Clock synchronized dynamic password security label validity real-time authentication system and method thereof
    91.
    发明授权
    Clock synchronized dynamic password security label validity real-time authentication system and method thereof 有权
    时钟同步动态密码安全标签有效性实时认证系统及其方法

    公开(公告)号:US09553871B2

    公开(公告)日:2017-01-24

    申请号:US15035224

    申请日:2015-04-15

    发明人: Xiaodong Fan

    摘要: This invention discloses a clock synchronized dynamic password security label validity real-time authentication system and method thereof, which comprises, the electronic label module, the user authentication terminal module, and the authentication service module. The electronic label module is used for generating the dynamic password data and displaying. The user authentication terminal module captures the dynamic password data generated by the electronic label module and the image data of the ID number of the electronic label module. After the analyzing processing, the text data is obtained, and then is sent to the authentication service module through the Internet. After receiving the text data, the authentication service module obtains the result of whether the first dynamic password data generating algorithm of the electronic label module is consistent with the second dynamic password data generating algorithm of the authentication service module. The result is returned to the user authentication terminal module.

    摘要翻译: 本发明公开了一种时钟同步动态密码安全标签有效性实时认证系统及其方法,包括电子标签模块,用户认证终端模块和认证服务模块。 电子标签模块用于生成动态密码数据和显示。 用户认证终端模块捕获由电子标签模块生成的动态密码数据和电子标签模块的ID号的图像数据。 分析处理后,获取文本数据,然后通过互联网发送给认证服务模块。 认证服务模块收到文本数据后,得到电子标签模块的第一动态口令数据生成算法是否符合认证服务模块的第二动态口令数据生成算法。 结果返回给用户认证终端模块。

    System and method for performing secure communications
    94.
    发明授权
    System and method for performing secure communications 有权
    用于执行安全通信的系统和方法

    公开(公告)号:US09531537B2

    公开(公告)日:2016-12-27

    申请号:US14767273

    申请日:2015-01-27

    申请人: TEIXEM CORP.

    摘要: A method of providing a new enhanced public key by a secure communications terminal for securing system communications, the secure communications terminal having a processor operably connected to a memory and a communications interface, the method comprising: generating, by the processor, a first portion for verifying a client account; generating, by the processor, a second portion for authenticating a public key server; generating, by the processor, an asymmetric public key and a corresponding asymmetric private key; combining, by the processor, the first portion, the second portion and the asymmetric public key to form the new enhanced public key; normalizing, by the processor, the enhanced public key based on a size of the asymmetric public key.

    摘要翻译: 一种由安全通信终端提供新的增强型公钥以保护系统通信的方法,所述安全通信终端具有可操作地连接到存储器和通信接口的处理器,该方法包括:由处理器产生第一部分,用于 验证客户帐户; 由处理器生成用于认证公钥服务器的第二部分; 由所述处理器生成非对称公钥和对应的非对称私钥; 由处理器组合第一部分,第二部分和非对称公钥,以形成新的增强型公共密钥; 基于非对称公钥的大小,通过处理器对增强型公钥进行归一化。

    SERVER, PROVISION DEVICE, AND ONE-TIME PASSWORD GENERATION DEVICE
    95.
    发明申请
    SERVER, PROVISION DEVICE, AND ONE-TIME PASSWORD GENERATION DEVICE 有权
    服务器,配置设备和一次性密码生成设备

    公开(公告)号:US20160373435A1

    公开(公告)日:2016-12-22

    申请号:US15251477

    申请日:2016-08-30

    IPC分类号: H04L29/06

    摘要: Realized is a low-cost provision system capable of providing a provision item or a provision system that requires a smaller number of operation steps to be made by a user. A server includes a first receiving unit receiving transaction information transmitted by a communication terminal requesting a provision device having a provision item stored thereon to make a transaction of the provision item, a second receiving unit receiving a communication result including authentication information input to the communication terminal before the communication, the communication result being generated by a communication between the provision device and the communication terminal, and a transmission unit transmitting an instruction to execute the transaction to the provision device based on the transaction information or the communication result.

