Establishing mutual authentication and secure channels in devices without previous credentials
    2.
    发明申请
    Establishing mutual authentication and secure channels in devices without previous credentials 失效
    在没有先前凭据的情况下,在设备中建立相互认证和安全渠道

    公开(公告)号:US20070150420A1

    公开(公告)日:2007-06-28

    申请号:US11314089

    申请日:2005-12-22

    IPC分类号: G06Q99/00

    摘要: The invention provides for installing encryption keys on a device not having any previous security credentials. An installation authority generates a security token to be used by the device for secure communications, and an installation credential for the device, and stores them in association with one another. A user of the device is provided with the installation credential, whereby the user inputs the installation credential into the device. The device utilizes the installation credential as a temporary security key, establishes a secure communication channel with the installation authority and requests provision of the security token. The installation authority provides the security token associated with the installation credential to the device over the established secure communication channel, and the device installs the security token, after which the device erases the installation credential from the device. The installation authority may also certify the security token and provide a certified token and a root verification certificate to the device.

    摘要翻译: 本发明提供在不具有任何先前的安全证书的设备上安装加密密钥。 安装权限生成安全令牌以供设备使用以进行安全通信,以及设备的安装凭证,并将它们彼此关联存储。 设备的用户被提供有安装凭证,由此用户将安装凭证输入到设备中。 该设备使用安装凭证作为临时安全密钥,与安装权限建立安全通信通道,并请求提供安全令牌。 安装权限通过建立的安全通信通道向设备提供与安装凭证相关联的安全令牌,并且设备安装安全令牌,之后设备从设备中删除安装凭证。 安装机构还可以证明安全令牌,并向设备提供经认证的令牌和根验证证书。

    Establishing mutual authentication and secure channels in devices without previous credentials
    3.
    发明授权
    Establishing mutual authentication and secure channels in devices without previous credentials 失效
    在没有先前凭据的情况下,在设备中建立相互认证和安全渠道

    公开(公告)号:US07646874B2

    公开(公告)日:2010-01-12

    申请号:US11314089

    申请日:2005-12-22

    摘要: The invention provides for installing encryption keys on a device not having any previous security credentials. An installation authority generates a security token to be used by the device for secure communications, and an installation credential for the device, and stores them in association with one another. A user of the device is provided with the installation credential, whereby the user inputs the installation credential into the device. The device utilizes the installation credential as a temporary security key, establishes a secure communication channel with the installation authority and requests provision of the security token. The installation authority provides the security token associated with the installation credential to the device over the established secure communication channel, and the device installs the security token, after which the device erases the installation credential from the device. The installation authority may also certify the security token and provide a certified token and a root verification certificate to the device.

    摘要翻译: 本发明提供在不具有任何先前的安全证书的设备上安装加密密钥。 安装权限生成安全令牌以供设备使用以进行安全通信,以及设备的安装凭证,并将它们彼此关联存储。 设备的用户被提供有安装凭证,由此用户将安装凭证输入到设备中。 该设备使用安装凭证作为临时安全密钥,与安装权限建立安全通信通道,并请求提供安全令牌。 安装权限通过建立的安全通信通道向设备提供与安装凭证相关联的安全令牌,并且设备安装安全令牌,之后设备从设备中删除安装凭证。 安装机构还可以证明安全令牌,并向设备提供经认证的令牌和根验证证书。

    Obtaining temporary exclusive control of a printing device
    4.
    发明授权
    Obtaining temporary exclusive control of a printing device 失效
    获取打印设备的临时独占控制

    公开(公告)号:US07454796B2

    公开(公告)日:2008-11-18

    申请号:US09747097

    申请日:2000-12-22

    IPC分类号: G06F17/30

    摘要: Obtaining exclusive control of a printing device by deferring printing of print data in a print queue. To obtain control, the recipient performs a process which may include authentication of the recipient. Control may be obtained either before the recipient is authenticated or after a successful authentication process. After the recipient has obtained control, print data in the print queue is temporarily deferred from being printed. The recipient may then select a print job to print, including selecting a print job from among the print jobs deferred in the print queue, or selecting a file to print over a network, including the Internet or an intranet. Further, printing device resources utilized in printing data during the period of exclusive control may be tracked and correlated to the recipient who has control.

    摘要翻译: 通过延迟打印队列中的打印数据的打印来获得对打印设备的排他控制。 为了获得控制,接收者执行可以包括接收者的认证的过程。 可以在接收者被认证之前或成功认证过程之后获得控制。 收件人获得控制后,打印队列中的打印数据将暂时被打印。 收件人然后可以选择要打印的打印作业,包括从在打印队列中延迟的打印作业中选择打印作业,或者选择要通过网络(包括因特网或内部网)进行打印的文件。 此外,可以跟踪在独占控制期间打印数据所使用的打印设备资源并将其与具有控制的接收者相关联。

    Systems and methods for implementing security services
    6.
    发明授权
    Systems and methods for implementing security services 有权
    用于实施安全服务的系统和方法

    公开(公告)号:US08732811B2

    公开(公告)日:2014-05-20

    申请号:US13420462

    申请日:2012-03-14

    摘要: Systems and methods for providing a login context operate a virtual machine, wherein the virtual machine includes an open services platform and an authentication service, wherein the authentication service includes a classloader, and an initial classloader is designated as the classloader of the authentication service, register a login module, receive an authentication request from a first application, and responsive to receiving the authentication request designate a classloader associated with the login module as the classloader of the authentication service, generate a login context of the login module, and provide the login context of the login module to the first application, whereby the first application uses the login context to perform an authentication.

