METHOD AND APPARATUS FOR SENDING ENCRYPTED ELECTRONIC MAIL THROUGH A DISTRIBUTION LIST EXPLODER
    82.
    发明申请
    METHOD AND APPARATUS FOR SENDING ENCRYPTED ELECTRONIC MAIL THROUGH A DISTRIBUTION LIST EXPLODER 审中-公开
    通过分发列表显示器发送加密电子邮件的方法和装置

    公开(公告)号:WO0141353A3

    公开(公告)日:2002-02-21

    申请号:PCT/US0041995

    申请日:2000-11-07

    Abstract: One embodiment of the present invention provides a system for sending an encrypted message through a distribution list exploder in order to forward the encrypted message to recipients on a distribution list. The system operates by encrypting the message at a sender using a message key to form an encrypted message. The system also encrypts the message key with a group public key to form an encrypted message key. The group public key is associated with a group private key to form a public key-private key pair associated with a group of valid recipients for the message. Next, the system sends the encrypted message and the encrypted message key to the distribution list exploder, and the distribution list exploder forwards the encrypted message to a plurality of recipients specified in the distribution list. After receiving the encrypted message and the encrypted message key, the recipient decrypts the encrypted message key to restore the message key. Next, the recipient decrypts the encrypted message using the message key to restore the message. In a variation on the above embodiment, the recipient decrypts the encrypted message key by sending the encrypted message key from the recipient to a group server, which holds the group private key. The group server decrypts the encrypted message key using the group private key to restore the message key, and returns the message key to the recipient in a secure manner.

    Abstract translation: 本发明的一个实施例提供了一种用于通过分发列表破解器发送加密消息以便将加密消息转发到分发列表上的收件人的系统。 该系统通过使用消息密钥在发送者处加密消息来形成加密消息来进行操作。 系统还使用组公钥对消息密钥进行加密,形成加密的消息密钥。 组公钥与组私钥相关联,以形成与消息的一组有效接收者相关联的公钥 - 私钥对。 接下来,系统将加密的消息和加密的消息密钥发送到分发列表扩展,并且分发列表将加密的消息转发到分发列表中指定的多个收件人。 收到加密消息和加密消息密钥后,收件人解密加密消息密钥以恢复消息密钥。 接下来,收件人使用消息密钥解密加密消息以恢复消息。 在上述实施例的变型中,接收者通过将加密的消息密钥从接收者发送到保存组私钥的组服务器来解密加密的消息密钥。 组服务器使用组私钥对加密的消息密钥进行解密,以恢复消息密钥,并以安全的方式将消息密钥返回给收件人。

    SYSTEM AND METHOD FOR SECURE TRANSACTIONS OVER A NETWORK
    83.
    发明申请
    SYSTEM AND METHOD FOR SECURE TRANSACTIONS OVER A NETWORK 审中-公开
    用于网络上的安全交易的系统和方法

    公开(公告)号:WO0120430A3

    公开(公告)日:2001-11-29

    申请号:PCT/CA0001073

    申请日:2000-09-15

    Inventor: MUNSHI ANEES

    CPC classification number: H04L63/0435 H04L63/0442 H04L63/0464 H04L69/40

    Abstract: The public Internet is the world's largest system of inter-networked computers. Adequate security means for protecting sensitive data communicated over the Internet is not, however, provided. The present invention, therefore, provides a system and method for performing secure transactions over an insecure packet-switched communication network. This is achieved by interconnecting a number of master nodes over the insecure communication network. The master nodes are capable of transmitting encrypted data packets over the insecure network via pseudo-random communication paths. The master nodes are further capable of returning to any state in a secure transaction in the event of a network failure. The master nodes are also capable of using new keys to encrypt each data packet.

    Abstract translation: 公共互联网是世界上最大的联网计算机系统。 然而,并未提供足够的安全手段来保护通过互联网传输的敏感数据。 因此,本发明提供了用于通过不安全的分组交换通信网络执行安全交易的系统和方法。 这通过在不安全的通信网络上互连多个主节点来实现。 主节点能够通过伪随机通信路径在不安全的网络上传输加密的数据分组。 在发生网络故障时,主节点还能够返回到安全事务中的任何状态。 主节点也能够使用新密钥来加密每个数据包。

    SYSTEMS AND METHODS FOR ENCRYPTING/DECRYPTING DATA
    84.
    发明申请
    SYSTEMS AND METHODS FOR ENCRYPTING/DECRYPTING DATA 审中-公开
    加密/分解数据的系统和方法

    公开(公告)号:WO01078491A2

    公开(公告)日:2001-10-25

    申请号:PCT/US2001/012157

    申请日:2001-04-12

    CPC classification number: H04L63/045 H04L9/083 H04L63/0464

    Abstract: The present invention relates to systems and methods for providing secure symmetric and asymmetric encryption/decryption using an intermediate or broker agent. The present systems and methods provide a more advanced and sophisticated manner of preventing unauthorized users from accessing sensitive and private data that is transmitted via the Internet. The broker agent (i.e., a server) is used to encrypt and decrypt data and/or session key during the transmission of the data from the sender to the recipient. These encryption processes are more secure because the recipients do not have access to the sender's private and public keys. The first and second embodiment relate to symmetric encryption/decryption systems and methods, while the third and fourth embodiments relate to asymmetric encryption/decryption systems and methods.

