Method and apparatus for providing efficient management of certificate revocation
    3.
    发明授权
    Method and apparatus for providing efficient management of certificate revocation 有权
    提供有效管理证书撤销的方法和装置

    公开(公告)号:US09083535B2

    公开(公告)日:2015-07-14

    申请号:US13882812

    申请日:2010-11-05

    IPC分类号: H04L9/32 H04L29/06

    摘要: A method for providing efficient management of certificate revocation may comprise storing a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator, storing a witness value in association with at least some entries in the revocation list in which the witness value provides proof of the membership or non-membership of an identifier in the revocation list, enabling generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list, and enabling batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a value generated based on elements added to the revocation list to a value generated based on elements deleted from the revocation list. A corresponding apparatus is also provided. A method for certificate authorities (CA) that use Bloom filters for certificate revocation list (CRL) compression that enables the CA to hash only the entry that is to be un-revoked so that a good compression rate may be provided while avoiding computation of the entire CRL for each un-revocation.

    摘要翻译: 用于提供证书吊销的有效管理的方法可以包括存储数字证书的标识符列表,包括定义撤消证书的列表的撤销列表在累加器中,存储与撤销列表中的至少一些条目相关联的证人值, 证人值提供了撤销列表中的标识符的成员身份证明或非成员身份证明,能够响应于撤销列表中的条目的每次插入或删除而生成新的累加器和新的证人值,并且允许批量更新 所述撤销列表使用基于基于添加到撤销列表的元素生成的值与基于从撤销列表中删除的元素生成的值而生成的缩减比特长度值。 还提供了相应的装置。 一种使用布隆过滤器进行证书吊销列表(CRL)压缩的证书颁发机构(CA)的方法,该方法使CA只能对未撤销的条目进行散列,以便可以提供良好的压缩率,同时避免计算 每个撤销的整个CRL。

    METHOD AND APPARATUS FOR PROVIDING EFFICIENT MANAGEMENT OF CERTIFICATE REVOCATION
    4.
    发明申请
    METHOD AND APPARATUS FOR PROVIDING EFFICIENT MANAGEMENT OF CERTIFICATE REVOCATION 有权
    提供有效管理认证证书的方法和设备

    公开(公告)号:US20130238897A1

    公开(公告)日:2013-09-12

    申请号:US13882812

    申请日:2010-11-05

    IPC分类号: H04L9/32

    摘要: A method for providing efficient management of certificate revocation may comprise storing a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator, storing a witness value in association with at least some entries in the revocation list in which the witness value provides proof of the membership or non-membership of an identifier in the revocation list, enabling generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list, and enabling batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a value generated based on elements added to the revocation list to a value generated based on elements deleted from the revocation list. A corresponding apparatus is also provided. A method for certificate authorities (CA) that use Bloom filters for certificate revocation list (CRL) compression that enables the CA to hash only the entry that is to be un-revoked so that a good compression rate may be provided while avoiding computation of the entire CRL for each un-revocation.

    摘要翻译: 用于提供证书吊销的有效管理的方法可以包括存储数字证书的标识符列表,包括定义撤消证书的列表的撤销列表在累加器中,存储与撤销列表中的至少一些条目相关联的证人值, 证人值提供了撤销列表中的标识符的成员身份证明或非成员身份证明,能够响应于撤销列表中的条目的每次插入或删除而生成新的累加器和新的证人值,并且允许批量更新 所述撤销列表使用基于基于添加到撤销列表的元素生成的值与基于从撤销列表中删除的元素生成的值而生成的缩减比特长度值。 还提供了相应的装置。 一种使用布隆过滤器进行证书吊销列表(CRL)压缩的证书颁发机构(CA)的方法,该方法使CA只能对未撤销的条目进行散列,以便可以提供良好的压缩率,同时避免计算 每个撤销的整个CRL。

    METHODS AND APPARATUS FOR AUTHENTICATION
    5.
    发明申请
    METHODS AND APPARATUS FOR AUTHENTICATION 有权
    验证方法和设备

    公开(公告)号:US20140019763A1

    公开(公告)日:2014-01-16

    申请号:US13547512

    申请日:2012-07-12

    IPC分类号: H04L9/32

    摘要: Message authentication in an ad-hoc network. Upon creation of a message, a message authentication code is created using a key shared with members of a group comprising a subset of nodes of the ad-hoc network. The message authentication code may be created using a cryptographic process having the message and a message identifier as inputs. After or in parallel with broadcast of the message, a pointer to the message is broadcast. The message authentication code is publicly broadcast and those members of the group among which the key has been shared are able to authenticate the message as coming from a particular sender.

    摘要翻译: 在ad-hoc网络中的消息认证。 在创建消息时,使用与包括ad-hoc网络的节点的子集的组的成员共享的密钥来创建消息认证码。 可以使用具有消息的密码处理和消息标识符作为输入来创建消息认证码。 在消息的广播之后或与广播并行,广播指向消息的指针。 消息认证码被公开广播,并且其中已经共享密钥的组的成员能够将消息认证为来自特定发送者。

    METHODS, APPARATUSES, SYSTEM, AND RELATED COMPUTER PROGRAM PRODUCTS FOR HANDOVER SECURITY
    6.
    发明申请
    METHODS, APPARATUSES, SYSTEM, AND RELATED COMPUTER PROGRAM PRODUCTS FOR HANDOVER SECURITY 有权
    方法,装置,系统和相关的计算机程序产品用于切换安全

    公开(公告)号:US20110201337A1

    公开(公告)日:2011-08-18

    申请号:US12809959

    申请日:2008-12-08

    IPC分类号: H04W36/00

    摘要: It is disclosed a method comprising receiving, prior to a handover operation, first key indication information, creating, prior to the handover operation, key information based on the received first key indication information, retaining the created key information, sending, after the handover operation, the received first key indication information associated with the key information created prior to the handover operation, and retrieving, after the handover operation, the retained key information based on the first key indication information; and a method comprising generating, prior to the handover operation, the first key indication information associated with key information intended to be created, sending, prior to the handover operation, the generated first key indication information, and receiving, after the handover operation, second key indication information corresponding to the generated first key indication information.