    摘要翻译: 用于提供登录上下文的系统和方法操作虚拟机,其中所述虚拟机包括开放服务平台和认证服务,其中所述认证服务包括类加载器,并且初始类加载器被指定为所述认证服务的类加载器,寄存器 登录模块,接收来自第一应用的认证请求,并且响应于接收到认证请求,指定与登录模块相关联的类加载器作为认证服务的类加载器,生成登录模块的登录上下文,并提供登录上下文 登录模块的第一应用程序,由此第一应用程序使用登录上下文来执行认证。

    Targeted secure printing
    7.
    发明授权
    Targeted secure printing 失效
    目标安全打印

    公开(公告)号:US07003667B1

    公开(公告)日:2006-02-21

    申请号:US09411070

    申请日:1999-10-04

    IPC分类号: H04L9/00 H04K1/00 H04N1/44

    摘要: Secure transmission of data to an intended image output device, wherein the data can be used to generate an image at the intended image output device in the presence of an intended recipient. The data is encrypted using a first key. The first key is then encrypted using a second key and a third key. The second key is a public key of a first private key/public key pair, a private key of the first private key/public key pair being primarily in the sole possession of the intended image output device. The third key is a public key of a second private key/public key pair, a private key of the second private key/public key pair being primarily in the sole possession of the intended recipient of the image. The encrypted data and the twice-encrypted first key are transmitted to the intended image output device. The twice-encrypted first key is then decrypted by using the private keys of the second and first key pairs, respectively, which are primarily in the sole possession of the intended recipient device and the intended image output device, respectively. The data is then decrypted and printed at an image output device.

    摘要翻译: 将数据安全传输到预期的图像输出设备,其中数据可用于在预期接收者的存在下在预期图像输出设备处生成图像。 使用第一个密钥对数据进行加密。 然后使用第二密钥和第三密钥对第一密钥进行加密。 第二密钥是第一私钥/公开密钥对的公开密钥,第一私钥/公钥对的私钥主要由目标图像输出装置唯一拥有。 第三密钥是第二私钥/公开密钥对的公开密钥,第二私钥/公钥对的私钥主要由图像的预期接收方唯一拥有。 加密数据和两次加密的第一密钥被发送到预期的图像输出设备。 然后,通过分别使用第二和第一密钥对的专用密钥来解密两次加密的第一密钥,这两个密钥主要分别属于预期的接收方设备和预期的图像输出设备。 然后将数据解密并在图像输出装置上打印。

    Authenticated secure printing
    8.
    发明授权
    Authenticated secure printing 失效
    认证安全打印

    公开(公告)号:US06862583B1

    公开(公告)日:2005-03-01

    申请号:US09411665

    申请日:1999-10-04

    摘要: Authorized printout of an image corresponding to print data received at a print node from a network. The authorized printout comprises encrypting print data by a print node and storing the encrypted print data without printout, receiving authentication of an intended recipient to print the print data, and decrypting the encrypted print data by the print node and printing the decrypted print data by an image forming device, responsive to receipt of authentication in the receiving step. The print node may be the image forming device itself or a gateway to multiple image forming devices. The print node encrypts the print data with either a symmetric key or an asymmetric key.

    摘要翻译: 与从网络在打印节点接收的打印数据相对应的图像的授权打印输出。 授权的打印输出包括由打印节点加密打印数据,并且不打印输出来存储加密的打印数据,接收打印接收者的打印打印数据的认证,以及由打印节点对加密的打印数据进行解密,并通过打印数据打印解密的打印数据 图像形成装置,响应于在接收步骤中接收到认证。 打印节点可以是图像形成装置本身,也可以是到多个图像形成装置的网关。 打印节点用对称密钥或非对称密钥对打印数据进行加密。

    Obtaining temporary exclusive control of a device
    9.
    发明授权
    Obtaining temporary exclusive control of a device 有权
    获取设备的临时独占控制

    公开(公告)号:US07284061B2

    公开(公告)日:2007-10-16

    申请号:US09986795

    申请日:2001-11-13

    摘要: Remotely obtaining exclusive control of a device by remotely establishing communication with the device over a network, requesting to obtain remote exclusive control of the device's capabilities, and determining whether remote exclusive control of the device's capabilities can be obtained based on whether or not another user already has exclusive control of the device's capabilities. In a first case where it is determined that remote exclusive control can be obtained, authenticating a user requesting to obtain remote exclusive control of the device's capabilities, providing the user remote exclusive control of the device's capabilities after the user has been authenticated, and temporarily deferring requests by users other than the user who has obtained remote exclusive control to perform operations utilizing the device's capabilities during a period in which the user maintains remote exclusive control of the device's capabilities. In a second case where it is determined that remote exclusive control cannot be obtained, denying the user's request to obtain remote exclusive control, adding the user to a reservation queue of user's requesting to obtain exclusive control of the device, and when the user ascends in the reservation queue to be the next user to obtain exclusive control, the user is notified that he can now obtain remote exclusive control of the device.

    摘要翻译: 通过远程建立通过网络与设备进行通信的远程获取对设备的独占控制,请求获得对设备能力的远程独占控制,并且基于是否已经有另一用户确定是否可以获得设备的能力的远程独占控制 具有对设备功能的专有控制。 在确定可以获得远程排他控制的第一种情况下,认证请求获得设备能力的远程独占控制的用户,在用户被认证之后提供用户对设备能力的远程排他性控制,并暂时延迟 获得远程排他控制的用户之外的用户的请求,在用户维持对设备能力的远程独占控制的时间段期间利用设备的能力执行操作。 在确定不能获得远程排他控制的第二种情况下,拒绝用户获得远程专用控制的请求,将用户添加到请求获得设备的排他控制的用户的预约队列中,以及当用户上升时 预留队列作为下一个用户获得排他控制,通知用户他现在可以获得设备的远程独占控制权。