会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 11. 发明授权
    • System and method for private secure financial transactions
    • 私人和安全金融交易的系统和方法
    • US07379916B1
    • 2008-05-27
    • US09706370
    • 2000-11-03
    • Len L. Mizrah
    • Len L. Mizrah
    • G06Q40/00G07F19/00G06F5/00
    • G06Q40/02G06Q20/04G06Q20/10G06Q20/108G06Q20/3823G06Q20/40G06Q20/425G06Q40/00G06Q40/025
    • A clocked authentication, authorization and accounting (CAAA) system and method offers private and secure credit/debit card online and offline financial transactions (FT) including an embedded privacy and security layer (EPSL) architecture. EPSL includes an authentication stage prior to the authorization stage that is automated and enabled through a back office, and enhanced by associating the authentication stage with projected timing, security and accounting parameters. It enables legal financial account holders to perform buy/sell or withdraw/deposit transactions without disclosing private personal information to the transaction counterparts, while preserving highly elevated and enhanced security and fraud protection as compared with conventional methods. The CAAA method enables efficient mass user EPSL implementation at back offices utilizing high frequency synchronized global clocking of EPSL logic blocks.
    • 计时认证,授权和会计(CAAA)系统和方法提供私人和安全的信用卡/借记卡在线和离线金融交易(FT),包括嵌入式隐私和安全层(EPSL)架构。 EPSL包括在授权阶段之前的认证阶段,其通过后台自动化和启用,并且通过将认证阶段与预计的时间安排和安全性和会计参数相关联来增强。 它使得法定财务账户持有人可以在不向交易对手披露私人个人信息的情况下执行买/卖或提取/存款交易,同时保持与传统方法相比高度提升和增强的安全性和欺诈保护。 CAAA方法可以利用EPSL逻辑块的高频同步全局时钟在后台实现高效的大量用户EPSL。
    • 12. 发明授权
    • Key conversion method for communication session encryption and authentication system
    • 通信会话加密和认证系统的密钥转换方法
    • US07299356B2
    • 2007-11-20
    • US10653500
    • 2003-09-02
    • Len L. Mizrah
    • Len L. Mizrah
    • H04L9/00
    • H04L63/061H04L9/0822H04L9/0844H04L63/08H04L63/0869
    • An interactive mutual authentication protocol, which does not allow shared secrets to pass through untrusted communication media, integrates an encryption key management system into the authentication protocol. The server encrypts a particular data random key by first veiling the particular data random key using a first conversion array seeded by a shared secret, and then encrypting the veiled particular data random key. The client decrypts and unveils the particular data random key using the shared secret, and returns a similarly veiled version of the particular data random key using a second conversion array seeded by a shared secret. Access to the shared secret indicates authenticity of the stations. The procedure may be repeated for a second shared secret for strong authentication, without allowing shared secrets to pass via untrusted media.
    • 不允许共享秘密通过不信任通信介质的交互式互认认证协议将加密密钥管理系统集成到认证协议中。 服务器通过首先使用由共享密钥接收的第一转换阵列来掩蔽特定数据随机密钥来加密特定数据随机密钥,然后加密掩蔽的特定数据随机密钥。 客户端使用共享秘密解密并发布特定数据随机密钥,并使用由共享密钥种子的第二转换阵列返回特定数据随机密钥的类似遮蔽版本。 访问共享密钥表示站点的真实性。 可以针对第二共享秘密重复该过程以进行强认证,而不允许共享秘密通过不受信任的媒体。
    • 14. 发明授权
    • Method of one time authentication response to a session-specific challenge indicating a random subset of password or PIN character positions
    • 一种针对特定于会话的挑战的一次认证响应的方法,指示密码或PIN字符位置的随机子集
    • US07681228B2
    • 2010-03-16
    • US11353560
    • 2006-02-14
    • Len L. Mizrah
    • Len L. Mizrah
    • G06F7/04G06F17/30H04L9/32H04K1/00G06K5/00H04L29/06G06Q40/00
    • G06Q40/02G06Q20/04G06Q20/10G06Q20/108G06Q20/3823G06Q20/40G06Q20/425G06Q40/00G06Q40/025
    • Financial institution back office computerized transaction-processing system with embedded privacy and security layer (EPSL) enables strong transaction authentication prior to a merchant or vendor contact, based on a user account number, transaction conditions like anticipated transaction time and money, user two-factor authentication with a static transaction PIN and a transaction session-specific random partial password or PIN recognition algorithm. User enters the user name and then, challenged by server with a random session-specific subset of a password or PIN character's consecutive position numbers, enters based on cognitive association a one time authentication response. The authentication session is interactive, transaction session-specific, and followed by either a transaction denial or an alphanumeric transaction signature generated by EPSL for this specific transaction. Then, the user submits her request to a transaction counterpart along with the transaction signature. The merchant or vendor requests an authorization session with EPSL.
