首页> 外国专利> Certificate echoing for session security

Certificate echoing for session security

机译:证书回显可确保会话安全

摘要

A client establishes a cryptographically protected communications session with a server. To detect a man-in-the-middle, the client echoes information about a certificate purportedly received from the server. The information echoed by the client is digitally signed so as to be verifiable by the server without any cryptographic key used in the cryptographically protected communications session or its establishment, thereby rendering the echoed information unmodifiable by a man-in-the-middle without invalidating the signature. The server can therefore verify both the echoed information and the digital signature to determine whether it has established a cryptographically protected communications session with the client or with a man-in-the-middle purporting to be the client.
机译:客户端与服务器建立受密码保护的通信会话。为了检测中间人,客户端回显有关据称从服务器接收到的证书的信息。客户端回显的信息经过数字签名,以便服务器可以验证,而无需在受密码保护的通信会话或其建立过程中使用任何加密密钥,从而使中间人无法修改回显的信息,而不会使密码无效。签名。因此,服务器可以验证回显的信息和数字签名,以确定它是否已与客户端或以中间人为客户端建立了受密码保护的通信会话。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号