Systems and methods for obscuring network services
    81.
    发明授权
    Systems and methods for obscuring network services 有权
    遮蔽网络服务的系统和方法

    公开(公告)号:US09525665B1

    公开(公告)日:2016-12-20

    申请号:US14210399

    申请日:2014-03-13

    Abstract: A computer-implemented method for obscuring network services may include (1) identifying a local network comprising at least one client and at least one host, where the host provides a service that is not bound to any routable address on the local network and the client is expected to send messages to the service, (2) provisioning the client with a proxy that intercepts the messages directed to the service by the client, identifies the host that provides the service, and adds at least one layer of encryption to the messages, (3) configuring the proxy to route the messages through an onion routing network within the local network that comprises at least one onion routing node, and (4) configuring the onion routing network to remove the at least one layer of encryption from the messages before forwarding the messages. Various other methods, systems, and computer-readable media are also disclosed.

    Abstract translation: 用于遮蔽网络服务的计算机实现的方法可以包括(1)识别包括至少一个客户端和至少一个主机的本地网络,其中主机提供不限于本地网络和客户端上的任何可路由地址的服务 期望向服务发送消息,(2)为客户端提供拦截客户端定向到服务的消息的代理,识别提供服务的主机,并向消息添加至少一层加密, (3)配置代理以通过包括至少一个洋葱路由节点的本地网络内的洋葱路由网络来路由消息,以及(4)配置洋葱路由网络以从消息中删除至少一层加密 转发消息。 还公开了各种其它方法,系统和计算机可读介质。

    METHOD, DEVICE AND EQUIPMENT FOR ENSURING DATA SECURITY
    84.
    发明申请
    METHOD, DEVICE AND EQUIPMENT FOR ENSURING DATA SECURITY 审中-公开
    用于保护数据安全的方法,设备和设备

    公开(公告)号:US20160323251A1

    公开(公告)日:2016-11-03

    申请号:US15141875

    申请日:2016-04-29

    CPC classification number: G06F13/4282 G06F16/22 H04L63/0471 H04L2463/121

    Abstract: A method includes a firmware layer of a computing device receiving data input via a data input device, the received data being inaccessible by an operating system layer of the computing device, the data is to be sent to a remote server, and the firmware layer being independent of the operating system layer. The method further includes the firmware layer encrypting the received data, and the operating system layer sending the encrypted data to the remote server. A computing device includes a data input device, an operating system layer, and a firmware layer, wherein the computing device is capable of performing the method.

    Abstract translation: 一种方法包括计算设备的固件层,其接收经由数据输入设备输入的数据,所接收的数据不可由计算设备的操作系统层访问,数据将被发送到远程服务器,固件层为 独立于操作系统层。 该方法还包括固件层加密接收的数据,操作系统层将加密的数据发送到远程服务器。 计算设备包括数据输入设备,操作系统层和固件层,其中计算设备能够执行该方法。

    METHOD FOR ACCESSING A DATA MEMORY OF A CLOUD COMPUTER SYSTEM
    85.
    发明申请
    METHOD FOR ACCESSING A DATA MEMORY OF A CLOUD COMPUTER SYSTEM 审中-公开
    用于访问云计算机系统的数据存储器的方法

    公开(公告)号:US20160321459A1

    公开(公告)日:2016-11-03

    申请号:US15100715

    申请日:2014-10-24

    Inventor: Frank BYSZIO

    Abstract: A process for accessing a data storage device of a cloud computer system CCS through a gateway computer system GCS includes setting up a protected connection over the Internet between a first piece of terminal equipment of the user and the GCS by inputting the URL of the CCS into a program of the piece of terminal equipment, and using a modified DNS for name resolution of the URL, so that the protected connection is set up with the GCS instead of with the CCS; transferring a file over the protected connection from the terminal equipment to the GCS; setting up a session over the network between the GCS and the cloud computer system; encrypting the file by the GCS using the cryptographic key; transferring the encrypted file through the session from the GCS to the CCS; and storing the encrypted file in the data storage device of the CCS.

