System, method and article of manufacture for a cryptographic key infrastructure for networked devices
    2.
    发明授权
    System, method and article of manufacture for a cryptographic key infrastructure for networked devices 有权
    用于联网设备的密钥基础设施的系统,方法和制造

    公开(公告)号:US06938154B1

    公开(公告)日:2005-08-30

    申请号:US09596948

    申请日:2000-06-19

    IPC分类号: H04L9/00

    摘要: A system, method and article of manufacture are provided for secure operation of a network device. A digital certificate is assigned to a network user. A command for operation of a network device and the digital certificate are received from the network user. A cryptographic key stored in the network device is utilized to authenticate the digital certificate of the network user. Operation of the network device is enabled if the digital certificate of the network user is authenticated. According to another aspect of the present invention, a system, method and article of manufacture are provided for secure identification of a network device. A digital certificate is assigned to a network device. A command for operation of the network device is received from a network user. The digital certificate is sent to the network user. The network user utilizes a cryptographic key to authenticate the digital certificate of the network device. Operation of the network device is enabled if the digital certificate of the network device is authenticated. In another embodiment of the present invention, a system, method and article of manufacture are provided for secure management of a network device. Policy information and/or a computational protocol are associated with a command for the network device. The policy information and/or computational protocols are encrypted, sent to the network device, and decrypted. The network device utilizing the policy information and/or computational protocols processes the command.

    摘要翻译: 提供了一种用于网络设备的安全操作的系统,方法和制造。 数字证书被分配给网络用户。 从网络用户接收网络设备的操作命令和数字证书。 存储在网络设备中的加密密钥用于认证网络用户的数字证书。 如果网络用户的数字证书被认证,则启用网络设备的操作。 根据本发明的另一方面,提供了一种用于网络设备的安全识别的系统,方法和制造商品。 数字证书被分配给网络设备。 从网络用户接收到用于操作网络设备的命令。 数字证书被发送给网络用户。 网络用户利用加密密钥对网络设备的数字证书进行认证。 如果网络设备的数字证书被认证,则启用网络设备的操作。 在本发明的另一个实施例中,提供了一种用于网络设备的安全管理的系统,方法和制品。 策略信息和/或计算协议与网络设备的命令相关联。 策略信息和/或计算协议被加密,发送到网络设备并进行解密。 利用策略信息和/或计算协议的网络设备处理该命令。

    System, method and article of manufacture for transition state-based cryptography
    3.
    发明授权
    System, method and article of manufacture for transition state-based cryptography 失效
    基于过渡状态的密码学的系统,方法和制造

    公开(公告)号:US06754821B1

    公开(公告)日:2004-06-22

    申请号:US09596834

    申请日:2000-06-19

    IPC分类号: G06F1130

    摘要: A system, method and article of manufacture are provided for transition state-based cryptography in an application including at least one state having a state key associated with it. A request for access is sent to a server utilizing a network upon reaching a state in the application. The request includes a state key associated with the state. A reply is received from the server in response to the request. The reply includes an access key for providing the access if the state key is valid. According to another embodiment of the present invention, a method is provided for transition state-based cryptography in an application including at least one state having a state key associated with it. A request for access is received from a client to a server utilizing a network. The state key is verified at the server. A reply is sent from the server in response to the request. The reply includes an access key for providing the access if the state key is verified. In one aspect of the present invention, the request for access is for a subsequent state in the application.

    摘要翻译: 提供了一种用于包括具有与其相关联的状态密钥的至少一个状态的应用中的基于过渡状态的密码学的系统,方法和制品。 在达到应用程序中的状态时,利用网络将访问请求发送到服务器。 请求包括与状态相关联的状态键。 响应于该请求,从服务器接收到答复。 如果状态密钥有效,该回复包括用于提供访问的访问密钥。 根据本发明的另一实施例,提供了一种用于包括具有与其相关联的状态密钥的至少一个状态的应用中的基于过渡状态的密码术的方法。 从客户端接收到使用网络的服务器的访问请求。 在服务器上验证状态密钥。 响应请求,从服务器发送回复。 如果状态密钥被验证,该回复包括用于提供访问的访问密钥。 在本发明的一个方面,访问请求用于应用中的后续状态。

