首页> 外国专利> Provision of Active Management Technology (AMT) in computer systems

Provision of Active Management Technology (AMT) in computer systems

机译:在计算机系统中提供主动管理技术(AMT)

摘要

A method comprising: selecting a zero-touch provisioning function using an unsecured domain name server option in response to determining that a certificate hash is present and a provisioning pre-shared key is absent, wherein the zero-touch provisioning function is under Using the unsecured Domain Name Server option includes: sending an update command to a client device to verify that the client device supports Active Management Technology, generating a one-time password in a management console after receiving Active Management Technology values from a client device Storing the one-time password in a provisioning server and the client device, command to an Active Management Technology Unit to open a network interface to receive a device message, identifying the provisioning server if a full domain name is not available, authenticating A client device using the one-time password by receiving the one-time password from the client device and matching the one-time password received from the client device with the one-time password stored in the provisioning server, authenticating the provisioning server using a certificate chain by providing a self-signed certificate to the provisioning server, the client device the self-signed certificate and a keypair are generated, receiving the certificate chain-wide device message via the network interface, the certificate chain including a root-of-trust, and matching a hash value of the certificate chain with a plurality of stored hash values, verifying the provisioning server, and making a secure connection between the client device and the provisioning server, wherein the zero-touch provisioning function allows the secure connection between the client device and the provisioning server is established without initiation by a user of the client device.
机译:一种方法,包括:响应于确定存在证书哈希并且不存在供应预共享密钥,使用不安全的域名服务器选项来选择零接触供应功能,其中,所述零接触供应功能在使用所述不安全的保护下域名服务器选项包括:向客户端设备发送更新命令以验证客户端设备是否支持Active Management Technology;在从客户端设备接收到Active Management Technology值后,在管理控制台中生成一次性密码。供应服务器和客户端设备中的密码,命令Active Management Technology Unit打开网络接口以接收设备消息,如果没有完整域名,则标识供应服务器,使用一次身份验证客户端设备通过从客户端设备接收一次性密码并匹配从客户端设备收到的一次性密码具有一次性密码的客户端设备存储在预配置服务器中,通过向预配置服务器提供自签名证书,使用证书链对预配置服务器进行身份验证,生成自签名证书和密钥对的客户端设备,接收经由网络接口​​的证书链范围内的设备消息,证书链包括信任根,并将证书链的哈希值与多个存储的哈希值进行匹配,以验证供应服务器并建立安全连接在客户端设备和供应服务器之间建立安全连接,其中零接触供应功能允许在无需由客户端设备的用户发起的情况下建立客户端设备和供应服务器之间的安全连接。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号