Computer system and access right setting method
    1.
    发明授权
    Computer system and access right setting method 有权
    计算机系统和访问权限设置方法

    公开(公告)号:US08646058B2

    公开(公告)日:2014-02-04

    申请号:US10588324

    申请日:2005-01-20

    IPC分类号: G06F7/04

    摘要: IC cards (R11, R12, and R21) are issued respectively to users α, β, and γ. An identification code (ID(11)) of a computer (11) supplied to user α and environment information (ENV(11)) that indicates a normal network environment of the computer (11) are recorded in the IC card (R11) issued to user α. When in order to use a computer, a user connects his/her IC card, the identification code and the network environment of the computer to be used are compared with the identification code and environment information recorded in the IC card and different access rights are provided in accordance to the degree of matching. The identification code may be a MAC address of a LAN circuit incorporated in the computer, and the environment information may be a default gateway address or the like. Different access rights can thus be set according to the computer or the network environment that is used.

    摘要翻译: IC卡(R11,R12和R21)分别发给用户α,β和γ。 提供给用户的计算机(11)的识别码(ID(11))和指示计算机(11)的正常网络环境的环境信息(ENV(11))被记录在发行的IC卡(R11)中 到用户alpha。 为了使用计算机,将用户连接他/她的IC卡,将要使用的计算机的识别码和网络环境与记录在IC卡中的识别码和环境信息进行比较,并提供不同的访问权限 按照匹配程度。 识别码可以是并入计算机中的LAN电路的MAC地址,并且环境信息可以是默认网关地址等。 因此,可以根据所使用的计算机或网络环境设置不同的访问权限。

    Computer System and Access Right Setting Method
    2.
    发明申请
    Computer System and Access Right Setting Method 有权
    计算机系统和访问权限设置方法

    公开(公告)号:US20080276307A1

    公开(公告)日:2008-11-06

    申请号:US10588324

    申请日:2005-01-20

    IPC分类号: H04L9/32

    摘要: IC cards (R11, R12, and R21) are issued respectively to users α, β, and γ. An identification code (ID(11)) of a computer (11) supplied to user α and environment information (ENV(11)) that indicates a normal network environment of the computer (11) are recorded in the IC card (R11) issued to user α. When in order to use a computer, a user connects his/her IC card, the identification code and the network environment of the computer to be used are compared with the identification code and environment information recorded in the IC card and different access rights are provided in accordance to the degree of matching. The identification code may be a MAC address of a LAN circuit incorporated in the computer, and the environment information may be a default gateway address or the like. Different access rights can thus be set according to the computer or the network environment that is used.

    摘要翻译: IC卡(R 11,R 12和R 21)分别发给用户α,β和γ。 提供给用户的计算机(11)的识别码(ID(11))和指示计算机(11)的正常网络环境的环境信息(ENV(11))被记录在IC卡(R11)中, 发给用户alpha。 为了使用计算机,将用户连接他/她的IC卡,将要使用的计算机的识别码和网络环境与记录在IC卡中的识别码和环境信息进行比较,并提供不同的访问权限 按照匹配程度。 识别码可以是并入计算机中的LAN电路的MAC地址,并且环境信息可以是默认网关地址等。 因此,可以根据所使用的计算机或网络环境设置不同的访问权限。

    Distributed data archive device and system
    3.
    发明授权
    Distributed data archive device and system 有权
    分布式数据存档设备和系统

    公开(公告)号:US06711594B2

    公开(公告)日:2004-03-23

    申请号:US09913305

    申请日:2001-08-13

    IPC分类号: G06F1730

    摘要: A distributed data archive device (1) is placed on an arbitrary location on a network (3) so that data can be saved and extracted. During data saving, a to-be-saved data file (F1) is given to the archive device (1), and a division/encryption means (13) carries out division/encryption, and individual divided files are distributed and saved onto data servers (2a, 2b, 2c) by a network communication means (16). A data management means (15) forms management data that shows a division/encryption method and a depository-destination data server, and records it onto a portable recording medium (10) during the data saving. During data extraction, the portable recording medium (10) is connected to an arbitrary archive device (1), and the management data is read. Based on this management data, the divided files are extracted from the depository destinations, and are reconstituted into the original data file (F1) by a decryption/integration means (14).