    摘要翻译: 实现了能够提供用户需要较少数量的操作步骤的提供项目或提供系统的低成本提供系统。 服务器包括:第一接收单元,接收由通信终端发送的交易信息,所述通信终端请求具有存储在其上的提供项目的提供设备进行提供项目的交易;第二接收单元,接收包括输入到通信终端的认证信息的通信结果 在通信之前,通过提供装置和通信终端之间的通信产生通信结果,以及发送单元,基于交易信息或通信结果向发布装置发送执行交易的指令。

    Authentication System and Car Onboard Control Device
    96.
    发明申请
    Authentication System and Car Onboard Control Device 审中-公开
    认证系统和车载控制设备

    公开(公告)号:US20160371481A1

    公开(公告)日:2016-12-22

    申请号:US15120782

    申请日:2015-01-23

    发明人: Junji MIYAKE

    IPC分类号: G06F21/44 H04L9/32

    摘要: The present invention prevents a maintenance tool for carrying out maintenance work of an electronic control unit (ECU) from being abused by a third person. In an authentication system according to the present invention, an authentication apparatus authenticates an operator of an operation terminal (equivalent to the maintenance tool), and the operation terminal forwards an authentication code generated by the authentication apparatus to the ECU. By using the authentication code, the ECU determines whether or not to permit the operation terminal to carry out a maintenance operation.

    摘要翻译: 本发明防止维护工具进行电子控制单元(ECU)的维护工作不被第三人员滥用。 在根据本发明的认证系统中,认证装置认证操作终端的操作者(相当于维护工具),操作终端将认证装置生成的认证码转发给ECU。 通过使用认证码,ECU判断是否允许操作终端进行维护操作。

    Randomly skewing secret values as a countermeasure to compromise
    97.
    发明授权
    Randomly skewing secret values as a countermeasure to compromise 有权
    随机倾斜秘密价值作为妥协的对策

    公开(公告)号:US09525551B1

    公开(公告)日:2016-12-20

    申请号:US13248127

    申请日:2011-09-29

    IPC分类号: H04L9/32 G06F21/31 G06F21/34

    摘要: A first cryptographic device is authenticated by a second cryptographic device. The second cryptographic device stores an alternative version of a secret value associated with the first cryptographic device as a countermeasure to compromise of the secret value. In conjunction with a protocol carried out between the first cryptographic device and the second cryptographic device, the second cryptographic device determines the secret value based at least in part on the alternative version of the secret value, and utilizes the determined secret value to authenticate the first cryptographic device. The alternative version of the secret value may comprise a randomly-skewed version of the secret value. For example, the secret value may comprise a key or other parameter of the first cryptographic device and the alternative version of the secret value may comprise a randomly-skewed version of the key or other parameter.

    摘要翻译: 第一加密设备由第二加密设备认证。 第二加密设备存储与第一密码设备相关联的秘密值的备选版本作为妥协秘密值的对策。 结合在第一加密装置和第二密码装置之间执行的协议,第二加密装置至少部分地基于秘密值的备选版本来确定秘密值,并利用所确定的秘密值来认证第一加密装置 加密设备 秘密值的替代版本可以包括秘密值的随机倾斜版本。 例如,秘密值可以包括第一密码设备的密钥或其他参数,秘密值的备选版本可以包括密钥或其他参数的随机倾斜版本。

    System, Design and Process for Secure Documents Credentials Management Using Out-of-Band Authentication
    98.
    发明申请
    System, Design and Process for Secure Documents Credentials Management Using Out-of-Band Authentication 审中-公开
    使用带外认证的安全文档证书管理的系统,设计和过程

    公开(公告)号:US20160351080A1

    公开(公告)日:2016-12-01

    申请号:US15158278

    申请日:2016-05-18

    IPC分类号: G09C5/00 H04L9/32 H04L29/06

    摘要: The invention provides an easy to use credential management mechanism for multi-factor out-of-band multi-channel authentication process to protect a large number of documents without the need to remember all the document passwords. When opened, the secure document application generates a multi-dimensional code. The user scans the multi-dimensional code and validates the secure document application and triggers an out-of-band outbound mechanism. The portable mobile device invoices the authentication server to get authenticated. The authentication server authenticates the user based on shared secret key and is automatically allowed access to the secure document. The process of the invention includes an authentication server, a secure document application to generate an authentication vehicle or an embodiment (i.e. multi-dimensional bar code) and handle incoming requests, secret keys and a portable communication device with a smartphone application.

