Protecting web application data
    1.
    发明授权
    Protecting web application data 失效
    保护Web应用程序数据

    公开(公告)号:US08285778B2

    公开(公告)日:2012-10-09

    申请号:US12491647

    申请日:2009-06-25

    IPC分类号: G06F15/16

    CPC分类号: H04L63/123

    摘要: A method, system and an article of manufacture tangibly embodying a computer readable program for protecting Web application data between a server and a client. A response created by the Web application for the client is backed up and modified by adding capturing code for capturing a user action, user data of the client, or combination thereof. The modified response is sent to the client and a request submitted by the client and the user action and/or user data captured by the capturing code is received. A verifying request is generated according to the received user action and/user data captured by the capturing code and the backup of the response. The request submitted by the client is verified according to the verifying request and the verified request is sent to the Web application of the server.

    摘要翻译: 一种有形地体现用于在服务器和客户端之间保护Web应用数据的计算机可读程序的方法,系统和制品。 通过添加用于捕获用户动作,客户端的用户数据或其组合的捕获代码来备份和修改由Web应用程序为客户端创建的响应。 经修改的响应被发送给客户端,并且接收由客户端提交的请求以及由捕获代码捕获的用户操作和/或用户数据。 根据由捕获代码捕获的接收到的用户动作和/用户数据以及响应的备份,生成验证请求。 客户端提交的请求将根据验证请求进行验证,并将验证的请求发送到服务器的Web应用程序。

    PROTECTING WEB APPLICATION DATA
    2.
    发明申请
    PROTECTING WEB APPLICATION DATA 失效
    保护WEB应用数据

    公开(公告)号:US20090327411A1

    公开(公告)日:2009-12-31

    申请号:US12491647

    申请日:2009-06-25

    IPC分类号: G06F15/16 G06F12/00 G06F17/30

    CPC分类号: H04L63/123

    摘要: A method, system and an article of manufacture tangibly embodying a computer readable program for protecting Web application data between a server and a client. A response created by the Web application for the client is backed up and modified by adding capturing code for capturing a user action, user data of the client, or combination thereof. The modified response is sent to the client and a request submitted by the client and the user action and/or user data captured by the capturing code is received. A verifying request is generated according to the received user action and/user data captured by the capturing code and the backup of the response. The request submitted by the client is verified according to the verifying request and the verified request is sent to the Web application of the server.

    摘要翻译: 一种有形地体现用于在服务器和客户端之间保护Web应用数据的计算机可读程序的方法,系统和制品。 通过添加用于捕获用户动作,客户端的用户数据或其组合的捕获代码来备份和修改由Web应用程序为客户端创建的响应。 经修改的响应被发送给客户端,并且接收由客户端提交的请求以及由捕获代码捕获的用户操作和/或用户数据。 根据由捕获代码捕获的接收到的用户动作和/用户数据以及响应的备份,生成验证请求。 客户端提交的请求将根据验证请求进行验证,并将验证的请求发送到服务器的Web应用程序。

    Secure apparatus and method for protecting integrity of software system and system thereof
    3.
    发明授权
    Secure apparatus and method for protecting integrity of software system and system thereof 失效
    用于保护软件系统完整性的安全装置和方法及其系统

    公开(公告)号:US08407481B2

    公开(公告)日:2013-03-26

    申请号:US12163797

    申请日:2008-06-27

    CPC分类号: G06F21/125

    摘要: Provided is a secure apparatus for protecting the integrity of a software system and a method thereof. The apparatus comprises: a template repository for storing templates required for generating an agent module; a template generator for randomly selecting one template from said template repository and generating a new agent module according to the selected template; and a transceiver for sending said new agent module to an external apparatus communicating with said secure apparatus to update a current agent module which is running in said external apparatus, wherein said current agent module is used to verify the integrity of said software system running in said external apparatus. The secure apparatus can protect software in an insecure environment with a high software protection level to prevent the software from being tampered or bypassed.

    摘要翻译: 提供一种用于保护软件系统的完整性的安全装置及其方法。 该装置包括:用于存储生成代理模块所需的模板的模板存储库; 模板生成器,用于从所述模板存储库中随机选择一个模板,并根据所选模板生成新的代理模块; 以及收发器,用于将所述新代理模块发送到与所述安全装置通信的外部设备,以更新在所述外部设备中运行的当前代理模块,其中所述当前代理模块用于验证在所述外部设备中运行的所述软件系统的完整性 外部设备 安全设备可以在具有高软件保护级别的不安全环境中保护软件,以防止软件被篡改或绕过。

    SECURE APPARATUS AND METHOD FOR PROTECTING INTEGRITY OF SOFTWARE SYSTEM AND SYSTEM THEREOF
    4.
    发明申请
    SECURE APPARATUS AND METHOD FOR PROTECTING INTEGRITY OF SOFTWARE SYSTEM AND SYSTEM THEREOF 失效
    用于保护软件系统及其系统的完整性的安全设备和方法