    摘要翻译: 公开了一种方法,包括在切换操作之前接收第一密钥指示信息,在切换操作之前,基于接收的第一密钥指示信息创建密钥信息,保留所创建的密钥信息,在切换操作之后发送 所接收的与切换操作之前创建的密钥信息相关联的第一密钥指示信息,以及在切换操作之后,基于第一密钥指示信息检索保留的密钥信息; 以及一种方法,包括在切换操作之前生成与要生成的密钥信息相关联的第一密钥指示信息,在切换操作之前发送生成的第一密钥指示信息,以及在切换操作之后接收第二密钥指示信息 与所生成的第一密钥指示信息对应的密钥指示信息。

    Methods, apparatuses, system, and related computer program products for handover security
    7.
    发明授权
    Methods, apparatuses, system, and related computer program products for handover security 有权
    方法,设备,系统和相关的计算机程序产品,用于切换安全

    公开(公告)号:US08331906B2

    公开(公告)日:2012-12-11

    申请号:US12809959

    申请日:2008-12-08

    IPC分类号: H04M1/66

    摘要: It is disclosed a method comprising receiving, prior to a handover operation, first key indication information, creating, prior to the handover operation, key information based on the received first key indication information, retaining the created key information, sending, after the handover operation, the received first key indication information associated with the key information created prior to the handover operation, and retrieving, after the handover operation, the retained key information based on the first key indication information; and a method comprising generating, prior to the handover operation, the first key indication information associated with key information intended to be created, sending, prior to the handover operation, the generated first key indication information, and receiving, after the handover operation, second key indication information corresponding to the generated first key indication information.

    摘要翻译: 公开了一种方法,包括在切换操作之前接收第一密钥指示信息,在切换操作之前,基于接收的第一密钥指示信息创建密钥信息,保留所创建的密钥信息,在切换操作之后发送 所接收的与切换操作之前创建的密钥信息相关联的第一密钥指示信息,以及在切换操作之后,基于第一密钥指示信息检索保留的密钥信息; 以及一种方法,包括在切换操作之前生成与要生成的密钥信息相关联的第一密钥指示信息,在切换操作之前发送生成的第一密钥指示信息,以及在切换操作之后接收第二密钥指示信息 与所生成的第一密钥指示信息对应的密钥指示信息。

    Methods and apparatus for authentication
    9.
    发明授权
    Methods and apparatus for authentication 有权
    认证方法和设备

    公开(公告)号:US09210578B2

    公开(公告)日:2015-12-08

    申请号:US13547512

    申请日:2012-07-12

    IPC分类号: H04L29/06 H04W12/10 H04W84/18

    摘要: Message authentication in an ad-hoc network. Upon creation of a message, a message authentication code is created using a key shared with members of a group comprising a subset of nodes of the ad-hoc network. The message authentication code may be created using a cryptographic process having the message and a message identifier as inputs. After or in parallel with broadcast of the message, a pointer to the message is broadcast. The message authentication code is publicly broadcast and those members of the group among which the key has been shared are able to authenticate the message as coming from a particular sender.

    摘要翻译: 在ad-hoc网络中的消息认证。 在创建消息时,使用与包括ad-hoc网络的节点的子集的组的成员共享的密钥来创建消息认证码。 可以使用具有消息的密码处理和消息标识符作为输入来创建消息认证码。 在消息的广播之后或与广播并行,广播指向消息的指针。 消息认证码被公开广播,并且其中已经共享密钥的组的成员能够将消息认证为来自特定发送者。

    METHOD AND APPARATUS FOR CONTEXT BASED ON SPATIAL TRAILS
    10.
    发明申请
    METHOD AND APPARATUS FOR CONTEXT BASED ON SPATIAL TRAILS 审中-公开
    基于空间轨迹的方法和装置

    公开(公告)号:US20120172050A1

    公开(公告)日:2012-07-05

    申请号:US12980864

    申请日:2010-12-29

    IPC分类号: H04W4/02

    摘要: Techniques for determining context based on a spatial trail include determining data that indicates a first trail comprising a plurality of locations of finite spatial granularity at a corresponding plurality of times. The techniques also comprise determining data that indicates at least one criterion for belonging in a group. The criterion indicates a first spatial granularity for at least a first location at a corresponding first time in the first trail. The techniques further comprise determining whether a particular entity belongs in the group based, at least in part, on the criterion and a second trail for the particular entity. A trail for any entity comprises a plurality of locations of finite spatial granularity indicating actual locations of the entity at a corresponding plurality of times.

    摘要翻译: 用于基于空间轨迹确定上下文的技术包括:在相应的多次中确定指示包括有限空间粒度的多个位置的第一轨迹的数据。 这些技术还包括确定表示属于一个组的至少一个标准的数据。 该标准表示在第一个跟踪中相应的第一时间的至少第一个位置的第一个空间粒度。 所述技术还包括至少部分地基于标准来确定特定实体是否属于所述组,以及针对所述特定实体确定第二跟踪。 任何实体的跟踪包括指示实体在相应多次的实际位置的有限空间粒度的多个位置。