首页> 外国专利> METHOD AND SYSTEM FOR STEPPING UP TO CERTIFICATE-BASED AUTHENTICATION WITHOUT BREAKING AN EXISTING SSL SESSION

METHOD AND SYSTEM FOR STEPPING UP TO CERTIFICATE-BASED AUTHENTICATION WITHOUT BREAKING AN EXISTING SSL SESSION

机译:在不破坏现有的SSL会话的情况下逐步进行基于证书的认证的方法和系统

摘要

A method is presented for performing authentication operations. When a clientrequests a resource from a server, a non-certificate~based authenticationoperation is performed through an SSL (Secure Sockets Layer) session betweenthe server and the client, When the client requests another resource, theserver determines to step up to a more restrictive level of authentication,and a certificate-based authentication operation is performed through the SSLsession without exiting or renegotiating the SSL session prior to completionof the certificate-based authentication operation. During the certificate-based authentication procedure, an executable module is downloaded to theclient from the server through the SSL session, after which the serverreceives through the SSL session a digital signature that has been generatedby the executable module using a digital certificate at the client. Inresponse to successfully verifying the digital signature at the server, theserver provides access to a requested resource.
机译:提出了一种用于执行认证操作的方法。当客户从服务器请求资源,非基于证书的身份验证通过SSL之间的SSL(安全套接字层)会话执行操作服务器和客户端,当客户端请求其他资源时,服务器决定提高身份验证的限制性,并通过SSL执行基于证书的身份验证操作会话,而无需在完成前退出或重新协商SSL会话基于证书的身份验证操作。在证明书中─基于身份验证过程,将可执行模块下载到服务器通过SSL会话从客户端开始,之后服务器通过SSL会话接收已生成的数字签名通过可执行模块使用客户端上的数字证书。在对在服务器上成功验证数字签名的响应,服务器提供对请求资源的访问。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号