METHOD AND SYSTEM OF USER AUTHENTICATION USING A PORTABLE AUTHENTICATOR
    3.
    发明申请
    METHOD AND SYSTEM OF USER AUTHENTICATION USING A PORTABLE AUTHENTICATOR 有权
    使用便携式认证机构的用户认证方法和系统

    公开(公告)号:US20120233681A1

    公开(公告)日:2012-09-13

    申请号:US13423966

    申请日:2012-03-19

    IPC分类号: H04L9/32

    摘要: Systems and methods are provided for facilitating access to an electronic device. Password information is stored on the electronic device, and on a portable authenticator. When a user attempts to access the electronic device, the user is prompted to enter a password at the electronic device. The portable authenticator determines the validity of the entered password. The electronic device receives the results of the validity determination from the portable authenticator, and provides access to the electronic device based on the received validity determination.

    摘要翻译: 提供了系统和方法以便于访问电子设备。 密码信息存储在电子设备和便携式认证器上。 当用户尝试访问电子设备时,提示用户在电子设备处输入密码。 便携式验证器确定输入密码的有效性。 电子设备从便携式认证器接收有效性确定的结果,并且基于所接收的有效性确定提供对电子设备的访问。

    System and method for enabling bulk retrieval of certificates
    4.
    发明授权
    System and method for enabling bulk retrieval of certificates 有权
    允许批量检索证书的系统和方法

    公开(公告)号:US08904170B2

    公开(公告)日:2014-12-02

    申请号:US13613069

    申请日:2012-09-13

    IPC分类号: H04L29/06 H04L9/32

    摘要: A system and method for searching and retrieving certificates, which may be used in the processing of encoded messages. In one embodiment, a certificate synchronization application is programmed to perform certificate searches by querying one or more certificate servers for all of the certificates on those certificate servers. If all of the certificates on a certificate server cannot be successfully retrieved using a single search query, due to a search quota on the certificate server being exceeded for example, the search is re-performed through multiple queries, each corresponding to a narrower subsearch. Embodiments described herein enable large amounts of certificates to be automatically searched for and retrieved from certificate servers, thereby minimizing the need for users to manually search for individual certificates.

    摘要翻译: 用于搜索和检索证书的系统和方法,其可以用于编码消息的处理。 在一个实施例中,证书同步应用程序被编程为通过向一个或多个证书服务器查询那些证书服务器上的所有证书来执行证书搜索。 如果证书服务器上的所有证书都无法使用单个搜索查询成功检索,因为例如超过了证书服务器上的搜索配额,则通过多个查询重新执行搜索,每个查询对应于较窄的子搜索。 本文描述的实施例能够从证书服务器自动搜索和检索大量证书,从而最小化对用户手动搜索单个证书的需要。

    METHOD AND DEVICE FOR SECURE NOTIFICATION OF IDENTITY
    7.
    发明申请
    METHOD AND DEVICE FOR SECURE NOTIFICATION OF IDENTITY 有权
    用于安全通知身份的方法和设备

    公开(公告)号:US20130145153A1

    公开(公告)日:2013-06-06

    申请号:US13566252

    申请日:2012-08-03

    IPC分类号: H04L29/06

    CPC分类号: H04L63/0823 G06F21/6263

    摘要: A system, methods and devices for the secure notification of an identity in a communications network. The methods include sending or receiving a communication including a hash of a certificate of a device to notify or detect the presence of the device in a network. Each certificate is associated with an identity which is excluded from the communication of the hash of the certificate. The received hash is compared to hashes of certificates stored in an electronic device to determine an identity. The identity may represent an electronic device or a user of the electronic device.