    • 具有嵌入式隐私和安全层(EPSL)的金融机构后台计算机化交易处理系统可以在商家或供应商联系之前,根据用户帐号,诸如预期交易时间和金额之类的交易条件,用户双因素 使用静态事务PIN和事务会话特定的随机部分密码或PIN识别算法进行认证。 用户输入用户名,然后由具有密码或PIN字符的连续位置号码的随机会话特定子集的服务器挑战,基于认知关联进行一次认证响应。 认证会话是交互式的,事务会话特定的,后面是EPSL为此特定事务生成的事务拒绝或字母数字事务签名。 然后,用户将其请求与交易签名一起提交给交易对方。 商家或供应商请求与EPSL的授权会话。
    • 15. 发明授权
    • System and method for user authentication interface
    • 用户认证接口的系统和方法
    • US07188314B2
    • 2007-03-06
    • US10353500
    • 2003-01-29
    • Len L. Mizrah
    • Len L. Mizrah
    • H04L9/32G06F7/04
    • H04L63/08G06F21/31G06F21/36
    • A graphical user interface supports an interactive client-server authentication based on Random Partial Pattern Recognition algorithm (RPPR). In RPPR, an ordered set of data fields is stored for a client to be authenticated in secure memory on the server side. A graphical user interface presents a clue generated at the server to the client, such positions in the ordered set of a random subset of data fields from the ordered set. The client enters input data in multiple fields of the interface according to the clue, and the server accepts the input data from the client. The input data includes storage units representing alpha-numeric characters, images and colors corresponding to the field contents for the data fields. The interface includes indicators for elapsed time and status of the authentication session.
    • 图形用户界面支持基于随机部分模式识别算法(RPPR)的交互式客户端 - 服务器认证。 在RPPR中,存储一组有序数据字段以供客户端在服务器端的安全内存中进行身份验证。 图形用户界面向客户端呈现在服务器处产生的线索,来自有序集合的数据字段的随机子集的有序集合中的位置。 客户根据线索在接口的多个字段中输入输入数据,服务器接受来自客户端的输入数据。 输入数据包括表示与数据字段的字段内容相对应的字母数字字符,图像和颜色的存储单元。 该接口包括经过时间和认证会话状态的指示符。
    • 16. 发明授权
    • Two-channel challenge-response authentication method in random partial shared secret recognition system
    • 随机部分共享秘密识别系统中的双向质询 - 响应认证方法
    • US08006300B2
    • 2011-08-23
    • US11552500
    • 2006-10-24
    • Len L. Mizrah
    • Len L. Mizrah
    • G06F21/00
    • G06F21/36G06F21/42G06F2221/2103H04L9/3215H04L9/3271H04L63/08H04L63/18H04L2209/60H04L2209/80
    • Random partial shared secret recognition is combined with using more than one communication channel between server-side resources and two logical or physical client-side data processing machines. After a first security tier, a first communication channel is opened to a first data processing machine on the client side. The session proceeds by delivering an authentication challenge, identifying a random subset of an authentication credential, to a second data processing machine on the client side using a second communication channel. Next, the user enters an authentication response in the first data processing machine, based on a random subset of the authentication credential. The authentication response is returned to the server side on the first communication channel for matching. The authentication credential can be a one-session-only credential delivered to the user for one session, or a static credential used many times.
    • 随机部分共享秘密识别与服务器端资源和两个逻辑或物理客户端数据处理机之间的多个通信信道相结合。 在第一安全层之后,向客户端的第一数据处理机打开第一通信信道。 会话通过使用第二通信信道向客户端侧的第二数据处理机器递送认证挑战(识别认证凭证的随机子集)。 接下来,用户基于认证凭证的随机子集在第一数据处理机器中输入认证响应。 认证响应返回到第一通信信道上的服务器侧进行匹配。 身份验证凭证可以是一次会话传递给用户的一会话凭据,也可以是多次使用静态凭据。
    • 17. 发明授权
    • Operation modes for user authentication system based on random partial pattern recognition
    • 基于随机部分模式识别的用户认证系统的操作模式
    • US07577987B2
    • 2009-08-18
    • US10378226
    • 2003-03-03
    • Len L. Mizrah
    • Len L. Mizrah
    • H04L9/32
    • H04L63/08G06F21/31G06F21/36H04L63/102
    • A system for authentication of a client includes logic supporting a “what user knows” algorithm for authentication of a client, such as a random partial pattern recognition algorithm, based upon client credentials including an account user name and an account authentication code. Logic supporting client account administration is operable without human intervention on the server side, and includes at least one mode of operation that presents an interface to a client via the data network having at least two tiers of security based on input by the client of secret information shared only between the client and the server. A first tier in said at least two tiers requires entry of one of the account user name and user's email address, and a second tier in the at least two tiers requires entry of one of client profile data sufficient to identify the client and at least a subset of said account authentication code.