    公开(公告)号:US20090327745A1

    公开(公告)日:2009-12-31

    申请号:US12163797

    申请日:2008-06-27

    IPC分类号: G06F21/00 G06F12/14

    CPC分类号: G06F21/125

    摘要: Provided is a secure apparatus for protecting the integrity of a software system and a method thereof. The apparatus comprises: a template repository for storing templates required for generating an agent template; a template generator for randomly selecting one template from said template repository and generating a new agent template according to the selected template; and a transceiver for sending said new agent module to an external apparatus communicating with said secure apparatus to update a current agent module which is running in said external apparatus, wherein said current agent module is used to verify the integrity of said software system running in said external apparatus. The secure apparatus can protect software in an insecure environment with a high software protection level to prevent the software from being tampered or bypassed.

    摘要翻译: 提供一种用于保护软件系统的完整性的安全装置及其方法。 该装置包括:用于存储生成代理模板所需的模板的模板存储库; 模板生成器,用于从所述模板存储库中随机选择一个模板,并根据所选模板生成新的代理模板; 以及收发器,用于将所述新代理模块发送到与所述安全装置通信的外部设备,以更新在所述外部设备中运行的当前代理模块,其中所述当前代理模块用于验证在所述外部设备中运行的所述软件系统的完整性 外部设备 安全设备可以在具有高软件保护级别的不安全环境中保护软件,以防止软件被篡改或绕过。

    Method of dynamically providing a compound object's source information during its development
    5.
    发明授权
    Method of dynamically providing a compound object's source information during its development 失效
    在开发过程中动态提供复合对象的源信息的方法

    公开(公告)号:US08024315B2

    公开(公告)日:2011-09-20

    申请号:US12249472

    申请日:2008-10-10

    IPC分类号: G06F17/30

    摘要: A method and system for dynamically providing a composite source information report whenever source information of a composite object is updated. The system includes a subscription handler for receiving a subscription request and generating a subscription query, a means for determining whether source information of an element in a composite object has been edited (added, deleted and/or modified), a source information determining handler for automatically determining source information of an element in a composite object and a composite source information report generation handler for generating a composite source information report and providing the report to users. The system further comprises an authentication handler, an editing handler, an editing monitor, a source information recording handler, subscription source information retrieving handler and a server database.

    摘要翻译: 每当更新复合对象的源信息时动态地提供复合源信息报告的方法和系统。 该系统包括用于接收订阅请求并生成订阅查询的订阅处理程序,用于确定复合对象中的元素的源信息是否已被编辑(添加,删除和/或修改)的装置,源信息确定处理程序,用于 自动确定复合对象中的元素的源信息和用于生成复合源信息报告并将报告提供给用户的复合源信息报告生成处理程序。 该系统还包括认证处理程序,编辑处理程序,编辑监视器,源信息记录处理程序,订阅源信息检索处理程序和服务器数据库。

    METHOD OF DYNAMICALLY PROVIDING A COMPOUND OBJECT'S SOURCE INFORMATION DURING IT'S DEVELOPMENT
    6.
    发明申请
    METHOD OF DYNAMICALLY PROVIDING A COMPOUND OBJECT'S SOURCE INFORMATION DURING IT'S DEVELOPMENT 失效
    在发展过程中动态提供化合物对象的来源信息的方法

    公开(公告)号:US20090089262A1

    公开(公告)日:2009-04-02

    申请号:US12249472

    申请日:2008-10-10

    IPC分类号: G06F17/30

    摘要: A method and system for dynamically providing a composite source information report whenever source information of a composite object is updated. The system includes a subscription handler for receiving a subscription request and generating a subscription query, a means for determining whether source information of an element in a composite object has been edited (added, deleted and/or modified), a source information determining handler for automatically determining source information of an element in a composite object and a composite source information report generation handler for generating a composite source information report and providing the report to users. The system further comprises an authentication handler, an editing handler, an editing monitor, a source information recording handler, subscription source information retrieving handler and a server database.

    摘要翻译: 每当更新复合对象的源信息时动态地提供复合源信息报告的方法和系统。 该系统包括用于接收订阅请求并生成订阅查询的订阅处理程序,用于确定复合对象中的元素的源信息是否已被编辑(添加,删除和/或修改)的装置,源信息确定处理程序,用于 自动确定复合对象中的元素的源信息和用于生成复合源信息报告并将报告提供给用户的复合源信息报告生成处理程序。 该系统还包括认证处理程序,编辑处理程序,编辑监视器,源信息记录处理程序,订阅源信息检索处理程序和服务器数据库。

    Method for source-related risk detection and alert generation
    7.
    发明授权
    Method for source-related risk detection and alert generation 有权
    与源相关的风险检测和警报生成方法

    公开(公告)号:US08171458B2

    公开(公告)日:2012-05-01

    申请号:US12249511

    申请日:2008-10-10

    IPC分类号: G06F9/44

    CPC分类号: G06F8/71

    摘要: A method and system for detecting a source-related risk and generating an alert concerning the source-related risk are disclosed. Criteria of the source-related risk are defined. Thresholds associated with the source-related risk are defined. Every operation on an object is detected. If an operation on an object satisfies a criterion among the criteria or if the operation causes to exceed a threshold among the thresholds, an alert is generated for the operation.

