1460737377-012cadd7-fac5-4a17-8d2a-7bb5431c27cf

1. In a portable electronic authorization device (PEAD) with inaccessible storage of a user’s private key, a method for approving a transaction request originating from an electronic transaction system, comprising:
receiving at said portable electronic authorization device first digital data, said first digital data representing said transaction request; and
if said transaction request is approved by a user of said portable electronic authorization device, decrypting the user private key using a decryption key stored at and transmitted to the PEAD from a remote server, and transmitting a second digital data to said electronic transaction system, said second digital data being encrypted by said user private key but without transmission of the private key alone.
2. In an electronic authorization system with inaccessible storage of a user’s private key, at a portable electronic authorization device (PEAD) a method for approving a transaction request originating from an electronic transaction system, comprising:
receiving at said electronic authorization system first digital data, said first digital data representing said transaction request; and
if said transaction request is approved by a user of said electronic authorization system, decrypting the user private key using a decryption key stored at and transmitted to the PEAD from a remote server, transmitting a second digital data to said electronic transaction system, said second digital data being encrypted by said user private key but without transmission of the private key alone.
3. A method as claimed in claim 1 wherein decrypting the user private key includes sending a request from the PEAD to the server including a password from the user of the PEAD but not including transmission of the user’s private key to the server.
4. A method as claimed in claim 3 wherein the request includes transmitting a user password or pass phrase.
5. A method as claimed in claim 4 wherein the password or pass phrase is keyed in at the PEAD.
6. A method as claimed in claim 5 wherein if the password or pass phrase provided to the server is incorrect, the PEAD is informed and the event is recorded.
7. A method as claimed in claim 6 wherein once a certain number of failures due to an uncorrected password or pass phrase have occurred, the users account associated with the private key is deactivated.
8. A method as claimed in claim 7 wherein upon deactivation of the account, the server will refuse to provide the decryption key.
9. A method as claimed in claim 1 wherein the user private key is stored in the PEAD encrypted with a symmetric key scheme.
10. A method as claimed in claim 9 wherein the symmetric key scheme is 3DES.
11. A method as claimed in claim 10 wherein the 3DES key is stored in the remote server associated with an authorization test password or pass phrase for the user.
12. A method as claimed in claim 11 wherein whenever the user needs to authorize a transaction, the user inputs the password or pass phrase at a keyboard at the PEAD.
13. A method as claimed in claim 12 where upon the password or pass phrase being keyed into the PEAD, it is transmitted to the remote server, the remote server returning the symmetric key to the PEAD for decrypting the private key.
14. A method as claimed in claim 13 wherein after finishing the signing process, both the 3DES key and the plain private key, the password or pass phrase entered by the user are deleted from the PEAD.
15. A method as claimed in claim 14 wherein the remote server will monitor and detect any unauthorized attempted access of the symmetric key stored at the server, and notifies the PEAD user through e-mail alert, phone call or message alert.
16. A method as claimed in claim 2 wherein decrypting the user private key includes sending a request from the electronic authorization system to the server including a password from the user of the electronic authorization system.
17. A method as claimed in claim 16 wherein the request includes transmitting a user password or pass phrase.
18. A method as claimed in claim 17 wherein the password or pass phrase is keyed in at the electronic authorization system.
19. A method as claimed in claim 18 wherein if the password or pass phrase provided to the server is incorrect, the electronic authorization system is informed and the event is recorded.
20. A method as claimed in claim 19 wherein once a certain number of failures due to an uncorrected password or pass phrase have occurred, the users account associated with the private key is deactivated.
21. A method as claimed in claim 20 wherein upon deactivation of the account, the server will refuse to provide the decryption key.
22. A method as claimed in claim 2 wherein the user private key is stored in the electronic authorization system encrypted with a symmetric key scheme.
23. A method as claimed in claim 22 wherein the symmetric key scheme is 3DES.
24. A method as claimed in claim 23 wherein the 3DES key is stored in the remote server associated with an authorization test password or pass phrase for the user.
25. A method as claimed in claim 24 wherein whenever the user needs to authorize a transaction, the user inputs the password or pass phrase at a keyboard at the electronic authorization system.
26. A method as claimed in claim 25 where upon the password or pass phrase being keyed into the electronic authorization system, it is transmitted to the remote server, the remote server returning the symmetric key to the electronic authorization system for decrypting the private key.
27. A method as claimed in claim 26 wherein after finishing the signing process, both the 3DES key and the plain private key, the password or pass phrase entered by the user are deleted from the electronic authorization system.
28. A method as claimed in claim 27 wherein the remote server will monitor and detect any unauthorized attempted access of the symmetric key stored at the server, and notifies the electronic authorization system user through e-mail alert, phone call or message alert.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method of establishing a tunnel from a first interface between a first network and a second network to a second interface between the second network and a third network, the first and third networks operating in accordance with a first transmission protocol and having addresses in accordance with a first addressing convention, and the second network operating in accordance with a second transmission protocol and having addresses in accordance with a second addressing convention, the tunnel being for the transport of messages from a first host on the first network to a second host on the third network, the method comprising:
sending from the first host an address request message in accordance with the first transmission protocol, referred to herein as a first type address request message, containing the name of the second host;
upon receipt of the address request message at a name to address conversion system of the third network, returning an address response message in accordance with the first transmission protocol, referred to herein as a first type address response message, and containing the address of the second host in a response address field;
upon receipt of that first type address response message at the second interface,
converting it to an address response message in accordance with the second transmission protocol, referred to herein as a second type address response message; and
augmenting that converted second type address response message by fields respectively containing the address of the second interface in accordance with the second addressing convention and the address of the second host in accordance with the first addressing convention; and