    摘要翻译: 用于通信网络中的身份的安全通知的系统,方法和设备。 所述方法包括发送或接收包括设备的证书的散列的通信,以通知或检测网络中设备的存在。 每个证书与从证书的散列通信中排除的身份相关联。 将接收到的散列与存储在电子设备中的证书的散列进行比较以确定身份。 身份可以表示电子设备或电子设备的用户。

    Method and device for secure notification of identity
    8.
    发明授权
    Method and device for secure notification of identity 有权
    用于安全通知身份的方法和设备

    公开(公告)号:US08826008B2

    公开(公告)日:2014-09-02

    申请号:US13566252

    申请日:2012-08-03

    IPC分类号: H04L9/32

    CPC分类号: H04L63/0823 G06F21/6263

    摘要: A system, methods and devices for the secure notification of an identity in a communications network. The methods include sending or receiving a communication including a hash of a certificate of a device to notify or detect the presence of the device in a network. Each certificate is associated with an identity which is excluded from the communication of the hash of the certificate. The received hash is compared to hashes of certificates stored in an electronic device to determine an identity. The identity may represent an electronic device or a user of the electronic device.

    摘要翻译: 用于通信网络中的身份的安全通知的系统,方法和设备。 所述方法包括发送或接收包括设备的证书的散列的通信,以通知或检测网络中设备的存在。 每个证书与从证书的散列通信中排除的身份相关联。 将接收到的散列与存储在电子设备中的证书的散列进行比较以确定身份。 身份可以表示电子设备或电子设备的用户。

    Trusted Certificate Authority to Create Certificates Based on Capabilities of Processes
    9.
    发明申请
    Trusted Certificate Authority to Create Certificates Based on Capabilities of Processes 有权
    基于进程能力创建证书的可信证书颁发机构

    公开(公告)号:US20130166907A1

    公开(公告)日:2013-06-27

    申请号:US13336217

    申请日:2011-12-23

    IPC分类号: H04L9/32

    摘要: A device certificate binds an identity of a first device to a public key of the first device. The first device comprises a certificate authority service that creates for a process on the first device a process certificate certifying one or more capabilities of the process on the first device. The process certificate is presented to the second device. Upon validating the process certificate using the device certificate, the second device permits the process on the first device to have on the second device one or more of the verified certified capabilities.

    摘要翻译: 设备证书将第一设备的标识绑定到第一设备的公钥。 第一设备包括证书授权服务,其为第一设备上的过程创建证明第一设备上的过程的一个或多个能力的过程证书。 过程证书被呈现给第二设备。 在使用设备证书验证过程证书时,第二设备允许第一设备上的过程在第二设备上具有经验证的认证能力中的一个或多个。

    Derived certificate based on changing identity
    10.
    发明授权
    Derived certificate based on changing identity 有权
    基于变化身份的衍生证书

    公开(公告)号:US08843740B2

    公开(公告)日:2014-09-23

    申请号:US13310356

    申请日:2011-12-02

    IPC分类号: H04L29/06 H04L9/32

    摘要: A first device with a changing identity establishes a secure connection with a second device in a network by acting as its own certificate authority. The first device issues itself a self-signed root certificate that binds an identity of the first device to a long-term public key of the first device. The root certificate is digitally signed using a long-term private key, where the long-term public key and the long-term private key form a public/private key pair. The first device provides its root certificate to the second device in any trusted manner. The first device can then create a certificate for one or more short-term identities acquired by the first device and sign the newly-created certificate using the long-term private key. The first device can authenticate itself to the second device by sending the newly-created certificate to the second device.

    摘要翻译: 具有变化的身份的第一个设备通过充当其自己的证书颁发机构来建立与网络中的第二设备的安全连接。 第一个设备发布自身签名的根证书,将第一个设备的标识绑定到第一个设备的长期公钥。 根证书使用长期私钥进行数字签名,其中长期公钥和长期私钥形成公钥/私钥对。 第一个设备以任何可信的方式将其根证书提供给第二个设备。 然后,第一个设备可以为第一个设备获取的一个或多个短期身份创建证书,并使用长期私钥对新创建的证书进行签名。 第一个设备可以通过将新创建的证书发送到第二个设备来认证自己到第二个设备。