-
公开(公告)号:JPH11154140A
公开(公告)日:1999-06-08
申请号:JP23887398
申请日:1998-08-25
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
IPC: G07D9/00 , G06F1/00 , G06F21/00 , G06F21/20 , G06F21/22 , G06Q20/34 , G06Q20/40 , G07F7/10 , G09C1/00 , H04L9/08 , H04L9/32 , G06F15/00 , G06F19/00
Abstract: PROBLEM TO BE SOLVED: To provide a method for controlling access to service which is electronically supplied and a method for supplying improved security and flexibility by generating a decoding key from individual data supplied by a user and accessing to a requested service by decoding the associated application module. SOLUTION: Partial key data 5 is read from a card indicated by the user and is supplied to a key generator 7. Then, the decoding key is generated and is supplied to a decoding service module 2 through a bus 3. The decoding service module 2 is the software module which is usually formed to control a processing unit and decodes a selected applet under the control of the decoding key supplied through the bus 3. The decoded applet is supplied to a register 6 through a bus 4 and it controls the operation of requested service.
-
公开(公告)号:AU2002321589A1
公开(公告)日:2003-06-30
申请号:AU2002321589
申请日:2002-09-02
Applicant: IBM
Inventor: ORCHARD JAMES RONALD LEWIS
Abstract: A method and system for preparing multimedia content, whereby the multimedia content comprises at least one file, comprising content data and associated security functions. The content data further comprises associated characteristics. The system comprises at least one server machine comprising storage for storing the file, at least one client machine comprising means for rendering the file and a network. Firstly, the client machine requests the file (e.g. a movie file). Next, the server machine determines whether it has the file stored in memory. If the file is present, the file's associated security functions (e.g. encryption etc.) are obtained and the file's content data is analyzed to obtain the associated characteristics (e.g. bit rate etc.). Finally, the associated security functions and the associated characteristics are combined into a data structure.
-
公开(公告)号:GB2329499B
公开(公告)日:2001-05-30
申请号:GB9719881
申请日:1997-09-19
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
IPC: G07D9/00 , G06F1/00 , G06F21/00 , G06F21/20 , G06F21/22 , G06Q20/34 , G06Q20/40 , G07F7/10 , G09C1/00 , H04L9/08 , H04L9/32 , G06F12/14
Abstract: The security and integrity of card initiated transactions are improved by encrypting processes involved in such transactions and controlling access to the processes by developing decryption keys partially from data derived from a card presented by an intending user and partially from personal data supplied by the user. In an embodiment a hierarchy of security levels provides for users of different authority to access selected processes.
-
公开(公告)号:GB2329499A
公开(公告)日:1999-03-24
申请号:GB9719881
申请日:1997-09-19
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
IPC: G07D9/00 , G06F1/00 , G06F21/00 , G06F21/20 , G06F21/22 , G06Q20/34 , G06Q20/40 , G07F7/10 , G09C1/00 , H04L9/08 , H04L9/32 , G06F12/14
Abstract: The security and integrity of card initiated transactions are improved by encrypting processes involved in such transactions and controlling access to the processes by developing decryption keys partially from data derived from a card presented by an intending user and partially from personal data supplied by the user. In an embodiment a hierarchy of security levels provides for users of different authority to access selected processes.
-
公开(公告)号:GB2326315B
公开(公告)日:2002-05-29
申请号:GB9711890
申请日:1997-06-10
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
Abstract: In a distributed data processing system each component is provided with an object orientated platform together with instantiations of a generic network object for each application involving data transmission, enabling it to run a multiplexing/demultiplexing object appropriate to each application being processed. This effectively provides multiple concurrent data "pipes" over a single physical/logical connection.
-
公开(公告)号:GB2329497A
公开(公告)日:1999-03-24
申请号:GB9719874
申请日:1997-09-19
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
Abstract: The security of stored data and applications is improved by an access control system and method in which user keys for accessing the stored data/services (which keys are provided to users) are representative of the user's level of authority, such that there is no need to maintain a separate lookup table of user authority levels. This removes a potential security exposure from the system. The user keys are advantageously hierarchical, including data for generating a plurality of different access keys for different access levels. The access keys may be decryption keys for encrypted data or application programs. The invention is applicable to SmartCard systems.
-
公开(公告)号:GB2328042A
公开(公告)日:1999-02-10
申请号:GB9715744
申请日:1997-07-26
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
Abstract: A method of executing a transaction between a smartcard and an external terminal adapted to access related data comprises determining from the data stored on the smartcard and the related data whether the transaction can be executed validly; if so, executing the transaction and in the event of the smartcard or the external terminal failing to execute the transaction, restoring 108 the smartcard data and the related data to their pre-transaction states. The smartcard may use a Java environment in which, before the determining steps are carried out, a stream of references to objects is created 100 which update 102 data in the transaction and when the transaction is complete the references are removed. A smartcard is also provided including means to determine whether a transaction can be validly executed and commit means to execute the transaction, together with a transaction processing system including such a smartcard and a terminal.
-
公开(公告)号:GB2442273A
公开(公告)日:2008-04-02
申请号:GB0619203
申请日:2006-09-29
Applicant: IBM
Inventor: COLGRAVE JOHN , ORCHARD JAMES RONALD LEWIS , WHITTINGHAM GARY OWEN
IPC: G06F21/60
Abstract: A system provides a number of resources, some of which are subjected to security policies and some of which are not. For secured resources a policy specifying how the resource may be used and by whom is drawn up as usual (Fig. 4a). The system then creates a complementary policy which specifies that all users can use the resource (Fig. 4b). For unsecured resources no security policies are created. When access to a resource is requested 302 the normal policy is checked in the normal fashion 304 and access allowed 306 or denied as usual. If usual access is denied then the complementary policy is checked 310, however the result of this check is inverted. That is, where a policy allows blanket access the access is denied 314 . Whereas where there is no access policy the access is allowed 312. In this fashion access to the unsecured resources with no security policies is facilitated (Fig. 4c).
-
公开(公告)号:GB2328042B
公开(公告)日:2002-10-09
申请号:GB9715744
申请日:1997-07-26
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
Abstract: A method of executing a transaction on a smartcard of the type including a processor, a memory for storing a system program, an application programs and for storing data and an interface enabling communication with an external processor in a local terminal adapted to access related data is disclosed. The method comprises the steps of: determining from the data stored on the smartcard in a pre-transaction state if the transaction can be executed validly by the smartcard (102); determining from the related data stored in a pre-transaction state and accessible by said external processor if the transaction can be executed validly by the external processor (102); in response to said determining steps being affirmative, executing said transaction on said smartcard and by said external processor (105); and in response to said smartcard or said external processor failing to execute said transaction, restoring said data and said related data to the or each pre-transaction state (108).
-
10.
公开(公告)号:GB2329497B
公开(公告)日:2001-01-31
申请号:GB9719874
申请日:1997-09-19
Applicant: IBM
Inventor: LAMBERT HOWARD SHELTON , ORCHARD JAMES RONALD LEWIS
-
-
-
-
-
-
-
-
-