Method and system for protection against replay of an indicium message in a closed system meter
    3.
    发明授权
    Method and system for protection against replay of an indicium message in a closed system meter 有权
    用于防止在封闭系统仪表中重放标记信息的方法和系统

    公开(公告)号:US07319989B2

    公开(公告)日:2008-01-15

    申请号:US10378785

    申请日:2003-03-04

    IPC分类号: G06Q99/00

    摘要: A method and system that protects against a replay attack in a closed system postage meter is provided. “Freshness” data is included along with each indicium message sent from the meter to the printer, thereby enabling the printer to detect “stale” indicium data, i.e., indicium data that was previously generated and is being replayed, and prohibit the printing of duplicate indicia. The freshness data includes a random nonce generated by the printer during initialization along with sequence data that the printer can verify against sequence data from the previous printed indicium. If in the current indicium message the nonce is different or the current sequence data is not greater than or equal to the sequence data from the previous printed indicium, indicating the current indicium data may have been previously generated and is a replay, the printer will not print the current indicium data.

    摘要翻译: 提供了一种在封闭的系统邮资计费器中防止重放攻击的方法和系统。 包括“新鲜度”数据以及从仪表发送到打印机的每个标记信息,从而使打印机能够检测“过时”标记数据,即先前产生和正在重播的标记数据,并禁止打印副本 标记。 新鲜度数据包括打印机在初始化期间产生的随机随机数以及打印机可以针对来自先前打印的标记的序列数据的序列数据。 如果在当前的标记消息中,随机数不同,或者当前序列数据不大于或等于来自先前打印的标记的序列数据,表明当前标记数据可能已经被生成并且是重播,则打印机将不会 打印当前的标记数据。

    Method and system for optimizing throughput of mailing machines
    4.
    发明授权
    Method and system for optimizing throughput of mailing machines 有权
    优化邮寄机的吞吐量的方法和系统

    公开(公告)号:US07272581B2

    公开(公告)日:2007-09-18

    申请号:US10246040

    申请日:2002-09-17

    摘要: A mailing machine that optimizes throughput by reducing the amount of time necessary for the PSD to generate the digital signature and indicium for each mail piece is provided. The debit operation performed by the PSD, i.e., adjusting the PSD registers, is separated into three different sections, a pre-debit operation, a perform debit operation, and a complete debit operation. In addition, the calculation of the digital signature can optionally be pre-computed, or, alternatively, computed in stages, i.e., partial signature calculation. Utilizing this granularity, the cryptographic operations associated with generating the digital signature can be shifted between the three debit operations such that the execution time of the time critical portion of the debit operation (perform debit) can be optimized to meet the performance requirements of the mailing machine in which the PSD is deployed.

    摘要翻译: 提供了通过减少PSD生成每个邮件的数字签名和标记所需的时间来优化吞吐量的邮寄机。 由PSD执行的借记操作,即调整PSD寄存器,被分为三个不同的部分:预借记操作,执行借记操作和完整借记操作。 此外,可以可选地预先计算数字签名的计算,或者可选地,分阶段地计算,即部分签名计算。 利用这种粒度,与生成数字签名相关联的加密操作可以在三个借记操作之间移动,使得借记操作的时间关键部分(执行借记)的执行时间可被优化以满足邮寄的性能要求 配备PSD的机器。

    Mutual authentication system and method for protection of postal security devices and infrastructure
    7.
    发明授权
    Mutual authentication system and method for protection of postal security devices and infrastructure 有权
    相互认证系统和保护邮政安全设备和基础设施的方法

    公开(公告)号:US07912788B2

    公开(公告)日:2011-03-22

    申请号:US10953828

    申请日:2004-09-29

    IPC分类号: G06Q99/00

    摘要: A method of authenticating a PSD and an initializing infrastructure that uses a secret key, a PSD public/private key pair and a provider public/private key pair. The infrastructure prepares a signed provider key record using the provider public key and the provider private key and a first MAC using the signed provider key record and the secret key. Both are sent to the PSD. The PSD authenticates the signed provider key record using the first MAC and the provider public key using the included digital signature. The PSD prepares a signed PSD key record using the PSD public key and the PSD private key and a second MAC using the signed PSD key record and the secret key. Both are sent to the infrastructure. The infrastructure authenticates the signed PSD key record using the second MAC and the PSD public key using the included digital signature.