    System, method and article of manufacture for cryptoserver-based auction
    4.
    发明授权
    System, method and article of manufacture for cryptoserver-based auction 有权
    基于密码服务的拍卖的系统,方法和制造

    公开(公告)号:US06990468B1

    公开(公告)日:2006-01-24

    申请号:US09596857

    申请日:2000-06-19

    IPC分类号: G06F17/60

    摘要: A system, method, and article of manufacture are provided for pricing a cryptographic service on a network utilizing one or more cryptoservers. A request for a cryptographic service is received from a user utilizing a network. The request is received by a cryptographic service provider. A contract is generated based on a variable pricing scheme in response to the request. The contract is sent from the cryptographic service provider to the user utilizing the network. A method is also provided for auditing a security provision on a network utilizing a cryptoserver. A cryptographic key is obtained such as by obtaining it from a trusted source or generating the key. A plurality of users are allowed to request that a cryptoserver use the cryptographic key to sign a message in violation of a security provision. It is determined whether the cryptoserver signed the message in response to the request. An indication of failed security integrity is provided upon determining that the cryptographic server has signed the message.

    摘要翻译: 提供了一种系统,方法和制品,用于利用一个或多个密码服务器对网络上的加密服务进行定价。 从使用网络的用户接收对加密服务的请求。 该请求由加密服务提供商接收。 根据请求,根据可变定价方案生成合同。 合同从加密服务提供商发送到利用网络的用户。 还提供了一种用于使用密码服务器对网络上的安全性规定进行审核的方法。 获得加密密钥,例如通过从可信源获得密钥或生成密钥。 允许多个用户请求密码服务器使用加密密钥对违反安全性规定的消息进行签名。 确定密码服务器是否响应于该请求而签名该消息。 确定密码服务器已经签署了消息后,提供了安全完整性失败的指示。

    Systems and methods for policy based printing
    5.
    发明授权
    Systems and methods for policy based printing 有权
    用于基于策略的打印的系统和方法

    公开(公告)号:US07110541B1

    公开(公告)日:2006-09-19

    申请号:US09722508

    申请日:2000-11-28

    IPC分类号: H04K1/00

    摘要: A print management system includes a policy that determines a protection level for a document to be printed. The document is printed using forgery detection and deterrence technologies, such as fragile and robust watermarks, glyphs, and digital signatures, that are appropriate to the level of protection determined by the policy. A plurality of printers are managed by a print management system. Each printer can provide a range of protection technologies. The policy determines the protection technologies for the document to be printed and the print management system routes the print job to a printer that can apply the appropriate protections and sets the appropriate parameters in the printer. Copy evidence that can verify that a document is a forgery and/or tracing information that identifies the custodian(s) of the document and restrictions on copying of the document and use of the information in the document are included in the watermark that is printed with the document information. A document can be verified as an original or a forgery by inspecting the copy evidence and/or tracing information in the watermark.

    摘要翻译: 打印管理系统包括确定要打印的文档的保护等级的策略。 该文件使用伪造检测和威慑技术打印,例如脆弱和鲁棒的水印,字形和数字签名,这些技术适用于由策略确定的保护级别。 多个打印机由打印管理系统管理。 每台打印机都可以提供一系列保护技术。 该策略确定要打印的文档的保护技术,打印管理系统将打印作业路由到可应用适当保护的打印机,并在打印机中设置适当的参数。 复印证明文件是伪造的和/或跟踪信息,用于标识文档的保管人,复制文档和文档中信息的使用的限制包含在打印的水印中 文件信息。 通过检查水印中的复制证据和/或跟踪信息,可以将文档验证为原件或伪造。

    Method for enabling privacy and trust in electronic communities
    7.
    发明授权
    Method for enabling privacy and trust in electronic communities 失效
    实现电子社区隐私和信任的方法