    Abstract translation: 通过网关计算机系统访问云计算机系统CCS的数据存储设备的过程GCS包括通过将CCS的URL输入到用户的第一个终端设备和GCS之间的Internet上建立受保护的连接 终端设备的程序,并使用修改后的DNS进行名称解析,以保护连接与GCS而不是CCS建立; 将受保护连接的文件从终端设备传送到GCS; 在GCS和云计算机系统之间的网络上建立会话; 使用加密密钥通过GCS加密该文件; 将加密的文件通过会话从GCS传送到CCS; 并将加密的文件存储在CCS的数据存储装置中。

    PREVENTING CONTENT DATA LEAK ON MOBILE DEVICES
    86.
    发明申请
    PREVENTING CONTENT DATA LEAK ON MOBILE DEVICES 审中-公开
    防止移动设备上的内容数据泄漏

    公开(公告)号:US20160292440A1

    公开(公告)日:2016-10-06

    申请号:US15136608

    申请日:2016-04-22

    Abstract: Preventing enterprise or other protected content data from “leaking” from being under secure management on a device, for example by virtue of being viewed using an untrusted app on the device, is disclosed. An indication is received that a content to be provided to a first mobile application on a mobile device is to be protected against unauthorized access at the mobile device using unauthorized applications other than the first mobile application. The content is encrypted while in transit to the mobile device, using a key associated with a second mobile application authorized to be used to access the content at the mobile device.

    Abstract translation: 公开了防止企业或其他受保护的内容数据在设备上的安全管理“泄漏”,例如通过在设备上使用不受信任的应用来查看。 接收到将要提供给移动设备上的第一移动应用的内容被保护以防止使用除第一移动应用之外的未授权应用的移动设备的未经授权的访问的指示。 使用与被授权用于访问移动设备上的内容的第二移动应用相关联的密钥,在传送到移动设备期间对内容进行加密。

    Server apparatus and program to re-encrypt ciphertext data
    87.
    发明授权
    Server apparatus and program to re-encrypt ciphertext data 有权
    服务器设备和程序重新加密密文数据

    公开(公告)号:US09426131B2

    公开(公告)日:2016-08-23

    申请号:US14219747

    申请日:2014-03-19

    Abstract: A server apparatus according to an embodiment generates a random number on receiving from a user apparatus a notification showing that a re-encryption key should be updated, and calculates re-encryption key data on the basis of the re-encryption key stored and the random number generated. The server apparatus transmits the re-encryption key to the user apparatus and receives, from the user apparatus, the user private key not updated yet and re-encryption key updating data calculated from the re-encryption key data on the basis of the user private key updated. The server apparatus calculates the re-encryption key updated, on the basis of the re-encryption key updating data and the random number, and replaces the re-encryption key stored in the storage device with the updated re-encryption key.

    Abstract translation: 根据实施例的服务器装置在从用户装置接收到的情况下生成随机数,该通知表示应当更新重新加密密钥,并且基于存储的重新加密密钥和随机数来计算重新加密密钥数据 数字生成。 服务器装置向用户装置发送重新加密密钥,并从用户装置接收未更新的用户私钥,并根据用户私有从重新加密密钥数据计算出的重新加密密钥更新数据 密钥更新。 服务器装置根据重新加密密钥更新数据和随机数计算更新的重新加密密钥,并用更新的重新加密密钥替换存储在存储装置中的重新加密密钥。

    ADJUSTABLE PROXY RE-ENCRYPTION
    89.
    发明申请
    ADJUSTABLE PROXY RE-ENCRYPTION 有权
    可调节代码重新加密

    公开(公告)号:US20160182467A1

    公开(公告)日:2016-06-23

    申请号:US14579317

    申请日:2014-12-22

    CPC classification number: H04L63/0464 H04L63/0471 H04L63/0807

    Abstract: Methods, systems, and computer-readable storage media for proxy re-encryption of encrypted data stored in a first database of a first server and a second database of a second server. Implementations include actions of receiving a first token at the first server from a client-side computing device, providing a first intermediate re-encrypted value based on a first encrypted value and the first token, transmitting the first intermediate re-encrypted value to the second server, receiving a second intermediate re-encrypted value from the second server, the second intermediate re-encrypted value having been provided by encrypting the first encrypted value at the second server based on a second token, providing the first encrypted value as a first re-encrypted value based on the first intermediate re-encrypted value and the second intermediate re-encrypted value, and storing the first re-encrypted value in the first database.

    Abstract translation: 用于对存储在第一服务器的第一数据库和第二服务器的第二数据库中的加密数据进行代理重新加密的方法,系统和计算机可读存储介质。 实现包括从客户端计算设备在第一服务器处接收第一令牌的动作,基于第一加密值和第一令牌提供第一中间重新加密的值,将第一中间重新加密值发送到第二中继重新加密值 服务器,从第二服务器接收第二中间重新加密的值,第二中间重新加密值是通过基于第二令牌加密第二服务器处的第一加密值而提供的,提供第一加密值作为第一重新 基于所述第一中间重新加密值和所述第二中间重新加密值的加密值,并将所述第一重新加密值存储在所述第一数据库中。

Patent Agency Ranking