintext message into a ciphertext message. The method includes dividing the plaintext message into at least two working blocks, each working block having a mathematical relationship to the plaintext message. For each working block, a working block ciphertext is computed as a function of such working block, a deterministic working block initialization vector, and a deterministic working block encryption key. For each working block, a message authentication tag is computed as a function of a deterministic working block message authentication key and at least one of (a) the working block ciphertext computed for such working block and an indication corresponding to the mathematical relationship of such working block to the plaintext message and (b) such working block. The method further includes computing a global message authentication tag as a function of the message authentication tag computed for each working block and a global message authentication key. The ciphertext message comprises the working block ciphertext computed for each working block and the global message authentication tag.

    Abstract translation: 一种用于将明文消息转换成密文消息的计算机实现的认证加密方法。 该方法包括将明文消息划分成至少两个工作块,每个工作块与明文消息具有数学关系。 对于每个工作块,计算工作块密文作为这种工作块,确定性工作块初始化向量和确定性工作块加密密钥的函数。 对于每个工作块,消息认证标签被计算为确定性工作块消息认证密钥的函数,并且(a)为这种工作块计算的工作块密文和对应于这种工作块的数学关系的指示中的至少一个 阻止明文消息,(b)这样的工作块。 该方法还包括根据为每个工作块计算的消息认证标签和全局消息认证密钥来计算全局消息认证标签。 密文消息包括为每个工作块和全局消息认证标签计算的工作块密文。

    System and Method of Lawful Access to Secure Communications
    7.
    发明申请
    System and Method of Lawful Access to Secure Communications 有权
    合法访问安全通信的系统和方法

    公开(公告)号:US20130182840A1

    公开(公告)日:2013-07-18

    申请号:US13739620

    申请日:2013-01-11

    CPC classification number: H04L63/306 H04L9/0861 H04L2209/80

    Abstract: The present disclosure relates to systems and methods for secure communications. In some aspects, a method of signalling an interception time period is described. At least one keying information used by a KMF to regenerate a key is stored. A start_interception message is signaled from an ADMF to a CSCF. A halt_message is signaled from the ADMF to the CSCF.

    Abstract translation: 本公开涉及用于安全通信的系统和方法。 在一些方面,描述了用于发信号通知截取时间段的方法。 KMF用于重新生成密钥的至少一个密钥信息被存储。 从ADMF向CSCF发送start_interception消息。 从ADMF向CSCF发出halt_message信号。

    HTTP layer countermeasures against blockwise chosen boundary attack
    10.
    发明授权
    HTTP layer countermeasures against blockwise chosen boundary attack 有权
    HTTP层对抗屏蔽选择边界攻击的对策

    公开(公告)号:US08996855B2

    公开(公告)日:2015-03-31

    申请号:US13676730

    申请日:2012-11-14

    CPC classification number: H04L63/0428 H04L63/0823 H04L63/166

    Abstract: A client application, when executed by a processor, is operative to create a HyperText Transfer Protocol (HTTP) request containing a target header that includes a confidential value. The HTTP request is to be sent over a Secure Sockets Layer (SSL) 3.0 connection or a Transport Layer Security (TLS) 1.0 connection to a web server. The client application implements at its HTTP layer a countermeasure to a blockwise chosen-boundary attack. The client application generates an additional header having a header name that is not recognizable by the web server and inserts the additional header into the HTTP request ahead of the target header, thus creating a modified HTTP request. The modified HTTP request is to be sent, instead of the unmodified HTTP request, over the SSL 3.0 connection or the TLS 1.0 connection to the web server.

    Abstract translation: 当由处理器执行时,客户端应用程序可操作以创建包含包含机密值的目标报头的超文本传输​​协议(HTTP)请求。 HTTP请求将通过安全套接字层(SSL)3.0连接或传输层安全(TLS)1.0连接发送到Web服务器。 客户端应用程序在其HTTP层实现了对块选择边界攻击的对策。 客户机应用程序生成一个额外的标头,其标题名称不能由Web服务器识别,并将附加标头插入到目标标题之前的HTTP请求中,从而创建修改的HTTP请求。 修改的HTTP请求将通过SSL 3.0连接或与服务器的TLS 1.0连接发送,而不是未修改的HTTP请求。

Patent Agency Ranking