    公开(公告)号:US07006999B1

    公开(公告)日:2006-02-28

    申请号:US09568794

    申请日:2000-05-09

    IPC分类号: G06F17/60

    CPC分类号: G06Q10/10 G06Q20/383

    摘要: A method for enabling privacy and trust in electronic communities is disclosed. A major impediment to using recommendation systems and collective knowledge for electronic commerce is the reluctance of individuals to reveal preferences in order to find groups of people that share them. An equally important barrier to fluid electronic commerce is the lack of agreed upon trusted third parties. We propose new non-third party mechanisms to overcome these barriers. Our solutions facilitate finding shared preferences, discovering communities with shared values, removing disincentives posed by liabilities, and negotiating on behalf of a group. We adapt known techniques from the cryptographic literature to enable these new capabilities.

    摘要翻译: 公开了一种在电子社区中实现隐私和信任的方法。 使用推荐系统和集体知识进行电子商务的主要障碍是个人不愿意透露偏好,以寻找分享他们的群体。 流动电子商务同样重要的障碍是缺乏可信第三方的认可。 我们提出新的非第三方机制来克服这些障碍。 我们的解决方案有助于发现共同的偏好,发现具有共同价值观念的社区,消除负债构成的不利因素,代表团体进行谈判。 我们从加密文献中调整已知技术,以实现这些新功能。

    System for encrypting documents with stencils
    8.
    发明授权
    System for encrypting documents with stencils 失效
    用模具加密文件的系统

    公开(公告)号:US06728376B1

    公开(公告)日:2004-04-27

    申请号:US09470876

    申请日:1999-12-22

    IPC分类号: G09C500

    CPC分类号: G09C5/00

    摘要: A symmetric key encryption system includes a printer or copier for performing decryption in two passes. During a first pass an encrypted image is decrypted to define a first partially decrypted image and during a second pass a complement of the encrypted image is decrypted to define a second partially decrypted image. The first partially decrypted image is formed when the encrypted image is rendered onto a first recording medium through a stencil. The stencil, which is a random arrangement of holes, is overlaid on the first recording medium to permit only selected portions of the encrypted image to be rendered on the recording medium. During the second pass, the complement of the encrypted image is rendered on a second recording medium through a complement of the stencil to yield the second partially decrypted image. Overlaying and aligning the first partially decrypted image and the second partially decrypted image finally decrypts the encrypted image.

    摘要翻译: 对称密钥加密系统包括用于在两遍中执行解密的打印机或复印机。 在第一次通过期间,加密图像被解密以定义第一部分解密的图像,并且在第二次传递期间,加密图像的补码被解密以定义第二部分解密的图像。 当通过模板将加密图像呈现在第一记录介质上时,形成第一部分解密的图像。 作为空穴的随机排列的模板被覆盖在第一记录介质上,以仅允许在记录介质上呈现加密图像的选定部分。 在第二遍期间,加密图像的补码通过模板的补码在第二记录介质上呈现,以产生第二部分解密的图像。 重叠和对准第一部分解密图像和第二部分解密的图像最终解密加密图像。

    Secure auction systems
    9.
    发明授权
    Secure auction systems 失效
    安全拍卖系统

    公开(公告)号:US6055518A

    公开(公告)日:2000-04-25

    申请号:US745717

    申请日:1996-11-12

    摘要: The apparatus and method of the present invention provide secure auction service for use in a network having servers and bidding terminals. The auction service makes transactions among servers and bidding terminals subject to a distributed protocol. The distributed protocol distributes submitted bids among the multiple servers, closes a bidding period, verifies validity of monetary value of each submitted bid by utilizing said distributed protocol and determines a winning bidder.

    摘要翻译: 本发明的装置和方法提供了在具有服务器和投标终端的网络中使用的安全拍卖服务。 拍卖服务使服务器和招标终端之间的交易受制于分布式协议。 分布式协议在多个服务器之间分配提交的出价,关闭投标期,利用所述分布式协议验证每个提交出价的货币价值的有效性,并确定中标者。