-
公开(公告)号:US08099781B2
公开(公告)日:2012-01-17
申请号:US12508327
申请日:2009-07-23
申请人: Kay S. Anderson , Pau-Chen Cheng , Mark D. Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent R. Jaeger , Paul Ashley Karger , Zhen Liu , Ronald Perez , Anton V. Riabov , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
发明人: Kay S. Anderson , Pau-Chen Cheng , Mark D. Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent R. Jaeger , Paul Ashley Karger , Zhen Liu , Ronald Perez , Anton V. Riabov , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
IPC分类号: H04L29/00
CPC分类号: G06F21/577
摘要: An exemplary method is provided for managing and mitigating security risks through planning. A first security-related information of a requested product is received. A second security-related information of resources that are available for producing the requested product is received. A multi-stage process with security risks managed by the first security-related information and the second security-related information is performed to produce the requested product.
摘要翻译: 提供了一种示范性的方法来通过规划来管理和减轻安全风险。 收到所请求产品的第一个安全相关信息。 接收到可用于生成请求的产品的资源的第二个安全相关信息。 执行由第一安全相关信息和第二安全相关信息管理的具有安全风险的多阶段过程以产生所请求的产品。
-
公开(公告)号:US07832007B2
公开(公告)日:2010-11-09
申请号:US11328589
申请日:2006-01-10
申请人: Kay S. Anderson , Pau-Chen Cheng , Mark D. Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent R. Jaeger , Paul Ashley Karger , Zhen Liu , Ronald Perez , Anton V. Riabov , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
发明人: Kay S. Anderson , Pau-Chen Cheng , Mark D. Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent R. Jaeger , Paul Ashley Karger , Zhen Liu , Ronald Perez , Anton V. Riabov , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
IPC分类号: H04L29/00
CPC分类号: G06F21/577
摘要: An exemplary method is provided for managing and mitigating security risks through planning. A first security-related information of a requested product is received. A second security-related information of resources that are available for producing the requested product is received. A multi-stage process with security risks managed by the first security-related information and the second security-related information is performed to produce the requested product.
摘要翻译: 提供了一种示范性的方法来通过规划来管理和减轻安全风险。 收到所请求产品的第一个安全相关信息。 接收到可用于生成请求的产品的资源的第二个安全相关信息。 执行由第一安全相关信息和第二安全相关信息管理的具有安全风险的多阶段过程以产生所请求的产品。
-
公开(公告)号:US20090282487A1
公开(公告)日:2009-11-12
申请号:US12508327
申请日:2009-07-23
申请人: Kay S. Anderson , Pau-Chen Cheng , Mark D. Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent R. Jaeger , Paul Ashley Karger , Zhen Liu , Ronald Perez , Anton V. Riabov , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
发明人: Kay S. Anderson , Pau-Chen Cheng , Mark D. Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent R. Jaeger , Paul Ashley Karger , Zhen Liu , Ronald Perez , Anton V. Riabov , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
IPC分类号: G06F11/00
CPC分类号: G06F21/577
摘要: An exemplary method is provided for managing and mitigating security risks through planning. A first security-related information of a requested product is received. A second security-related information of resources that are available for producing the requested product is received. A multi-stage process with security risks managed by the first security-related information and the second security-related information is performed to produce the requested product.
摘要翻译: 提供了一种示范性的方法来通过规划来管理和减轻安全风险。 收到所请求产品的第一个安全相关信息。 接收到可用于生成请求的产品的资源的第二个安全相关信息。 执行由第一安全相关信息和第二安全相关信息管理的具有安全风险的多阶段过程以产生所请求的产品。
-
公开(公告)号:US08087090B2
公开(公告)日:2011-12-27
申请号:US12131206
申请日:2008-06-02
申请人: Pau-Chen Cheng , Shai Halevi , Trent Ray Jaeger , Paul Ashley Karger , Ronald Perez , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
发明人: Pau-Chen Cheng , Shai Halevi , Trent Ray Jaeger , Paul Ashley Karger , Ronald Perez , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
CPC分类号: G06N7/023 , G06F21/577 , G06F21/604 , G06F21/6218 , H04L63/105
摘要: An access control system and method includes a risk index module which computes a risk index for a dimension contributing to risk. A boundary range defined for a parameter representing each risk index such that the parameter above the range is unacceptable, below the range is acceptable and in the range is acceptable with mitigation measures. A mitigation module determines the mitigation measures which reduce the parameter within the range by mapping the effectiveness of performing the mitigation measures to determine a residual risk after a mitigation measure has been implemented.