    Abstract translation: 本发明涉及使用中间或代理代理提供安全对称和非对称加密/解密的系统和方法。 本系统和方法提供了更先进和更复杂的方式来防止未经授权的用户访问通过因特网传送的敏感和私有数据。 代理代理(即,服务器)用于在从发送者到接收者的数据传输期间加密和解密数据和/或会话密钥。 这些加密过程更安全,因为收件人无权访问发件人的私钥和公钥。 第一和第二实施例涉及对称加密/解密系统和方法,而第三和第四实施例涉及非对称加密/解密系统和方法。

    CONTENT SCREENING WITH END-TO-END ENCRYPTION
    85.
    发明申请
    CONTENT SCREENING WITH END-TO-END ENCRYPTION 审中-公开
    使用端到端加密的内容筛选

    公开(公告)号:WO01063879A1

    公开(公告)日:2001-08-30

    申请号:PCT/US2001/003135

    申请日:2001-01-31

    Abstract: One embodiment of the present invention provides a system that performs content screening on a message that is protected by end-to-end encryption. The system operates by receiving an encrypted message and an encrypted message key at a destination from a source; the encrypted message having been formed by encrypting the message with a message key; the encrypted message key having been formed by encrypting the message key. The destination forwards the message to a content screener in a secure manner, and allows the content screener to screen the message to determine whether the message satisfies a screening criterion. If the message satisfies the screening criterion, the destination receives a communication from the content screener that enables the destination to process the message. In one embodiment of the present invention, the system decrypts the encrypted message key at the destination to restore the message key, and forwards the message key along with the encrypted message to the content screener. This enables the content screener to decrypt the encrypted message using the message key. In one embodiment of the present invention, the system decrypts the encrypted message key at the destination to restore the message key, and then decrypts the encrypted message with the message key to restore the message before sending the message to the content screener.

    Abstract translation: 本发明的一个实施例提供一种对通过端到端加密保护的消息执行内容筛选的系统。 该系统通过从源头在目的地接收加密消息和加密消息密钥来操作; 已经通过用消息密钥加密消息形成加密消息; 已经通过加密消息密钥形成的加密消息密钥。 目的地以安全的方式将消息转发到内容筛选器,并且允许内容筛选器屏蔽消息以确定该消息是否满足筛选标准。 如果消息满足筛选标准,则目的地从内容筛选器接收使能目的地处理消息的通信。 在本发明的一个实施例中,系统解密目的地的加密消息密钥以恢复消息密钥,并将消息密钥与加密消息一起转发到内容筛选器。 这使得内容筛选器能够使用消息密钥解密加密的消息。 在本发明的一个实施例中,系统解密目的地的加密消息密钥以恢复消息密钥,然后用消息密钥对加密的消息进行解密,以在将消息发送到内容筛选器之前恢复消息。

    DYNAMIC CONNECTION TO MULTIPLE ORIGIN SERVERS IN A TRANSCODING PROXY
    86.
    发明申请
    DYNAMIC CONNECTION TO MULTIPLE ORIGIN SERVERS IN A TRANSCODING PROXY 审中-公开
    动态连接到转码代理中的多个原始服务器

    公开(公告)号:WO0103398A3

    公开(公告)日:2001-06-07

    申请号:PCT/GB0002469

    申请日:2000-06-28

    Applicant: IBM IBM UK

    CPC classification number: H04L63/0464 H04L63/166 H04L2463/102

    Abstract: A method of enabling a proxy to participate in a secure communication between a client and a set of servers. The method begins by establishing a first secure session between the client and the proxy. Upon verifying the first secure session, the method continues by establishing a second secure session between the client and the proxy. In the second secure session, the client requests the proxy to act as a conduit to a first server. Thereafter, the client and the first server negotiate a first session master secret. Using the first secure session, this first session master secret is then provided by the client to the proxy to enable the proxy to participate in secure communications between the client and the first server. After receiving the first session master secret, the proxy generates cryptographic information that enables it to provide a given service (e.g., transcoding) on the client's behalf and without the first server's knowledge or participation. If data from a second server is required during the processing of a given client request to the first server, the proxy issues a request to the client to tunnel back through the proxy to the second server using the same protocol.

