Obtaining temporary exclusive control of a device
    2.
    发明授权
    Obtaining temporary exclusive control of a device 有权
    获取设备的临时独占控制

    公开(公告)号:US07284061B2

    公开(公告)日:2007-10-16

    申请号:US09986795

    申请日:2001-11-13

    摘要: Remotely obtaining exclusive control of a device by remotely establishing communication with the device over a network, requesting to obtain remote exclusive control of the device's capabilities, and determining whether remote exclusive control of the device's capabilities can be obtained based on whether or not another user already has exclusive control of the device's capabilities. In a first case where it is determined that remote exclusive control can be obtained, authenticating a user requesting to obtain remote exclusive control of the device's capabilities, providing the user remote exclusive control of the device's capabilities after the user has been authenticated, and temporarily deferring requests by users other than the user who has obtained remote exclusive control to perform operations utilizing the device's capabilities during a period in which the user maintains remote exclusive control of the device's capabilities. In a second case where it is determined that remote exclusive control cannot be obtained, denying the user's request to obtain remote exclusive control, adding the user to a reservation queue of user's requesting to obtain exclusive control of the device, and when the user ascends in the reservation queue to be the next user to obtain exclusive control, the user is notified that he can now obtain remote exclusive control of the device.

    摘要翻译: 通过远程建立通过网络与设备进行通信的远程获取对设备的独占控制,请求获得对设备能力的远程独占控制,并且基于是否已经有另一用户确定是否可以获得设备的能力的远程独占控制 具有对设备功能的专有控制。 在确定可以获得远程排他控制的第一种情况下,认证请求获得设备能力的远程独占控制的用户,在用户被认证之后提供用户对设备能力的远程排他性控制,并暂时延迟 获得远程排他控制的用户之外的用户的请求,在用户维持对设备能力的远程独占控制的时间段期间利用设备的能力执行操作。 在确定不能获得远程排他控制的第二种情况下,拒绝用户获得远程专用控制的请求,将用户添加到请求获得设备的排他控制的用户的预约队列中,以及当用户上升时 预留队列作为下一个用户获得排他控制,通知用户他现在可以获得设备的远程独占控制权。

    LONG TERM KEY ESTABLISHMENT FOR EMBEDDED DEVICES
    4.
    发明申请
    LONG TERM KEY ESTABLISHMENT FOR EMBEDDED DEVICES 审中-公开
    嵌入式设备的长期关键设备

    公开(公告)号:US20090240942A1

    公开(公告)日:2009-09-24

    申请号:US12052592

    申请日:2008-03-20

    IPC分类号: H04L9/00

    CPC分类号: H04L9/0841 G06F21/606

    摘要: A secure communication session is established between a first device and a second device, by generating, in the first device, a first secret key to be utilized for communication sessions with other devices. The second device requests to establish a first communication session with the first device, and the second device generates a second secret key corresponding to the first secret key of the first device. The second device stores the generated second secret key in a non-volatile memory of the second device, the second secret key being stored in the non-volatile memory in association with an identifier of the first device. Finally, a secure communication session is established between the first and second devices utilizing the first and second secret keys.

    摘要翻译: 通过在第一设备中生成用于与其他设备的通信会话的第一秘密密钥,在第一设备和第二设备之间建立安全通信会话。 第二设备请求与第一设备建立第一通信会话,并且第二设备生成与第一设备的第一密钥对应的第二密钥。 第二设备将生成的第二秘密密钥存储在第二设备的非易失性存储器中,第二密钥与第一设备的标识符相关联地存储在非易失性存储器中。 最后,使用第一和第二秘密密钥在第一和第二设备之间建立安全通信会话。

    Secure printing with authenticated printer key
    5.
    发明授权
    Secure printing with authenticated printer key 失效
    通过验证的打印机密钥进行安全打印