摘要翻译: 访问控制系统和方法包括风险指数模块,其计算用于风险的维度的风险指数。 为表示每个风险指数的参数定义的边界范围,使得高于该范围的参数是不可接受的,低于该范围是可接受的,并且在该范围内可以用缓解措施来接受。 缓解模块通过绘制执行缓解措施的有效性来确定缓解措施实施后的剩余风险,确定减少范围内的参数的缓解措施。
-
公开(公告)号:US07530110B2
公开(公告)日:2009-05-05
申请号:US11123998
申请日:2005-05-06
申请人: Pau-Chen Cheng , Shai Halevi , Trent Ray Jaeger , Paul Ashley Karger , Ronald Perez , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
发明人: Pau-Chen Cheng , Shai Halevi , Trent Ray Jaeger , Paul Ashley Karger , Ronald Perez , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
CPC分类号: G06N7/023 , G06F21/577 , G06F21/604 , G06F21/6218 , H04L63/105
摘要: An access control system and method includes a risk index module which computes a risk index for a dimension contributing to risk. A boundary range defined for a parameter representing each risk index such that the parameter above the range is unacceptable, below the range is acceptable and in the range is acceptable with mitigation measures. A mitigation module determines the mitigation measures which reduce the parameter within the range.
摘要翻译: 访问控制系统和方法包括风险指数模块,其计算用于风险的维度的风险指数。 为表示每个风险指数的参数定义的边界范围,使得高于该范围的参数是不可接受的,低于该范围是可接受的,并且在该范围内可以用缓解措施来接受。 缓解模块确定减少该范围内的参数的缓解措施。
-
公开(公告)号:US20080263662A1
公开(公告)日:2008-10-23
申请号:US12131206
申请日:2008-06-02
申请人: Pau-Chen Cheng , Shai Halevi , Trent Ray Jaeger , Paul Ashley Karger , Ronald Perez , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
发明人: Pau-Chen Cheng , Shai Halevi , Trent Ray Jaeger , Paul Ashley Karger , Ronald Perez , Pankaj Rohatgi , Angela Marie Schuett , Michael Steiner , Grant M. Wagner
IPC分类号: G06F21/00
CPC分类号: G06N7/023 , G06F21/577 , G06F21/604 , G06F21/6218 , H04L63/105
摘要: An access control system and method includes a risk index module which computes a risk index for a dimension contributing to risk. A boundary range defined for a parameter representing each risk index such that the parameter above the range is unacceptable, below the range is acceptable and in the range is acceptable with mitigation measures. A mitigation module determines the mitigation measures which reduce the parameter within the range.
摘要翻译: 访问控制系统和方法包括风险指数模块,其计算用于风险的维度的风险指数。 为表示每个风险指数的参数定义的边界范围,使得高于该范围的参数是不可接受的,低于该范围是可接受的,并且在该范围内可以用缓解措施来接受。 缓解模块确定减少该范围内的参数的缓解措施。
-
公开(公告)号:US20070162976A1
公开(公告)日:2007-07-12
申请号:US11328589
申请日:2006-01-10
申请人: Kay Anderson , Pau-Chen Cheng , Mark Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent Jaeger , Paul Karger , Zhen Liu , Ronald Perez , Anton Riabov , Pankaj Rohatgi , Angela Schuett , Michael Steiner , Grant Wagner
发明人: Kay Anderson , Pau-Chen Cheng , Mark Feblowitz , Genady Grabarnik , Shai Halevi , Nagui Halim , Trent Jaeger , Paul Karger , Zhen Liu , Ronald Perez , Anton Riabov , Pankaj Rohatgi , Angela Schuett , Michael Steiner , Grant Wagner
IPC分类号: G06F11/00
CPC分类号: G06F21/577
摘要: An exemplary method is provided for managing and mitigating security risks through planning. A first security-related information of a requested product is received. A second security-related information of resources that are available for producing the requested product is received. A multi-stage process with security risks managed by the first security-related information and the second security-related information is performed to produce the requested product.
