会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 11. 发明授权
    • Systems and methods for non-interactive session key distribution with revocation
    • 具有撤销的非交互式会话密钥分发的系统和方法
    • US07400732B2
    • 2008-07-15
    • US10255964
    • 2002-09-27
    • Jessica N. StaddonThomas A. BersonMatthew FranklinSara MoreMichael MalkinRalph C. MerkleDirk Balfanz
    • Jessica N. StaddonThomas A. BersonMatthew FranklinSara MoreMichael MalkinRalph C. MerkleDirk Balfanz
    • H04L9/16
    • H04L9/0833H04L9/0891H04L2209/601
    • Systems and methods that allow the formation and distribution of session keys amongst a dynamic group of users communicating over an unreliable, or lossy, network. The systems and methods according to this invention allow an intermediate session key contained in an intermediate key distribution broadcast to be determined by receiving a preceding key distribution broadcast that precedes the intermediate key distribution broadcast, the preceding key distribution broadcast including a first portion of the intermediate session key; receiving a subsequent key distribution broadcast that follows the intermediate key distribution broadcast, the subsequent key distribution broadcast including a second portion of the intermediate session key that is distinct from the first portion; and combining at least the first portion of the intermediate session key contained within the preceding key distribution broadcast and the second portion of the intermediate session key contained within the subsequent key distribution broadcast to obtain the intermediate session key.
    • 允许在通过不可靠或有损耗的网络通信的动态用户组中形成和分发会话密钥的系统和方法。 根据本发明的系统和方法允许通过接收在中间密钥分配广播之前的先前密钥分发广播来确定包含在中间密钥分发广播中的中间会话密钥,前一密钥分发广播包括中间密钥分发广播的第一部分 会话密钥; 接收所述中间密钥分发广播之后的随后密钥分发广播,所述后续密钥分发广播包括与所述第一部分不同的所述中间会话密钥的第二部分; 以及组合至少包含在前述密钥分发广播中的中间会话密钥的第一部分和包含在后续密钥分发广播中的中间会话密钥的第二部分以获得中间会话密钥。
    • 15. 发明授权
    • Method, apparatus, and program product for enabling access to flexibly redacted content
    • 方法,装置和程序产品,用于访问灵活编辑的内容
    • US07865742B2
    • 2011-01-04
    • US11611845
    • 2006-12-15
    • Jessica N. StaddonPhilippe Jean-Paul Golle
    • Jessica N. StaddonPhilippe Jean-Paul Golle
    • G06F21/00
    • G06F21/6209G06Q20/3821H04L9/0847H04L9/085H04L9/3073
    • A capability key is generated that provides access to sensitive information within a selectively encrypted data unit created from an unencrypted data unit. A user specifies access rights as a monotone boolean relationship between a selection of a list of attributes related to the unencrypted data unit. This relationship is used to compute a key descriptor. Next one or more shares of a master secret is generated responsive to the monotone boolean relationship and a random number. Next a unique capability key is computed from one or more cryptosystem parameters, the one or more shares and the random number. The unique capability key and the key descriptor together enable decryption of sensitive information within a selectively encrypted data unit created from an unencrypted data unit. Finally, the unique capability key and the key descriptor are provided to allow decryption of sensitive information within the selectively encrypted data unit.
    • 生成能够提供对从未加密的数据单元创建的选择性加密的数据单元中的敏感信息的访问的能力密钥。 用户将访问权限指定为与未加密的数据单元相关的属性列表的选择之间的单调布尔关系。 该关系用于计算密钥描述符。 响应于单调布尔关系和随机数生成下一个主秘密的一个或多个共享。 接下来,从一个或多个密码系统参数,一个或多个共享和随机数计算独特的能力密钥。 唯一能力密钥和密钥描述符可以在从未加密的数据单元创建的选择性加密的数据单元中解密敏感信息。 最后,提供独特的能力密钥和密钥描述符,以允许对选择性加密的数据单元内的敏感信息进行解密。
    • 16. 发明授权
    • Method, apparatus, and program product for revealing redacted information
    • 方法,设备和程序产品,用于显示编辑信息
    • US07861096B2
    • 2010-12-28
    • US11611848
    • 2006-12-15
    • Jessica N. StaddonPhilippe Jean-Paul Golle
    • Jessica N. StaddonPhilippe Jean-Paul Golle
    • G09C1/00
    • G06F21/6209H04L9/085H04L2209/60
    • A selectively encrypted data unit includes an encrypted version of sensitive information (capable of being decrypted to reveal the sensitive information), a plurality of auxiliary values, and an attribute vector associated with the encrypted version of the sensitive information. The selectively encrypted data unit and a unique capability key are accessed. The unique capability key is associated with a key descriptor and is responsive to one or more cryptosystem parameters, one or more random numbers and one or more shares of a master secret. Next the technology determines whether the attribute vector is filtered or enabled by the key descriptor. If so, a protection key is acquired that is responsive to the one or more cryptosystem parameters, the plurality of auxiliary values, the key descriptor and the unique capability key. Once acquired, the protection key is used to decrypt the encrypted version to generate the sensitive information which is presented.
    • 选择性加密的数据单元包括敏感信息的加密版本(能够被解密以显示敏感信息),多个辅助值以及与敏感信息的加密版本相关联的属性向量。 访问选择性加密的数据单元和独特的能力密钥。 唯一能力密钥与密钥描述符相关联,并且响应于一个或多个密码系统参数,一个或多个随机数以及主秘密的一个或多个共享。 接下来,该技术确定属性向量是否被密钥描述符过滤或启用。 如果是,则获取响应于一个或多个密码系统参数,多个辅助值,密钥描述符和唯一能力密钥的保护密钥。 一旦获取,保护密钥用于解密加密版本,以产生呈现的敏感信息。
    • 19. 发明授权
    • Non-sensitive-passage database for cut-and-paste attack detection systems
    • 用于切割和粘贴攻击检测系统的非敏感通道数据库
    • US08402542B2
    • 2013-03-19
    • US12546493
    • 2009-08-24
    • Tracy H. KingPhilippe J. P. GolleJohn T. Maxwell, IIIJessica N. Staddon
    • Tracy H. KingPhilippe J. P. GolleJohn T. Maxwell, IIIJessica N. Staddon
    • H04L29/06
    • G06F21/6218
    • One embodiment provides a system that detects sensitive passages. During operation, the system receives a document and disassembles the document into a plurality of passages. For a respective passage, the system performs a search through a non-sensitive-passage database to determine whether the passage is a known non-sensitive passage. If so, the system marks the passage as non-sensitive, and if not, the system determines whether the passage triggers a cut-and-paste attack detection. If so, the system forwards the passage to an administrator and allows the administrator to determine whether the passage is non-sensitive and, further, to add the passage to the non-sensitive-passage database responsive to the administrator determining the passage to be non-sensitive.
    • 一个实施例提供了一种检测敏感通道的系统。 在操作期间,系统接收文档并将文档分解成多个通道。 对于相应的段落,系统通过非敏感通道数据库执行搜索,以确定通道是否是已知的非敏感通道。 如果是这样,系统会将通道标记为非敏感的,如果不是,系统会确定通道是否触发切割和粘贴攻击检测。 如果是这样,系统将该段落转发给管理员,并允许管理员确定该段落是否不敏感,并且进一步将该段落添加到非敏感段数据库中,以响应管理员确定该段落为非敏感段 -敏感。