    摘要翻译: 本发明提供了一种易于使用的多因素带外多信道认证过程的凭据管理机制,以保护大量文档,而不需要记住所有的文档密码。 打开时,安全文档应用程序生成多维代码。 用户扫描多维码并验证安全文档应用程序,并触发带外出站机制。 便携式移动设备发证认证服务器进行认证。 认证服务器基于共享密钥对用户进行认证,并自动允许访问安全文档。 本发明的过程包括认证服务器,用于生成认证车辆的安全文档应用或实施例(即,多维条形码)并且处理传入请求,秘密密钥和具有智能电话应用的便携式通信设备。

    Network Authentication Of Multiple Profile Accesses From A Single Remote Device
    99.
    发明申请
    Network Authentication Of Multiple Profile Accesses From A Single Remote Device 有权
    来自单个远程设备的多个配置文件访问的网络认证

    公开(公告)号:US20160323290A1

    公开(公告)日:2016-11-03

    申请号:US15205375

    申请日:2016-07-08

    IPC分类号: H04L29/06 G06Q40/02

    摘要: A network authentication system and method is described for authenticating multiple profile accesses from a single remote device. A device remote from a web server, yet connected to the web server via, for example, the Internet, can allow multiple users to register their profiles within the device. The profiles are registered using a pre-existing user ID and password corresponding to, for example, the user's financial accounts. Multiple profiles and, specifically, the indicia of those profiles, can appear on the display of the remote device allowing each user the ability to select their own registered profile. Access to a profile is granted when the user enters their private PIN. Once the PIN is entered, the private information such as financial account information will be securely forwarded from the web server to the remote device.

    摘要翻译: 描述了用于从单个远程设备认证多个简档访问的网络认证系统和方法。 远离web服务器的设备,但是通过例如因特网连接到web服务器,可以允许多个用户在设备内注册他们的配置文件。 使用与例如用户的财务账户对应的预先存在的用户ID和密码来注册该配置文件。 多个配置文件,特别是这些配置文件的标记,可以出现在远程设备的显示器上,从而允许每个用户选择自己注册的配置文件。 当用户输入私人PIN码时,系统会授予对配置文件的访问权限。 一旦输入PIN,私人信息(如财务帐户信息)将被安全地从网络服务器转发到远程设备。

    METHOD AND SYSTEM FOR PROTECTING INFORMATION AGAINST UNAUTHORIZED USE (VARIANTS)
    100.
    发明申请
    METHOD AND SYSTEM FOR PROTECTING INFORMATION AGAINST UNAUTHORIZED USE (VARIANTS) 审中-公开
    保护未经授权使用的信息的方法和系统(变体)

    公开(公告)号:US20160321656A1

    公开(公告)日:2016-11-03

    申请号:US15026967

    申请日:2014-11-05

    摘要: The given invention refers to ways of information protection from unsanctioned use. Method of creating of a safe environment for protecting information from unsanctioned use is characterized by encrypting information with a cryptographic processor and a closed cryptographic key, stored in the use's device, by forming and sending the data package, containing single-use authentication code of the user, to the aiding person's server, decrypting data package at the aiding person's server, and checking at the server of the single-use authentication code and test code, and, in case of positive result of verification server sends to the user a data package, single-use code of user authentication, received during decrypting the user's data package, after which the user's device forms a new data package, characterized by a new single-use code of user authentication, also data package consists of encrypted and non-encrypted parts, and the non-encrypted part contains a verification code, made with an ability to check the data package integrity and user identifier,

    摘要翻译: 给定的发明是指未经未经授权的使用的信息保护方式。 创建用于保护信息免受未经授权的使用的安全环境的方法的特征在于通过存储在使用设备中的加密处理器和封闭的加密密钥来加密信息,通过形成和发送包含一次性认证码的数据包 用户到辅助人员的服务器,在辅助人员的服务器上解密数据包,并在服务器上检查一次性认证码和测试代码,并且如果验证服务器的肯定结果向用户发送数据包 在用户数据包解密期间接收的用户认证的一次性代码,之后用户的设备形成新的数据包,其特征在于新的用户认证的一次性代码,还包括加密和未加密的数据包 部分,非加密部分包含验证码,具有检查数据包完整性和用户标识符的能力,