Authentication based on a current location of a communications device associated with an entity
    1.
    发明授权
    Authentication based on a current location of a communications device associated with an entity 有权
    基于与实体相关联的通信设备的当前位置的认证

    公开(公告)号:US08904496B1

    公开(公告)日:2014-12-02

    申请号:US13435951

    申请日:2012-03-30

    IPC分类号: G06F21/00 G06F21/44

    摘要: There is disclosed a method and system for use in authenticating an entity in connection with a computerized resource. An authentication request is received from entity for access to computerized resource. An input signal is received from a communications device associated with entity. The input signal comprises current location of communications device. The current location of communications device is derived from input signal. A location history in connection with communications device is captured. The location history comprises a record of discrete locations visited by communications device over a period of time. An analysis is performed between current location of the communications device and location history in connection with communications device. An authentication result is generated based on analysis between current location of communications device and location history in connection with communications device. The authentication result can be used for authenticating entity.

    摘要翻译: 公开了一种用于认证与计算机资源有关的实体的方法和系统。 从实体接收到对计算机资源的访问的认证请求。 从与实体相关联的通信设备接收输入信号。 输入信号包括通信设备的当前位置。 通信设备的当前位置来源于输入信号。 捕获与通信设备相关的位置历史记录。 位置历史包括通信设备在一段时间内访问的离散位置的记录。 在通信设备的当前位置和与通信设备相关的位置历史之间进行分析。 基于通信设备的当前位置和与通信设备相关的位置历史之间的分析生成认证结果。 验证结果可用于认证实体。

    Authenticating an entity
    4.
    发明授权

    公开(公告)号:US09781129B1

    公开(公告)日:2017-10-03

    申请号:US13536978

    申请日:2012-06-28

    IPC分类号: H04L29/06

    摘要: There is disclosed a method and system for use in authenticating an entity. An authentication request is received from the entity. An input signal is received from a communications device associated with the entity. The input signal comprises the current location of the communications device. The current location of the communications device is derived from the input signal. Based on the current location of the communications device, an event is detected at substantially the same location as the current location of the communications device. An analysis is performed between the current location of the communications device and the event. An authentication result is generated based on the analysis between the current location of the communications device and the event. The authentication result can be used for authenticating the entity.

    Authenticating an entity
    5.
    发明授权
    Authenticating an entity 有权
    认证一个实体

    公开(公告)号:US09405897B1

    公开(公告)日:2016-08-02

    申请号:US13538640

    申请日:2012-06-29

    摘要: There is disclosed a method and system for use in authenticating an entity. An entity location history is stored comprising a historical record of locations visited by the entity. An authentication request is received from the entity. A pattern of recent locations visited by the entity indicative of irregular behavior is detected. An analysis is performed between the pattern of recent locations indicative of irregular behavior and the entity location history for establishing the riskiness of the authentication request. An authentication result is generated based on the analysis between the pattern of recent locations indicative of irregular behavior and the entity location history.

    摘要翻译: 公开了一种用于认证实体的方法和系统。 存储实体位置历史,其包括由该实体访问的位置的历史记录。 从实体接收到认证请求。 检测到由实体访问的指示不规则行为的最近位置的模式。 在指示不规则行为的最近位置的模式和用于建立认证请求的风险的实体位置历史之间进行分析。 基于指示不规则行为的最近位置的模式与实体位置历史之间的分析,生成认证结果。

    Generation of alerts in an event management system based upon risk
    6.
    发明授权
    Generation of alerts in an event management system based upon risk 有权
    根据风险在事件管理系统中生成警报

    公开(公告)号:US09282114B1

    公开(公告)日:2016-03-08

    申请号:US13172999

    申请日:2011-06-30

    IPC分类号: G06F21/55 H04L9/00 H04L29/06

    摘要: Embodiments relate to the generation of alerts in an event management system based upon risk. When an event device associated with the event management system, presents a logon page to a client device, the event device includes a beacon as part of the page to monitor and collect web device profile characteristics related to the client device. In response to a logon attempt by the client device, an event management device receives a notification regarding logon attempt and a risk assessment associated with the web device profile characteristics of the client device. Based upon a correlation of the notification and the corresponding risk assessment, the event management device can generate an alert, such as a SIEM alert, and can include an indication of priority, whether relatively low or high, and/or a confidence factor, whether or not the alert can be suppressed as part of the alert.

    摘要翻译: 实施例涉及基于风险在事件管理系统中生成警报。 当与事件管理系统相关联的事件设备向客户端设备提供登录页面时,事件设备包括作为页面一部分的信标,以监视和收集与客户端设备相关的web设备配置文件特征。 响应于客户端设备的登录尝试,事件管理设备接收关于登录尝试的通知和与客户端设备的web设备简档特性相关联的风险评估。 基于通知的相关性和相应的风险评估,事件管理设备可以生成诸如SIEM警报的警报,并且可以包括无论相对低或高的优先级的指示和/或置信因子 或者不是可以抑制警报作为警报的一部分。

    Assessing risk for third-party data collectors
    7.
    发明授权
    Assessing risk for third-party data collectors 有权
    评估第三方数据收集者的风险

    公开(公告)号:US09230066B1

    公开(公告)日:2016-01-05

    申请号:US13534873

    申请日:2012-06-27

    IPC分类号: H04L29/00 G06F21/00

    摘要: An improved technique authenticates a user based on an ability to corroborate previous transaction data sent by a user device. Along these lines, the improved technique makes use of an independent information source for verifying the accuracy of previous transaction data obtained by a given collector. For example, when a collector of location data is a GPS unit of a cell phone, an independent information source may be a cell tower closest to the cell phone at the time of the transaction. While location data provided by the cell tower may not be as precise as that provided by the GPS unit, such data is useful for corroborating the location data from the GPS unit. In this scenario, if the data provided by the cell tower fails to corroborate that provided by the GPS unit, then the GPS unit adds significant risk to authenticating the user.