    • 用于客户端验证的系统包括基于包括帐户用户名和帐户认证码的客户端证书支持用户认证的“用户知道”算法的逻辑,诸如随机部分模式识别算法。 支持客户帐户管理的逻辑可在没有人为干预的情况下在服务器侧进行操作,并且包括至少一种操作模式,其经由具有至少两层安全性的数据网络向客户端呈现基于客户机秘密信息的输入 仅在客户端和服务器之间共享。 所述至少两个层中的第一层需要输入帐户用户名和用户的电子邮件地址之一,并且所述至少两个层中的第二层需要输入足以识别客户端的客户端简档数据之一,并且至少要 所述帐户认证码的子集。
    • 18. 发明申请
    • AUTHENTICATION METHOD OF RANDOM PARTIAL DIGITIZED PATH RECOGNITION WITH A CHALLENGE BUILT INTO THE PATH
    • 随机部分数字路径识别的确认方法与挑战性建立在路径中
    • US20080072045A1
    • 2008-03-20
    • US11466697
    • 2006-08-23
    • Len L. Mizrah
    • Len L. Mizrah
    • H04L9/00
    • G06F21/83G06F21/36
    • An interactive method for authentication is based on two shared secrets, including a first shared secret in the form of an ordered path on the frame of reference, and a second shared secret in the form of locations on the frame of reference at which characters identifying a subset of the ordered path are to be displayed. An instance of the frame of reference comprises a set of characters which is arranged in a random or other irregular pattern. Authentication requires that a user enter the characters in the displayed instance of the frame of reference found in the locations in the random subset of the ordered path by indicating characters either in these locations, or any other locations having the same characters. Thus, a secret challenge identifying the random partial subset is embedded within the displayed instance of the graphical representation of the frame of reference.
    • 用于认证的交互方法基于两个共享秘密,包括在参考帧上以有序路径的形式的第一共享秘密,以及在参考帧上的位置形式的第二共享秘密,其中字符识别 要显示有序路径的子集。 参考框架的实例包括以随机或其他不规则图案排列的一组字符。 认证要求用户通过在这些位置或具有相同字符的任何其他位置指示字符来输入在有序路径的随机子集中的位置中找到的参考帧的显示实例中的字符。 因此,识别随机部分子集的秘密挑战被嵌入在参考帧的图形表示的所显示的实例内。
    • 19. 发明授权
    • Authentication system and method based upon random partial pattern recognition
    • 基于随机部分模式识别的认证系统和方法
    • US07644433B2
    • 2010-01-05
    • US10328640
    • 2002-12-23
    • Len L. Mizrah
    • Len L. Mizrah
    • G06F7/04G06F17/30H04L9/32
    • H04L63/08G06F21/31G06F21/36
    • An interactive client-server authentication system and method are based on Random Partial Pattern Recognition algorithm (RPPR). In RPPR, an ordered set of data fields is stored for a client to be authenticated in secure memory. An authentication server presents a clue to the client via a communication medium, such positions in the ordered set of a random subset of data fields from the ordered set. The client enters input data in multiple fields according to the clue, and the server accepts the input data from the client via a data communication medium. The input data corresponds to the field contents for the data fields at the identified positions of the random subset of data fields. The server then determines whether the input data matches the field contents of corresponding data fields in a random subset.
    • 交互式客户端 - 服务器认证系统和方法是基于随机部分模式识别算法(RPPR)。 在RPPR中,存储一组有序数据字段以供客户端在安全存储器中进行身份验证。 认证服务器通过通信介质向客户端提供线索,来自有序集合的数据字段的随机子集的有序集合中的位置。 客户根据线索输入多个字段的输入数据,服务器通过数据通信媒介从客户端接受输入数据。 输入数据对应于数据字段的随机子集的识别位置处的数据字段的字段内容。 然后,服务器确定输入数据是否与随机子集中相应数据字段的字段内容匹配。