    摘要翻译: 分布式数据归档设备(1)被放置在网络(3)上的任意位置,从而可以保存和提取数据。 在数据保存期间,向归档设备(1)提供待保存的数据文件(F1),并且分割/加密装置(13)执行分割/加密,并且将各个分割的文件分发并保存到数据 服务器(2a,2b,2c)通过网络通信装置(16)。 数据管理装置(15)形成显示分割/加密方法和存储目的地数据服务器的管理数据,并在数据保存期间将其记录在便携式记录介质(10)上。 在数据提取期间,便携式记录介质(10)连接到任意存档装置(1),并且读取管理数据。 基于该管理数据,从存放目的地提取划分的文件,并通过解密/积分装置(14)将其重构为原始数据文件(F1)。

    Electronic contract system
    4.
    发明授权
    Electronic contract system 有权
    电子合同制

    公开(公告)号:US07620585B2

    公开(公告)日:2009-11-17

    申请号:US10459377

    申请日:2003-06-11

    IPC分类号: G06Q40/00

    CPC分类号: G06Q30/02 G06Q40/04

    摘要: In order to give sufficient evidential admissibility to the content of a contract made online, contractual terms data C that shows a character string of contractual terms is prepared and stored by a processor on the side of a transacting party A. The data C is then transmitted to a processor on the side of a transacting party B, and is stored. A hash value ID2 of the contractual terms data C is calculated by the B-side processor, and a signature Sig2 of the party B is added and transmitted to the A-side processor as formal contractual proposal information. The signature Sig2 is verified by the A-side processor. A coincidence is verified between a hash value ID1 of the data C and the ID2 that has been transmitted. A signature Sig1 of the party A is added to a coinciding hash value ID, and is transmitted to the B-side processor as formal contractual acceptance information. The signature Sig1 is verified by the B-side processor, and a coincidence is verified between the hash value ID2 and the ID that has been transmitted.

    摘要翻译: 为了给予在线合同内容充分的证据可接受性,显示合同条款的字符串的合同条款数据C由交易方A侧的处理器准备和存储。然后传送数据C 到交易方B侧的处理器,并被存储。 合同项数据C的散列值ID2由B侧处理器计算,并且将方方B的签名Sig2作为正式契约提案信息相加并发送给A侧处理器。 签名Sig2由A侧处理器验证。 在数据C的散列值ID1和已经发送的ID2之间验证一致。 A方的签名Sig1被添加到一致的哈希值ID,并作为正式契约接受信息发送给B侧处理器。 签名Sig1由B侧处理器验证,并且在散列值ID2和已经发送的ID之间验证一致。

    Information processing apparatus, and method for retaining security
    5.
    发明授权
    Information processing apparatus, and method for retaining security 有权
    信息处理装置和保持安全性的方法

    公开(公告)号:US07574440B2

    公开(公告)日:2009-08-11

    申请号:US10588322

    申请日:2005-01-20

    IPC分类号: G06F7/00 G06F17/30

    摘要: When a user, who has logged onto an information processing apparatus (100), executes a logoff procedure, a saving unit (160) executes the following processes. Firstly, from among the files residing in a data storage unit (110), any files that are recognized as requiring a security protection and hence are to be saved are copied into an external storage device (300) via a network (200), and the original files in the data storage unit (110) are then deleted. At this moment, the address of the copy destination is stored, as management information, into a portable information recording medium (400) possessed by the user. When the user logs onto the information processing apparatus (100) again, a restoring unit (170) restores, based on the management information stored in the portable information recording medium (400), the files saved in the external storage device (300) into the data storage unit (110). In this way, a sufficient security can be retained when a plurality of users share a single information processing apparatus.

    摘要翻译: 当登录到信息处理设备(100)的用户执行注销过程时,保存单元(160)执行以下处理。 首先,从驻留在数据存储单元(110)的文件中,经由网络(200)将被认定为需要安全保护并因此被保存的任何文件经由网络(200)复制到外部存储设备(300)中,并且 然后删除数据存储单元(110)中的原始文件。 此时,将复制目的地的地址作为管理信息存储到用户拥有的便携式信息记录介质(400)中。 当用户再次登录到信息处理设备(100)时,恢复单元(170)基于存储在便携式信息记录介质(400)中的管理信息,将保存在外部存储设备(300)中的文件恢复为 数据存储单元(110)。 以这种方式,当多个用户共享单个信息处理设备时,可以保持足够的安全性。

    Method for issuing IC card storing encryption key information
    6.
    发明授权
    Method for issuing IC card storing encryption key information 有权
    用于发行存储加密密钥信息的IC卡的方法

    公开(公告)号:US08099771B2

    公开(公告)日:2012-01-17

    申请号:US13111586

    申请日:2011-05-19

    IPC分类号: H04L9/14 H04L9/12 H04L29/06

    摘要: It is possible to issue an IC card storing unique encryption key information in such a manner that re-issuing is enabled and sufficient security can be assured. An IC card provider X delivers an IC card having a group code G(A) to a company A and an IC card having a group code G(B) to a company B. When a company staff α inputs a unique personal code P(α) and performs initialization, in the IC card, calculation is performed according to a predetermined algorithm using the P(α) and G(A). Data uniquely determined by the calculation is stored as encryption key information K(α) in the IC card. Even if the company staff α loses the IC card, it is possible to obtain the IC card having the same encryption key information K(α) as before by performing initialization again by using the IC card delivered by the IC card provider X.

