会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明申请
    • AUTHORIZING ACCESS TO AN APPLICATION LIBRARY
    • 授权访问应用程序库
    • US20160219055A1
    • 2016-07-28
    • US14982869
    • 2015-12-29
    • Paul Hilliar
    • Paul Hilliar
    • H04L29/06
    • H04L63/10H04L9/0816H04L9/3228H04L63/0428H04L63/06H04L2209/80
    • To prevent malicious code from accessing security sensitive functions implemented in a private portion of an application, accesses to the private portion are performed using a secure session established within the application between the private portion and a public portion of the same application. An authorization key can be shared between the public portion and the private portion. When the public portion attempts to invoke a function implemented in the private portion, a secure session is set up by generating a session ID, combining the session ID and the authorization key in a key derivation function to generate a conversation key, and using the conversation key to encrypt the function call from the public potion. The private portion can then decrypt a properly encrypted function call and invoke the appropriate function.
    • 为了防止恶意代码访问在应用程序的私有部分中实现的安全敏感功能,使用在同一应用程序的私有部分和公共部分之间的应用程序中建立的安全会话来执行对私有部分的访问。 公共部分和私有部分之间可以共享授权密钥。 当公共部分尝试调用在私有部分中实现的功能时,通过产生会话ID来建立安全会话,该会话ID在密钥导出功能中组合会话ID和授权密钥以生成会话密钥,并且使用会话 从公共药水加密功能调用的关键。 私有部分可以解密正确加密的函数调用并调用适当的函数。