【24h】

Replacement of Lost User Certificates for instant IS access

机译:替换丢失的用户证书以立即访问IS

获取原文
获取原文并翻译 | 示例

摘要

This paper focuses on a practical aspect of employing user certificates for strong authentication in web based systems. As soon as users are dependent on X.509-certificates to access important resources as e.g. corporate information systems there has to be a fast workflow for securely replacing previously issued certificates in the possible case of loss or theft. The ordinary way to issue certificates is too time consuming, since it takes too much time, including checks, to determine whether a person has the right to obtain a certificate and to make sure that he or she is the one who is allowed to get this certificate. If a valid certificate is lost or stolen, the primary task is revoking the old unusable certificate and certifying a new key pair. Therefore, we suggest a workflow involving two priviledged colleagues to certify the identity of a third employee who has no access to his or her certificate. This workflow is currently being implemented in one and under consideration for deployment in another large PKI-project in Europe.
机译:本文着重于在基于Web的系统中使用用户证书进行强身份验证的实践方面。用户一旦依赖X.509证书即可访问重要资源,例如公司信息系统必须有一个快速的工作流程,以在可能丢失或失窃的情况下安全地替换以前颁发的证书。颁发证书的普通方法非常耗时,因为要花费很多时间(包括检查)来确定一个人是否有权获得证书并确保他或她是被允许获得证书的人。证书。如果有效证书丢失或被盗,则主要任务是撤销旧的不可用证书并验证新的密钥对。因此,我们建议使用由两个特权同事组成的工作流来验证无法访问其证书的第三名员工的身份。该工作流程目前正在一个实施中,正在考虑在欧洲的另一个大型PKI项目中进行部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号