首页> 外文期刊>Computer Networks >Providing secure mobile access to information servers with temporary certificates
【24h】

Providing secure mobile access to information servers with temporary certificates

机译:使用临时证书为信息服务器提供安全的移动访问

获取原文
获取原文并翻译 | 示例
           

摘要

This paper presents a solution that compatibilizes user mobility and secure access to information servers by means of X.509 certificates with a short validity period. The common approach to compatibilizing user mobility and secure access is based on removable tokens that hold cryptographic information. The use of these techniques restricts user mobility in several ways. Firstly, when specific hardware is required, it must be available in any computer the user may employ to connect from. Secondly, using software that must be added to well-known client programs means that the user must circumscribe to those hosts where the software is installed or install it on his/her own. The solution we present here does not impose any constraints on hardware and, since it is based on the thin client paradigm, software requirements are minimal. The application of X.509 certificates permits the use of (de facto) standard software for accessing the information. Furthermore, since the system uses short term certificates it does not necessitate the user eliminating any traces left behind in the client g any traces left behind in the client program after its use. Finally, the token (actually, a diskette) can be used with practically any computer, as it contains all the software and data needed for user authentication, and is based on a thin client written in an architecture-neutral language like Java. The requirements on the computer the user is connecting from are minimal: having a floppy drive and a Java virtual machine. An implementation of the framework described here is in use to provide authorized access to internal servers at CICA.
机译:本文提出了一种解决方案,该解决方案可通过有效期限较短的X.509证书来实现用户移动性和安全访问信息服务器的功能。使用户移动性和安全访问兼容的常见方法是基于保存密码信息的可移动令牌。这些技术的使用以多种方式限制了用户的移动性。首先,当需要特定的硬件时,它必须在用户可能用来连接的任何计算机上可用。其次,使用必须添加到知名客户端程序的软件意味着用户必须外接到安装了该软件的主机,或者自己安装该主机。我们在此介绍的解决方案不对硬件施加任何限制,并且由于它基于瘦客户机范例,因此对软件的要求最小。 X.509证书的应用允许使用(事实上)标准软件来访问信息。此外,由于系统使用短期证书,因此用户无需消除客户端中遗留的任何痕迹,也无需消除客户端程序使用后遗留在客户端程序中的任何痕迹。最后,令牌(实际上是软盘)几乎可以在任何计算机上使用,因为它包含用户身份验证所需的所有软件和数据,并且基于以与架构无关的语言(如Java)编写的瘦客户机。用户所连接的计算机上的要求是最低的:具有软盘驱动器和Java虚拟机。此处描述的框架的实现用于在CICA提供对内部服务器的授权访问。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号