Data output method, system and apparatus
    1.
    发明申请
    Data output method, system and apparatus 有权
    数据输出方式,系统和装置

    公开(公告)号:US20050102512A1

    公开(公告)日:2005-05-12

    申请号:US10664069

    申请日:2003-09-16

    摘要: Data to be output to a removable storage medium is encrypted for sending to an output device by an encryption process based on encryption parameters comprising public data of a trusted party and an encryption key string comprising a policy for allowing the output of the data. The trusted party provides a decryption key to the output device but only after being satisfied that the policy has been met. The decryption key is generated in dependence on the encryption key string and private data of the trusted party. The output device uses the decryption key in decrypting the data to be output. Embodiments are provided that involve multiple policies and trusted parties.

    摘要翻译: 要输出到可移动存储介质的数据被加密,用于通过基于包括可信方的公共数据的加密参数的加密处理和包括用于允许输出数据的策略的加密密钥串来发送到输出设备。 可信方向输出设备提供解密密钥,但只有在满足该策略已被满足之后。 解密密钥根据加密密钥串和可信方的专用数据生成。 输出设备在解密要输出的数据时使用解密密钥。 提供涉及多个策略和受信任方的实施例。

    Smartcard with cryptographic functionality and method and system for using such cards
    2.
    发明申请
    Smartcard with cryptographic functionality and method and system for using such cards 审中-公开
    具有加密功能的智能卡以及使用这种卡的方法和系统

    公开(公告)号:US20050102523A1

    公开(公告)日:2005-05-12

    申请号:US10982500

    申请日:2004-11-05

    摘要: A smartcard is provided that stores a secret associated with the user of the card. The smartcard is arranged to map an input string to a first element of an algebraic group according to a known mapping function, to multiply the first element by the stored secret to form a second element of the same algebraic group such that there exists a computable bilinear map for the first and second elements, and to output this second element. This selection of the limited functionality of the smartcard enables it to be employed in the provision of a range of cryptographic services such as encryption, decryption and signature generation. The smartcard is therefore suitable for use in an organisation where multiple cryptographic services are required.

    摘要翻译: 提供了一种智能卡,其存储与卡的用户相关联的秘密。 智能卡被安排为根据已知的映射函数将输入字符串映射到代数组的第一元素,以将第一元素乘以存储的秘密以形成相同代数组的第二元素,使得存在可计算的双线性 映射第一个和第二个元素,并输出第二个元素。 智能卡的有限功能的这种选择使其能够用于提供一系列加密服务,例如加密,解密和签名生成。 因此,智能卡适用于需要多个加密服务的组织。

    Secure provision of image data
    3.
    发明申请
    Secure provision of image data 审中-公开
    安全提供图像数据

    公开(公告)号:US20050060545A1

    公开(公告)日:2005-03-17

    申请号:US10941262

    申请日:2004-09-14

    摘要: A method and apparatus are provided for the secure provision of payload data that comprises image data representing an image. The payload data is encrypted using encryption parameters comprising public data of a trusted party and an encryption key string. The encryption key string comprises thumbnail data that represents a low-resolution version of the image represented by the image data. The encryption key string preferably also comprises at least one condition to be met before the trusted party releases a decryption key for decrypting the encrypted payload data; advantageously, the apparatus enables a user to select, via a user interface, one or more conditions for incorporation into the encryption key string. The functionality for generating the thumbnail data, for choosing the conditions to be used for the encryption key string, and for encrypting the payload data is preferably incorporated into a physical add-in module such as a PCMCIA card.

    摘要翻译: 提供了一种用于安全提供包括表示图像的图像数据的有效载荷数据的方法和装置。 使用包括可信方的公共数据和加密密钥串的加密参数对有效载荷数据进行加密。 加密密钥串包括表示由图像数据表示的图像的低分辨率版本的缩略图数据。 加密密钥串优选地还包括在可信方释放用于解密加密的有效载荷数据的解密密钥之前要满足的至少一个条件; 有利地,该装置使得用户能够经由用户界面选择用于并入加密密钥串的一个或多个条件。 用于生成缩略图数据的功能,用于选择用于加密密钥串的条件和用于加密有效载荷数据的功能优选地并入到诸如PCMCIA卡的物理附加模块中。

    Privacy management of personal data
    4.
    发明申请
    Privacy management of personal data 有权
    个人资料的隐私管理

    公开(公告)号:US20050039031A1

    公开(公告)日:2005-02-17

    申请号:US10767868

    申请日:2004-01-28

    IPC分类号: H04L9/30 H04L29/06 H04L9/32

    摘要: When sending personal data to a recipient, the data owner encrypts the data using both a public data item provided by a trusted party and an encryption key string formed using at least policy data indicative of conditions to be satisfied before access is given to the personal data. The encryption key string is typically also provided to the recipient along with the encrypted personal data. To decrypt the personal data, the recipient sends the encryption key string to the trusted party with a request for the decryption key. The trusted party determines the required decryption key using the encryption key string and private data used in deriving its public data, and provides it to the requesting recipient. However, the decryption key is either not determined or not made available until the trusted party is satisfied that the associated policy conditions have been met by the recipient.