    摘要翻译: 可以发行存储唯一加密密钥信息的IC卡,使得能够重新发布并且可以确保足够的安全性。 IC卡提供商X向公司A提供具有组代码G(A)的IC卡和具有组代码G(B)的IC卡到公司B.当公司员工α输入唯一的个人代码P( α)并执行初始化,在IC卡中,根据使用P(α)和G(A)的预定算法进行计算。 由计算唯一确定的数据作为加密密钥信息K(α)存储在IC卡中。 即使公司员工α失去了IC卡,也可以通过使用由IC卡提供商X提供的IC卡再次执行初始化来获得具有与之前相同的加密密钥信息K(α)的IC卡。

    METHOD FOR ISSUING IC CARD STORING ENCRYPTION KEY INFORMATION
    7.
    发明申请
    METHOD FOR ISSUING IC CARD STORING ENCRYPTION KEY INFORMATION 有权
    解决IC卡存储加密密钥信息的方法

    公开(公告)号:US20110222686A1

    公开(公告)日:2011-09-15

    申请号:US13111586

    申请日:2011-05-19

    IPC分类号: H04L9/06

    摘要: It is possible to issue an. IC card storing unique encryption key information in such a manner that re-issuing is enabled and sufficient security can be assured. An IC card provider X delivers an IC card having a group code G(A) to a company A and an IC card having a group code G(B) to a company B. When a company staff α inputs a unique personal code P(α) and performs initialization, in the IC card, calculation is performed according to a predetermined algorithm using the P(α) and G(A). Data uniquely determined by the calculation is stored as encryption key information K(α) in the IC card. Even if the company staff α loses the IC card, it is possible to obtain the IC card having the same encryption key information K(α) as before by performing initialization again by using the IC card delivered by the IC card provider X.

    摘要翻译: 可以发出一个。 IC卡以这样的方式存储唯一的加密密钥信息,即重新启动并且可以确保足够的安全性。 IC卡提供商X向公司A提供具有组代码G(A)的IC卡和具有组代码G(B)的IC卡到公司B.当公司员工α输入唯一的个人代码P( α)并执行初始化,在IC卡中,根据使用P(α)和G(A)的预定算法进行计算。 由计算唯一确定的数据作为加密密钥信息K(α)存储在IC卡中。 即使公司员工α失去了IC卡,也可以通过使用由IC卡提供商X提供的IC卡再次执行初始化来获得具有与之前相同的加密密钥信息K(α)的IC卡。

    IC CARD FOR ENCRYPTION OR DECRYPTION PROCESS AND ENCRYPTED COMMUNICATION SYSTEM AND ENCRYPTED COMMUNICATION METHOD USING THE SAME
    8.
    发明申请
    IC CARD FOR ENCRYPTION OR DECRYPTION PROCESS AND ENCRYPTED COMMUNICATION SYSTEM AND ENCRYPTED COMMUNICATION METHOD USING THE SAME 有权
    用于加密或分解过程的IC卡和加密的通信系统和使用其的加密通信方法

    公开(公告)号:US20110213973A1

    公开(公告)日:2011-09-01

    申请号:US13098171

    申请日:2011-04-29

    IPC分类号: H04L9/32 G06F12/14

    摘要: It is possible to perform encrypted communication between members of a group while assuring a sufficient security compatible with a change of the members. An IC card having the same fixed code F(a) is distributed to all the staffs of company A. When communication is performed between a staff α and a staff β belonging to the same project group, α of the transmission side writes an arbitrary variable code V(1) in the IC card (100a) so as to generate encryption key information K(a1) according to F(a) and V(1) in the IC card and encrypt data D1 by using K(a1). β of the reception side writes the variable code V(1) received from α in the IC card (100b) so as to generate encryption key information K(a1). By using this K(a1), the encrypted data D2 received is decrypted to obtain data D3. The fixed code F(a) is different for each of the companies and rewrite-disabled so as to assure security.