    摘要翻译: 验证PSD的方法和使用秘密密钥,PSD公钥/私钥对以及提供商公钥/私钥对的初始化基础设施的方法。 基础设施使用提供商公钥和提供者私钥来准备签名的提供商密钥记录,并且使用签名的提供者密钥记录和秘密密钥来准备第一个MAC。 两者都发送到PSD。 PSD使用包含的数字签名,使用第一个MAC和提供者公开密钥对签名的提供商密钥记录进行身份验证。 PSD使用PSD公开密钥和PSD私钥来准备签名的PSD密钥记录,并且使用签名的PSD密钥记录和秘密密钥来准备第二MAC。 两者都被发送到基础设施。 基础设施使用附带的数字签名,使用第二MAC和PSD公开密钥对签名的PSD密钥记录进行认证。

    Method and system for optimizing throughput of mailing machines
    8.
    发明授权
    Method and system for optimizing throughput of mailing machines 有权
    优化邮寄机的吞吐量的方法和系统

    公开(公告)号:US07908217B2

    公开(公告)日:2011-03-15

    申请号:US11837750

    申请日:2007-08-13

    摘要: A mailing machine that optimizes throughput by reducing the amount of time necessary for the PSD to generate the digital signature and indicium for each mail piece is provided. The debit operation performed by the PSD, i.e., adjusting the PSD registers, is separated into three different sections, a pre-debit operation, a perform debit operation, and a complete debit operation. In addition, the calculation of the digital signature can optionally be pre-computed, or, alternatively, computed in stages, i.e., partial signature calculation. Utilizing this granularity, the cryptographic operations associated with generating the digital signature can be shifted between the three debit operations such that the execution time of the time critical portion of the debit operation (perform debit) can be optimized to meet the performance requirements of the mailing machine in which the PSD is deployed.

    摘要翻译: 提供了通过减少PSD生成每个邮件的数字签名和标记所需的时间来优化吞吐量的邮寄机。 由PSD执行的借记操作,即调整PSD寄存器,被分为三个不同的部分:预借记操作,执行借记操作和完整借记操作。 此外,可以可选地预先计算数字签名的计算,或者可选地,分阶段地计算,即部分签名计算。 利用这种粒度,与生成数字签名相关联的加密操作可以在三个借记操作之间移动,使得借记操作的时间关键部分(执行借记)的执行时间可被优化以满足邮寄的性能要求 配备PSD的机器。

    Method and system for increasing mailing machine throughput by precomputing indicia
    10.
    发明授权
    Method and system for increasing mailing machine throughput by precomputing indicia 有权
    通过预计算标记增加邮寄机吞吐量的方法和系统

    公开(公告)号:US07516105B2

    公开(公告)日:2009-04-07

    申请号:US10732939

    申请日:2003-12-11

    IPC分类号: G07B17/02

    摘要: A method and system that increases the throughput of a mailing machine by continuously computing indicia prior to and during mail processing is provided. The indicia generation process is divided into two distinct parts, cryptographic calculation and funds committal/printing. Indicium data are continuously computed, asynchronously with the printing of the indicia, and stored in a buffer until needed. This enables several indicium data to be computed and stored prior to processing of a mail piece by the mailing machine. Prior to printing an indicium on a mail piece, the funds for the indicium are accounted for by updating the registers of the mailing machine. Since a number of indicium data may be pre-computed prior to the start of processing the mail through the mailing machine, the throughput of the mailing machine can be increased.

    摘要翻译: 提供了一种通过在邮件处理之前和期间连续计算标记来增加邮寄机的吞吐量的方法和系统。 标记生成过程分为两个不同的部分,加密计算和资金交付/打印。 标记数据与标记的打印异步地连续计算,并存储在缓冲区中直至需要。 这可以在邮寄机处理邮件之前计算和存储几个标记数据。 在邮件上打印邮戳之前,通过更新邮寄机的登记簿来记账。 由于在通过邮寄机开始处理邮件之前可以预先计算多个标记数据,所以可以增加邮寄机的吞吐量。