    摘要翻译: 公开了一种用于检测源相关风险并产生与源相关风险有关的警报的方法和系统。 定义与源相关风险的标准。 定义与源相关风险相关的阈值。 检测到对象上的每个操作。 如果对象上的操作满足标准中的标准,或者如果操作导致阈值之间超过阈值,则为该操作生成警报。

    METHOD FOR SOURCE-RELATED RISK DETECTION AND ALERT GENERATION
    8.
    发明申请
    METHOD FOR SOURCE-RELATED RISK DETECTION AND ALERT GENERATION 有权
    用于与源相关的风险检测和警报发生的方法

    公开(公告)号:US20100095277A1

    公开(公告)日:2010-04-15

    申请号:US12249511

    申请日:2008-10-10

    IPC分类号: G06F9/44

    CPC分类号: G06F8/71

    摘要: A method and system for detecting a source-related risk and generating an alert concerning the source-related risk are disclosed. Criteria of the source-related risk are defined. Thresholds associated with the source-related risk are defined. Every operation on an object is detected. If an operation on an object satisfies a criterion among the criteria or if the operation causes to exceed a threshold among the thresholds, an alert is generated for the operation.

    摘要翻译: 公开了一种用于检测源相关风险并产生与源相关风险有关的警报的方法和系统。 定义与源相关风险的标准。 定义与源相关风险相关的阈值。 检测到对象上的每个操作。 如果对象上的操作满足标准中的标准,或者如果操作导致阈值之间超过阈值,则为操作生成警报。

    METHOD AND APPARATUS FOR DIGITAL RIGHTS MANAGEMENT
    9.
    发明申请
    METHOD AND APPARATUS FOR DIGITAL RIGHTS MANAGEMENT 审中-公开
    数字权限管理方法与装置

    公开(公告)号:US20130007894A1

    公开(公告)日:2013-01-03

    申请号:US13611394

    申请日:2012-09-12

    IPC分类号: G06F21/24

    摘要: A method and apparatus for digital rights management (DRM) with steps and means for receiving a registration request from one of a plurality of DRM agent devices requesting to register one of a plurality of user accounts and the one DRM agent device to one of a plurality of rights issuers, completing a registration process in the one rights issuer, including establishment of a relationship among the one user account, the one DRM agent device and the one rights issuer; and returning a registration completion response to the one DRM agent device. The invention provides support to the many-to-many relationships among DRM entities, such as DRM agent device, user account and rights issuer, so that the DRM system can be applied to more business modes.

    摘要翻译: 一种用于数字版权管理(DRM)的方法和装置,其具有步骤和装置,用于从多个DRM代理设备之一接收请求将多个用户帐户中的一个注册并将一个DRM代理设备注册到多个 的权利发行人,完成一个发行人的注册过程,包括建立一个用户帐户,一个DRM代理设备和一个发行者之间的关系; 并向所述一个DRM代理设备返回注册完成响应。 本发明提供对诸如DRM代理设备,用户帐户和权限发布者之类的DRM实体之间的多对多关系的支持,使得DRM系统可以应用于更多的业务模式。

    METHOD AND APPARATUS FOR OBTAINING WORKING INFORMATION IN SOFTWARE ENGINEERING
    10.
    发明申请
    METHOD AND APPARATUS FOR OBTAINING WORKING INFORMATION IN SOFTWARE ENGINEERING 审中-公开
    在软件工程中获取工作信息的方法和装置

    公开(公告)号:US20120317539A1

    公开(公告)日:2012-12-13

    申请号:US13590705

    申请日:2012-08-21

    IPC分类号: G06F9/44

    CPC分类号: G06F8/71 G06F8/30

    摘要: A method for obtaining working information in software engineering is provided. The method includes generating a sensor for a software tool used in software engineering according to data storage manner of the software tool, where the sensor detects artifact change events associated with the software tool; and collecting the artifact change events from the sensor and analyzing at least one attribute of the artifact change events to obtain the working information. Also provided is an article of manufacture for carrying out the method for obtaining working information in software engineering as described in this application.

    摘要翻译: 提供了一种软件工程中获取工作信息的方法。 该方法包括根据软件工具的数据存储方式生成用于软件工程中的软件工具的传感器,其中传感器检测与软件工具相关联的工件变化事件; 以及从所述传感器收集所述伪影改变事件,并且分析所述伪像改变事件的至少一个属性以获得所述工作信息。 还提供了一种用于执行在本申请中描述的用于获得软件工程中的工作信息的方法的制造商品。