    摘要翻译: 当向收件人发送个人数据时,数据所有者使用由受信任方提供的公共数据项和至少指示在将个人数据访问之前要满足的条件的策略数据形成的加密密钥串来加密数据 。 加密密钥字符串通常也与加密的个人数据一起提供给接收者。 为了解密个人数据,接收方通过请求解密密钥将加密密钥字符串发送给信任方。 可信方使用加密密钥串和用于导出其公共数据的私有数据来确定所需的解密密钥,并将其提供给请求的接收者。 然而,解密密钥在被信任方满足接收者已经满足相关联的策略条件之前,未被确定或不被提供。

    Data privacy management system and method
    5.
    发明申请
    Data privacy management system and method 审中-公开
    数据隐私管理系统和方法

    公开(公告)号:US20050251865A1

    公开(公告)日:2005-11-10

    申请号:US10972144

    申请日:2004-10-25

    摘要: A data privacy management system includes a data repository, a private data mediating system and a privacy manager. The data repository stores private data items in an obfuscated form. Each private data item has associated privacy policy data a defining conditions to be met to ensure the privacy of the data item. A private data mediating system communicates with the privacy manager to obtain de-obfuscated private data items that are extracted from the data repository 10. De-obfuscation of the data 51, 53 is subject to satisfaction of the privacy manager that the respective conditions ensuring privacy of the data item are met.

    摘要翻译: 数据隐私管理系统包括数据存储库,专用数据中介系统和隐私管理器。 数据存储库以混淆形式存储私人数据项。 每个私有数据项都具有相关联的隐私策略数据,定义要满足的条件以确保数据项的隐私。 私有数据中介系统与隐私管理器进行通信,以获得从数据储存库10提取的去混淆的私有数据项。 对数据51,53的去模糊化使得隐私管理者满意地确保满足数据项的隐私的各个条件。

    System and method for dynamically allocating resources
    6.
    发明申请
    System and method for dynamically allocating resources 有权
    动态分配资源的系统和方法

    公开(公告)号:US20060190986A1

    公开(公告)日:2006-08-24

    申请号:US11335877

    申请日:2006-01-20

    IPC分类号: H04L9/00

    摘要: A computer network has a number of resources. One or more trusted localisation provider certifies the location of the resources. Encrypted data is closely associated with a policy package defining privacy policies for the data and metapolicies for their selection. A trusted privacy service enforces the privacy policies. The trusted privacy service is arranged to supply a key to a resource to allow that resource to process data if the trusted privacy service determines from the trusted localisation provider certifying the location and other contextual information of the resource that the privacy policy allows processing of the data on that resource in that location.

    摘要翻译: 计算机网络具有许多资源。 一个或多个受信任的本地化提供商证明资源的位置。 加密数据与定义用于选择的数据和元数据的隐私策略的策略包密切相关。 值得信赖的隐私服务强制执行隐私政策。 信任的隐私服务被设置为向资源提供密钥以允许该资源处理数据,如果可信赖的隐私服务从可信定位提供者确定认证该资源的位置和其他上下文信息,该隐私策略允许处理数据 在该位置的资源上。

    Image capture
    7.
    发明申请
    Image capture 审中-公开
    图像捕获

    公开(公告)号:US20050237397A1

    公开(公告)日:2005-10-27

    申请号:US11114525

    申请日:2005-04-26

    摘要: Method and apparatus for enabling an imaging function of a mobile device in areas where use of such imaging functions is prohibited, including registering image data in the device in order to determine if such data relates to the image of a face of a user of the device, and on the basis of the determination, enabling an imaging function of the device proper.

    摘要翻译: 禁止使用这种成像功能的区域中的移动设备的成像功能的方法和装置,包括在设备中登记图像数据,以便确定这些数据是否与设备的用户的脸部的图像相关 ,并且在确定的基础上,使得设备的成像功能成为可能。