    摘要翻译: 改进的技术基于确定用户设备发送的先前交易数据的能力来认证用户。 沿着这些方式,改进的技术使用独立的信息源来验证给定收集器获得的先前交易数据的准确性。 例如,当位置数据的收集器是手机的GPS单元时,独立的信息源可以是在交易时最靠近手机的信元塔。 虽然由单元塔提供的位置数据可能不如GPS单元提供的位置数据那样精确,但是这样的数据对于确认来自GPS单元的位置数据是有用的。 在这种情况下,如果单元塔提供的数据未能证实由GPS单元提供的数据,则GPS单元增加了验证用户的重大风险。

    Validating association of client devices with sessions
    8.
    发明授权
    Validating association of client devices with sessions 有权
    验证客户端设备与会话的关联

    公开(公告)号:US08959650B1

    公开(公告)日:2015-02-17

    申请号:US13537539

    申请日:2012-06-29

    IPC分类号: G06F21/00

    CPC分类号: G06F21/44 G06F21/335

    摘要: A method is used in validating association of client devices with sessions. Information of a client device executing a user agent is gathered by a server for creating a device identifier for the client device upon receiving a request from the user agent for establishing a session between the user agent and the server. The device identifier includes information identifying the client device. The device identifier is associated with the session. The client device is validated by the server upon receiving subsequent requests from the client device during the session. Validating the client device includes gathering information of the client device sending each subsequent request for creating a device identifier for the client device and comparing the device identifier created from the information gathered during each subsequent request with the device identifier associated with the session.

    摘要翻译: 一种方法用于验证客户端设备与会话的关联。 服务器收集执行用户代理的客户端设备的信息,用于在从用户代理接收到用于在用户代理和服务器之间建立会话的请求时,为客户端设备创建设备标识符。 设备标识符包括标识客户端设备的信息。 设备标识符与会话相关联。 客户端设备在会话期间从客户端设备收到后续请求时由服务器进行验证。 验证客户端设备包括收集客户端设备的信息,发送每个后续请求,用于创建客户端设备的设备标识符,并将从每个后续请求中收集的信息创建的设备标识符与与该会话相关联的设备标识符进行比较。

    Injecting code decrypted by a hardware decryption module into Java applications
    9.
    发明授权
    Injecting code decrypted by a hardware decryption module into Java applications 有权
    将由硬件解密模块解密的代码注入Java应用程序

    公开(公告)号:US09021271B1

    公开(公告)日:2015-04-28

    申请号:US13337817

    申请日:2011-12-27

    IPC分类号: G06F11/30 G06F11/34

    CPC分类号: G06F11/34 G06F21/123

    摘要: A method is performed by a computer in communication with a hardware security module (HSM). The method includes (a) running a process virtual machine (PVM) on the computer, the PVM being configured to execute portable bytecode instructions within a PVM environment and (b) executing, within the PVM environment, instructions for (1) reading encrypted instruction code from data storage of the computer, (2) sending the encrypted instruction code to the HSM, (3) in response, receiving decrypted instruction code from the HSM, and (4) injecting the decrypted instruction code within an application running in the PVM environment for execution by the PVM. Embodiments are also directed to analogous computer program products and apparatuses.

    摘要翻译: 通过与硬件安全模块(HSM)通信的计算机执行方法。 该方法包括(a)在计算机上运行一个进程虚拟机(PVM),该PVM被配置为在PVM环境内执行便携式字节码指令,以及(b)在该PVM环境内执行(1)读取加密指令 来自计算机的数据存储的代码,(2)将加密的指令代码发送到HSM,(3)响应于从HSM接收解密的指令代码,以及(4)在PVM中运行的应用程序中注入解密的指令代码 由PVM执行的环境。 实施例还涉及类似的计算机程序产品和装置。

    Virtualization platform for secured communications between a user device and an application server
    10.
    发明授权
    Virtualization platform for secured communications between a user device and an application server 有权
    用于用户设备和应用服务器之间的安全通信的虚拟化平台

    公开(公告)号:US08694993B1

    公开(公告)日:2014-04-08

    申请号:US13077230

    申请日:2011-03-31

    IPC分类号: G06F9/455 G06F15/16

    摘要: A modular virtualization platform is provided for secured communications between a user device and an application server. A client-side computing device performs secured communications during a virtual session with an application server across a network. The client-side computing device loads a virtual machine client; and selects a remote module to serve as a virtualization server for the virtual session based on one or more performance factors. The virtual session is established with the selected module, and secured communications can occur between the client-side computing device and the application server via the virtual session of the selected module. The performance factors can be collected from a plurality of modules using a peer-to-peer gossip-based state notification process. A route list preferably stores the performance factors for a plurality of modules. The route list can contain pointers to a plurality of remote modules in a plurality of virtualization platforms, to increase reliability.

    摘要翻译: 为用户设备和应用服务器之间的安全通信提供了模块化虚拟化平台。 客户端计算设备在通过网络与应用服务器进行虚拟会话期间执行安全通信。 客户端计算设备加载虚拟机客户端; 并且基于一个或多个性能因素选择远程模块用作虚拟会话的虚拟化服务器。 利用所选择的模块建立虚拟会话,并且可以经由所选模块的虚拟会话在客户端计算设备和应用服务器之间发生安全通信。 可以使用基于点对点八卦的状态通知过程从多个模块收集性能因素。 路线列表优选地存储多个模块的性能因素。 路由列表可以包含指向多个虚拟化平台中的多个远程模块的指针,以增加可靠性。