upon receipt of that augmented that converted second type address response message at the first interface,
converting it to a first type address response message,
retrieving the contents of the augmenting fields,
storing at the first interface a mapping of the retrieved address of the second host and the retrieved address of the second interface for use in encapsulating messages from the first host addressed to the second host, and
replacing the content of the response address field of the resulting first type address response message by the retrieved address of the second host.
2. A method as in claim 1, wherein for establishing a tunnel in the reverse direction for the transport of messages from the second host to the first host, the method further comprises:
upon receipt at the first interface of a message from the first host addressed to the second host, encapsulating that received message in accordance with the first mapping; and
upon receipt of the encapsulated message at the second interface,
un-encapsulating that received encapsulated message,
retrieving from the encapsulating header the address of the first interface in accordance with the second addressing convention,
retrieving from the un-encapsulated message the address of the first host in accordance with the first addressing convention, and
storing at the second interface a mapping of the retrieved address of the first host and the retrieved address of the first interface for use in encapsulating messages from the second host addressed to the first host.
3. A method as in claim 1, including setting a time to live for a said stored mapping, and rendering that stored mapping unuseable upon the expiry of the time to life.
4. A method as in claim 3, wherein the rendering step deletes that stored mapping.
5. A method of sending packets from a first host on a first network via a second network to a second host on a third network, the first and third networks operating in accordance with a first transmission protocol and having addresses in accordance with a first addressing convention, and the second network operating in accordance with a second transmission protocol and having addresses in accordance with a second addressing convention, comprising:
establishing a tunnel from a first interface between the first network and the second network to a second interface between the second network and the third network in accordance with the method of claim 1;
upon receipt by the first host of the resulting first type address response message from the first interface, retrieving the content of the response address field;
generating one or more packets for transmission having a header including source and destination address fields, the source address field containing the address of the first host, and the destination address field containing the retrieved content of the response address field;
sending the or each generated packet to the first interface;
for the or each said generated packet received by the first interface, accessing the stored mappings in accordance with the destination address of the received generated packet,
retrieving the stored interface address of the mapping whose retrieved host address matches the destination address of the received generated packet,
generating an encapsulated packet having a payload formed by the received generated packet, and having a header including source and destination address fields, the source address field containing the address of the first interface, and the destination address field containing the retrieved interface network address,
sending the encapusulated packet to the second interface; and

for the or each encapsulated packet received by the second interface, un-encapsulating the received encapsulated packet to recover the original generated packet forming its payload, and
sending that recovered packet to the second host.
6. A method as in claim 5, including storing the retrieved content in association with the name of the second host.
7. A method as in claim 6, including offsetting a time to live for the stored retrieved content, and rendering that stored retrieved content unuseable upon the expiry of the time to live.
8. A method as in claim 7, wherein the rendering step deletes the stored retrieved content.