摘要翻译: 提供了一种示范性的方法来通过规划来管理和减轻安全风险。 收到所请求产品的第一个安全相关信息。 接收到可用于生成请求的产品的资源的第二个安全相关信息。 执行由第一安全相关信息和第二安全相关信息管理的具有安全风险的多阶段过程以产生所请求的产品。
-
公开(公告)号:US20060253709A1
公开(公告)日:2006-11-09
申请号:US11123998
申请日:2005-05-06
申请人: Pau-Chen Cheng , Shai Halevi , Trent Jaeger , Paul Karger , Ronald Perez , Pankaj Rohatgi , Angela Schuett , Michael Steiner , Grant Wagner
发明人: Pau-Chen Cheng , Shai Halevi , Trent Jaeger , Paul Karger , Ronald Perez , Pankaj Rohatgi , Angela Schuett , Michael Steiner , Grant Wagner
IPC分类号: H04L9/00
CPC分类号: G06N7/023 , G06F21/577 , G06F21/604 , G06F21/6218 , H04L63/105
摘要: An access control system and method includes a risk index module which computes a risk index for a dimension contributing to risk. A boundary range defined for a parameter representing each risk index such that the parameter above the range is unacceptable, below the range is acceptable and in the range is acceptable with mitigation measures. A mitigation module determines the mitigation measures which reduce the parameter within the range.
-
9.
公开(公告)号:US20080049939A1
公开(公告)日:2008-02-28
申请号:US11501831
申请日:2006-08-10
申请人: Ran Canetti , Shai Halevi , Michael Steiner
发明人: Ran Canetti , Shai Halevi , Michael Steiner
IPC分类号: H04L9/00
CPC分类号: H04L9/0894 , H04L9/0863 , H04L9/3226
摘要: The invention includes a method for key creation and recovery based on solutions to puzzles solvable by humans and not computers. In some exemplary embodiments, the key is created and recovered based on the solution(s) in conjunction with the password entered by the user. The puzzle(s) is selected based on the password used by the user from a puzzle database containing multiple puzzles that is greater in number to the number of puzzles used in conjunction with a particular password.
摘要翻译: 本发明包括一种基于由人而不是计算机可解的难题解决方案进行密钥创建和恢复的方法。 在一些示例性实施例中,基于与由用户输入的密码的解决方案来创建和恢复密钥。 根据用户从拼图数据库使用的密码来选择拼图,该拼图数据库包含多个拼图,其数量大于与特定密码结合使用的拼图数量。
-
10.
公开(公告)号:US08108683B2
公开(公告)日:2012-01-31
申请号:US11501831
申请日:2006-08-10
申请人: Ran Canetti , Shai Halevi , Michael Steiner
发明人: Ran Canetti , Shai Halevi , Michael Steiner
IPC分类号: G06F21/00
CPC分类号: H04L9/0894 , H04L9/0863 , H04L9/3226
摘要: The invention includes a method for key creation and recovery based on solutions to puzzles solvable by humans and not computers. In some exemplary embodiments, the key is created and recovered based on the solution(s) in conjunction with the password entered by the user. The puzzle(s) is selected based on the password used by the user from a puzzle database containing multiple puzzles that is greater in number to the number of puzzles used in conjunction with a particular password.
摘要翻译: 本发明包括一种基于由人而不是计算机可解的难题解决方案进行密钥创建和恢复的方法。 在一些示例性实施例中,基于与由用户输入的密码的解决方案来创建和恢复密钥。 根据用户从拼图数据库使用的密码来选择拼图,该拼图数据库包含多个拼图,其数量大于与特定密码结合使用的拼图数量。
-
-
-
-
-
-
-
-
-