    公开(公告)号:US07305556B2

    公开(公告)日:2007-12-04

    申请号:US10010974

    申请日:2001-12-05

    IPC分类号: H04L9/00

    摘要: Securely storing a public key for encryption of data in a computing device by using a user-specific key pair which is securely stored in the computing device, including receiving a target public key corresponding to a target device, obtaining a user-specific key pair from a secure registry, using a user-specific private key from the user-specific key pair to create a target key verifier based on the target public key, storing the target key verifier and the target public key in a storage area, retrieving the target key verifier and the target public key from the storage area, applying a user-specific public key from the user-specific key pair to the target key verifier for verifying the authenticity of the target public key, and encrypting data with the target public key, if authenticity of the target public key is verified, thereby creating encrypted data for transmission to the target device.

    摘要翻译: 通过使用安全地存储在计算设备中的用户专用密钥对来安全地存储用于数据加密的公钥,包括接收与目标设备相对应的目标公开密钥,从 安全注册表,使用来自用户特定密钥对的用户专用私钥,基于目标公开密钥创建目标密钥验证者,将目标密钥验证者和目标公开密钥存储在存储区域中,检索目标密钥 验证者和来自存储区域的目标公开密钥,将用户专用密钥对应用于目标密钥验证器,用于验证目标公钥的真实性,以及用目标公钥加密数据,如果 验证目标公开密钥的真实性,由此创建用于传输到目标设备的加密数据。

    Automatic generation of a new encryption key
    7.
    发明授权
    Automatic generation of a new encryption key 失效
    自动生成新的加密密钥

    公开(公告)号:US07111322B2

    公开(公告)日:2006-09-19

    申请号:US10309896

    申请日:2002-12-05

    IPC分类号: G06F4/00

    摘要: A device (such as a printer or a network device that may be connected to the printer) that is connected to a network and which performs secure operations using an existing encryption keypair maintained within the device, generates a new encryption keypair within the device by receiving a request from another device on the network to provide an encryption key of the existing encryption keypair to the another device. In response to the request, the device determines whether an encryption key of the existing encryption keypair within the device is valid. In a case where it is determined that the encryption key of the existing encryption keypair is invalid, the device automatically deletes each key of the existing encryption keypair from the device, generates a new encryption keypair within the device and stores the new encryption keypair in the device. The device then provides a new encryption key corresponding to the requested encryption key of the new encryption keypair to another device.

    摘要翻译: 连接到网络并使用维护在设备内的现有加密密钥对进行安全操作的设备(诸如可能连接到打印机的打印机或网络设备)通过接收来产生设备内的新的加密密钥对 来自网络上的另一设备的请求,以向现有加密密钥对提供另一设备的加密密钥。 响应于该请求,设备确定设备内现有加密密钥对的加密密钥是否有效。 在确定现有加密密钥对的加密密钥无效的情况下,设备自动从设备中删除现有加密密钥对的每个密钥,在设备内生成新的加密密钥对,并将新的加密密钥对存储在 设备。 然后,设备向另一设备提供与新加密密钥对的所请求的加密密钥相对应的新加密密钥。

    Targeted secure printing
    8.
    发明授权
    Targeted secure printing 失效
    目标安全打印

    公开(公告)号:US07003667B1

    公开(公告)日:2006-02-21

    申请号:US09411070

    申请日:1999-10-04

    IPC分类号: H04L9/00 H04K1/00 H04N1/44

    摘要: Secure transmission of data to an intended image output device, wherein the data can be used to generate an image at the intended image output device in the presence of an intended recipient. The data is encrypted using a first key. The first key is then encrypted using a second key and a third key. The second key is a public key of a first private key/public key pair, a private key of the first private key/public key pair being primarily in the sole possession of the intended image output device. The third key is a public key of a second private key/public key pair, a private key of the second private key/public key pair being primarily in the sole possession of the intended recipient of the image. The encrypted data and the twice-encrypted first key are transmitted to the intended image output device. The twice-encrypted first key is then decrypted by using the private keys of the second and first key pairs, respectively, which are primarily in the sole possession of the intended recipient device and the intended image output device, respectively. The data is then decrypted and printed at an image output device.