    Abstract translation: 一种使代理能够参与客户端与一组服务器之间的安全通信的方法。 该方法首先在客户端和代理之间建立第一个安全会话。 在验证第一安全会话后,该方法继续在客户端和代理之间建立第二安全会话。 在第二个安全会话中,客户端请求代理充当第一台服务器的管道。 此后,客户端和第一服务器协商第一会话主密钥。 使用第一安全会话,然后由客户端将第一会话主密钥提供给代理,以使代理能够参与客户端和第一服务器之间的安全通信。 在接收到第一会话主秘密之后,代理生成密码信息,使其能够代表客户提供给定的服务(例如代码转换),并且不需要第一服务器的知识或参与。 如果在处理给定第一个服务器的给定客户机请求期间需要来自第二个服务器的数据,则代理向客户机发出请求,以使用相同协议通过代理向第二个服务器进行隧道传输。

    METHOD AND SYSTEM FOR MANAGING SECURE CLIENT-SERVER TRANSACTIONS
    87.
    发明申请
    METHOD AND SYSTEM FOR MANAGING SECURE CLIENT-SERVER TRANSACTIONS 审中-公开
    用于管理安全客户端 - 服务器交易的方法和系统

    公开(公告)号:WO0102935A3

    公开(公告)日:2001-05-03

    申请号:PCT/US0013047

    申请日:2000-05-11

    Applicant: INTEL CORP

    Inventor: JARDIN CARY A

    Abstract: A server broker configured for use in a secure communication network, such as the Internet. The broker is configured to broker client transactions received over a secure network link, such as a secure socket layer (SSL) link, for distribution among one or more of a plurality of fulfillment servers. In one embodiment, the broker establishes a non-secure link with the one or more fulfillment servers. In another embodiment, the broker establishes a secure SSL link with the one or more fulfillment servers. The fulfillment server executes client transactions and sends response packets for delivery to the client.

    Abstract translation: 配置用于安全通信网络(例如因特网)的服务器代理。 代理被配置为代理通过诸如安全套接字层(SSL)链路的安全网络链接接收的客户端事务,以便在多个履行服务器中的一个或多个履行服务器之间分配。 在一个实施例中,代理建立与一个或多个履行服务器的非安全链接。 在另一个实施例中,代理建立与一个或多个履行服务器的安全SSL链接。 履行服务器执行客户端事务并发送响应数据包以传递给客户端。

    APPARATUS AND METHOD FOR PERFORMING AND CONTROLLING ENCRYPTION/DECRYPTION FOR DATA TO BE TRANSMITTED ON LOCAL AREA NETWORK
    88.
    发明申请
    APPARATUS AND METHOD FOR PERFORMING AND CONTROLLING ENCRYPTION/DECRYPTION FOR DATA TO BE TRANSMITTED ON LOCAL AREA NETWORK 审中-公开
    用于执行和控制要在本地区网络上传输的数据的加密/解码的装置和方法

    公开(公告)号:WO0030262A3

    公开(公告)日:2000-08-17

    申请号:PCT/DK9900625

    申请日:1999-11-12

    CPC classification number: H04L63/0428 H03M7/30 H04L63/0464 H04L63/08

    Abstract: A communication controller for performing data encryption and data decryption of data communication packages to be transferred in a network (such as LAN: Local Area Network, or a WAN: Wide Area Network). The data communication package contains a first section of non-encrypted data and a second section of encrypted data. The communication controller comprises a session key LUT unit (186), and a transmission and encryption section, which includes a data read transmission control unit (102), a data compressing unit (118), a data encryption unit (126), an integrity check value calculation unit (122) constituting a first series configuration, a network transmission controller (134), and a first switch means (108) enabling switching between two modes of operation a first mode of operation providing bypassing or disabling of the first series configuration and enabling communication between the data read transmission control unit (102) and the network transmission controller (134) for transferring the input data directly hereto and a second mode of operation enabling communication between the data read transmission control unit (102) through the first series configuration to the network transmission controller (134).

    Abstract translation: 一种通信控制器,用于执行要在网络(例如LAN:局域网或WAN:广域网)中传送的数据通信包的数据加密和数据解密。 数据通信包包含非加密数据的第一部分和加密数据的第二部分。 通信控制器包括会话密钥LUT单元(186)和传输和加密部分,包括数据读取传输控制单元(102),数据压缩单元(118),数据加密单元(126),完整性 构成第一串联配置的检查值计算单元(122),网络传输控制器(134)和能够在两种操作模式之间切换的第一操作模式提供旁路或禁用第一串联配置的第一开关装置(108) 并且使得数据读取传输控制单元(102)和网络传输控制器(134)之间的通信能够直接传送到这里的输入数据,以及第二操作模式,使数据读取传输控制单元(102)通过第一系列 配置到网络传输控制器(134)。

Patent Agency Ranking