1460737369-ecec64e5-2ac4-428f-90b7-9d2398e2fc0b

1. A method of providing a user interface to a user, comprising:
displaying a plurality of display areas on a screen, wherein each display area displays at least one control subject;
positioning a pointing object onto one of the control subjects, and
moving the pointing object between the display areas when a move command is input.
2. The method of claim 1, further comprising performing a control operation on the control subject located in the display area where the pointing object is positioned by inputting a control signal.
3. The method of claim 1, wherein the control subject comprises a menu which controls a portable broadcast-receiving device.
4. The method of claim 3, wherein the control subject further comprises a sub-menu which controls a display area.
5. The method of claim 1, wherein the control subject comprises at least one of video, audio, and data broadcasts.
6. The method of claim 1, wherein the pointing object comprises an icon representing a two-dimensional figure.
7. The method of claim 1, wherein the pointing object comprises an icon representing a three-dimensional figure.
8. The method of claim 1, wherein at least one of the pointing object’s shape, form, color, and brightness changes over time andor when the pointing object is moved.
9. An apparatus which provides a user interface, comprising:
a display control module, comprising:
a plurality of display areas which display control subjects, wherein each display area displays at least one control subject, and
a pointing object control module which moves a pointing object displayed on one display area to another display area when a move command is input.
10. The apparatus of claim 9, further comprising a function control module which performs a control operation on a control subject on which the pointing object is located when a control signal is input.
11. The apparatus of claim 8, wherein the control subject comprises a menu which controls a portable broadcast-receiving device.
12. The apparatus of claim 11, wherein the control subject further comprises a sub-menu which controls a display area.
13. The apparatus of claim 9, wherein the control subject comprises at least one of video, audio, and data broadcasts.
14. The apparatus of claim 9, wherein the pointing object comprises an icon which represents a two-dimensional figure.
15. The apparatus of claim 9, wherein the pointing object comprises an icon which represents a three-dimensional figure.
16. The apparatus of claim 9, wherein at least one of the pointing object’s shape, form, color, and brightness changes over time andor when the pointing object is moved.
17. A method of providing a user interface to a user, comprising:
receiving a plurality of digital broadcasts with a portable broadcast receiving device;
displaying the plurality of digital broadcasts in a corresponding plurality of display areas displayed on a screen of the portable broadcast receiving device; and
using a pointing object control module to move a pointing object between the display areas to select different digital broadcasts.
18. The method of claim 17, further comprising entering a command onto the display area which the pointing object is located on by pressing a function button located on the portable broadcast-receiving device.
19. The method of claim 18, wherein the entering of the command enlarges the display area.
20. The method of claim 17, wherein the plurality of digital broadcasts comprises at least one of digital video, digital audio, and digital data broadcasts.
21. The method of claim 17, wherein the pointing object comprises an icon which represents a two-dimensional icon.
22. The method of claim 17, wherein the pointing object comprises an icon which represents a three-dimensional icon.
23. The method of claim 17, wherein at least one of the pointing object’s shape, form, color, and brightness changes over time andor when the pointing object is moved.
24. An apparatus which provides a user interface, comprising:
a portable broadcast receiving device which receives a digital broadcast, comprising:
a display panel which displays the digital broadcast in a display area, and
a pointing object control module, wherein a movement of the pointing object control module causes a corresponding movement of a pointing object which allows a user to navigate the pointing object around the display area.
25. The apparatus of claim 24, further comprising a function control module which performs a control operation on the display area on which the pointing object is located when a control signal is input.
26. The apparatus of claim 25, wherein the display area displays a menu which controls the portable broadcast-receiving device.
27. The apparatus of claim 26, wherein the menu displays a sub-menu when the pointing object is moved onto the menu by the user.
28. The apparatus of claim 24, wherein the display area displays at least one of video, audio, and data broadcasts.
29. The apparatus of claim 24, wherein the pointing object comprises an icon which represents a two-dimensional figure.
30. The apparatus of claim 24, wherein the pointing object comprises an icon which represents a three-dimensional figure.
31. The apparatus of claim 24, wherein at least one of the pointing object’s shape, form, color, and brightness changes over time andor when the pointing object is moved.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method for producing a bonded silicon wafer comprising a step of implanting oxygen ions from one-side face of a silicon wafer for active layer with a substrate oxygen concentration of 10\xd71017cm3 to 18\xd71017cm3 (old ASTM conversion) sliced so as to have such a wafer face that an inclination angle \u03b8 (compound angle) with respect to a face perpendicular to <100> orientation or <110> orientation of a silicon single crystal ingot is 0\xb0<\u03b8\u22660.15\xb0 to form an oxygen ion implanted layer at a given depth position from the one-side face of the silicon wafer for active layer;
a step of bonding the one-side face of the silicon wafer for active layer to one-side face of a silicon wafer for support to form a silicon wafer composite;
a first heat treatment step of heat-treating the silicon wafer composite to strengthen the bonding and to convert the oxygen ion implanted layer into an inner SiO2 layer;
a step of exposing the inner SiO2 layer from other face of the silicon wafer for active layer in the silicon wafer composite;
a step of removing the inner SiO2 layer; and
a planarizing step of polishing a surface of the silicon wafer composite after the removal of the inner SiO2 layer or subjecting the silicon wafer composite to a heat treatment in a reducing atmosphere (a second heat treatment step) to improve a flatness of the silicon wafer composite.
2. A method for producing a bonded silicon wafer according to claim 1, wherein the silicon wafer for active layer is a p-type silicon wafer.
3. A method for producing a bonded silicon wafer according to claim 2, wherein the p-type silicon wafer contains boron as an electrically conductive component.
4. A method for producing a bonded silicon wafer according to claim 1, wherein the given depth position of the oxygen ion implantation is a depth position of 300 to 600 nm from the one-side face of the silicon wafer for active layer.
5. A method for producing a bonded silicon wafer according to claim 1, wherein the silicon wafer composite is formed by indirectly bonding the one-side face of the silicon wafer for active layer to the silicon wafer for support through an insulating layer previously formed on the one-side face of the silicon wafer for support.
6. A method for producing a bonded silicon wafer according to claim 1, wherein the silicon wafer composite is formed by directly bonding the one-side face of the silicon wafer for active layer to the silicon wafer for support without an insulating layer.
7. A method for producing a bonded silicon wafer according to claim 1, wherein the first heat treatment step is conducted within a temperature region of 1000 to 1300\xb0 C.
8. A method for producing a bonded silicon wafer according to claim 1, wherein the second heat treatment step is conducted within a temperature region of 1000 to 1200\xb0 C.