    摘要翻译: 将数据安全传输到预期的图像输出设备,其中数据可用于在预期接收者的存在下在预期图像输出设备处生成图像。 使用第一个密钥对数据进行加密。 然后使用第二密钥和第三密钥对第一密钥进行加密。 第二密钥是第一私钥/公开密钥对的公开密钥,第一私钥/公钥对的私钥主要由目标图像输出装置唯一拥有。 第三密钥是第二私钥/公开密钥对的公开密钥,第二私钥/公钥对的私钥主要由图像的预期接收方唯一拥有。 加密数据和两次加密的第一密钥被发送到预期的图像输出设备。 然后,通过分别使用第二和第一密钥对的专用密钥来解密两次加密的第一密钥,这两个密钥主要分别属于预期的接收方设备和预期的图像输出设备。 然后将数据解密并在图像输出装置上打印。

    Authenticated secure printing
    9.
    发明授权
    Authenticated secure printing 失效
    认证安全打印

    公开(公告)号:US06862583B1

    公开(公告)日:2005-03-01

    申请号:US09411665

    申请日:1999-10-04

    摘要: Authorized printout of an image corresponding to print data received at a print node from a network. The authorized printout comprises encrypting print data by a print node and storing the encrypted print data without printout, receiving authentication of an intended recipient to print the print data, and decrypting the encrypted print data by the print node and printing the decrypted print data by an image forming device, responsive to receipt of authentication in the receiving step. The print node may be the image forming device itself or a gateway to multiple image forming devices. The print node encrypts the print data with either a symmetric key or an asymmetric key.

    摘要翻译: 与从网络在打印节点接收的打印数据相对应的图像的授权打印输出。 授权的打印输出包括由打印节点加密打印数据,并且不打印输出来存储加密的打印数据,接收打印接收者的打印打印数据的认证,以及由打印节点对加密的打印数据进行解密,并通过打印数据打印解密的打印数据 图像形成装置,响应于在接收步骤中接收到认证。 打印节点可以是图像形成装置本身,也可以是到多个图像形成装置的网关。 打印节点用对称密钥或非对称密钥对打印数据进行加密。

    Security against replay attacks of messages
    10.
    发明授权
    Security against replay attacks of messages 有权
    消息的重放攻击的安全

    公开(公告)号:US07552476B2

    公开(公告)日:2009-06-23

    申请号:US10875240

    申请日:2004-06-25

    IPC分类号: G06F12/14 G06F12/16

    摘要: Security against replay of a message by generating a list of unique message enabling codes (TATs) in a first device and storing the list in a second device. A message generated in the first device, which includes at least one of the unique message enabling codes from the list, is transmitted to the second device. The unique message enabling code of the received message is compared with the list stored in the second device to determine whether or not to enable processing of the message by the second device. If the unique message enabling code received with the message is included in the stored list, processing of the message is enabled and, the corresponding unique message enabling code is deleted from the stored list. If the unique message enabling code received with the message is not included in the stored list, processing of the message is rejected.

    摘要翻译: 通过在第一设备中生成唯一消息启用代码(TAT)的列表并将列表存储在第二设备中来保护消息的重放。 在第一设备中生成的包括来自列表的唯一消息启用代码中的至少一个的消息被发送到第二设备。 将接收到的消息的启用代码的唯一消息与存储在第二设备中的列表进行比较,以确定是否允许由第二设备处理消息。 如果使用消息接收到的唯一消息使能码被包括在存储的列表中,则消息的处理被启用,并且从存储的列表中删除相应的唯一消息使能码。 如果使用消息接收的唯一消息使能码不包括在存储的列表中,则消息的处理被拒绝。