    摘要翻译: 可以在确保与成员的变化相容的足够的安全性的同时,在组的成员之间执行加密通信。 具有相同固定码F(a)的IC卡分配给公司A的所有员工。当在员工α和员工之间进行通信时, 属于相同项目组的传送侧的α将IC卡(100a)中的任意变量V(1)写入,以便根据F(a)和V(1)产生加密密钥信息K(a1) 在IC卡中使用K(a1)加密数据D1。 &bgr 接收侧将从α接收的可变码V(1)写入IC卡(100b)中以产生加密密钥信息K(a1)。 通过使用该K(a1),对所接收的加密数据D2进行解密,得到数据D3。 固定代码F(a)对于每个公司都是不同的,并且重写 - 禁用,以确保安全性。

    Ic Card for Encryption or Decryption Process and Encrypted Communication System and Encrypted Communication Method Using the Same
    9.
    发明申请
    Ic Card for Encryption or Decryption Process and Encrypted Communication System and Encrypted Communication Method Using the Same 审中-公开
    用于加密或解密过程的IC卡和加密通信系统以及使用它的加密通信方法

    公开(公告)号:US20070226513A1

    公开(公告)日:2007-09-27

    申请号:US11579079

    申请日:2005-05-02

    IPC分类号: H04L9/08 G06K19/10

    摘要: It is possible to perform encrypted communication between members of a group while assuring a sufficient security compatible with a change of the members. An IC card having the same fixed code F(a) is distributed to all the staffs of company A. When communication is performed between a staff α and a staff β belonging to the same project group, α of the transmission side writes an arbitrary variable code V(1) in the IC card (100a) so as to generate encryption key information K(a1) according to F(a) and V(1) in the IC card and encrypt data D1 by using K(a1). β of the reception side writes the variable code V(1) received from a in the IC card (100b) so as to generate encryption key information K(a1). By using this K(a1), the encrypted data D2 received is decrypted to obtain data D3. The fixed code F(a) is different for each of the companies and rewrite-disabled so as to assure security.

    摘要翻译: 可以在确保与成员的变化相容的足够的安全性的同时,在组的成员之间执行加密通信。 具有相同固定代码F(a)的IC卡被分发给公司A的所有员工。当在属于同一项目组的员工α和员工β之间执行通信时,发送方的α写入任意变量 在IC卡(100a)中的代码V(1),以便根据IC卡中的F(a)和V(1)产生加密密钥信息K(a 1),并使用K(a 1)。 接收端的beta写入从IC卡(100b)中从a接收的可变代码V(1),以便生成加密密钥信息K(a 1)。 通过使用该K(a 1),对所接收的加密数据D 2进行解密,得到数据D 3。 固定代码F(a)对于每个公司都是不同的,并且重写 - 禁用,以确保安全性。

    Information processing apparatus, and method for retaining security
    10.
    发明申请
    Information processing apparatus, and method for retaining security 有权
    信息处理装置和保持安全性的方法

    公开(公告)号:US20070143288A1

    公开(公告)日:2007-06-21

    申请号:US10588322

    申请日:2005-01-20

    IPC分类号: G06F17/30

    摘要: When a user, who has logged onto an information processing apparatus (100), executes a logoff procedure, a saving unit (160) executes the following processes. Firstly, from among the files residing in a data storage unit (110), any files that are recognized as requiring a security protection and hence are to be saved are copied into an external storage device (300) via a network (200), and the original files in the data storage unit (110) are then deleted. At this moment, the address of the copy destination is stored, as management information, into a portable information recording medium (400) possessed by the user. When the user logs onto the information processing apparatus (100) again, a restoring unit (170) restores, based on the management information stored in the portable information recording medium (400), the files saved in the external storage device (300) into the data storage unit (110). In this way, a sufficient security can be retained when a plurality of users share a single information processing apparatus.

    摘要翻译: 当登录到信息处理设备(100)的用户执行注销过程时,保存单元(160)执行以下处理。 首先,从驻留在数据存储单元(110)的文件中,经由网络(200)将被认定为需要安全保护并因此被保存的任何文件经由网络(200)复制到外部存储设备(300)中,并且 然后删除数据存储单元(110)中的原始文件。 此时,将复制目的地的地址作为管理信息存储到用户拥有的便携式信息记录介质(400)中。 当用户再次登录到信息处理设备(100)时,恢复单元(170)基于存储在便携式信息记录介质(400)中的管理信息,将保存在外部存储设备(300)中的文件恢复为 数据存储单元(110)。 以这种方式,当多个用户共享单个信息处理设备时,可以保持足够的安全性。