首页> 外国专利> System and method for stepping up to certificate-based authentication without disrupting existing SSL session

System and method for stepping up to certificate-based authentication without disrupting existing SSL session

机译:在不中断现有SSL会话的情况下提高基于证书的身份验证的系统和方法

摘要

A method is presented for performing authentication operations. When a client requests a resource from a server, a non-certificate-based authentication operation is performed through an SSL (Secure Sockets Layer) session between the server and the client. When the client requests another resource, the server determines to step up to a more restrictive level of authentication, and a certificate-based authentication operation is performed through the SSL session without exiting or renegotiating the SSL session prior to completion of the certificate-based authentication operation. During the certificate-based authentication procedure, an executable module is downloaded to the client from the server through the SSL session, after which the server receives through the SSL session a digital signature that has been generated by the executable module using a digital certificate at the client. In response to successfully verifying the digital signature at the server, the server provides access to a requested resource.
机译:提出了一种用于执行认证操作的方法。当客户端从服务器请求资源时,将通过服务器和客户端之间的SSL(安全套接字层)会话来执行基于非证书的身份验证操作。当客户端请求其他资源时,服务器将决定提高身份验证的限制性,并在完成基于证书的身份验证之前通过SSL会话执行基于证书的身份验证操作,而无需退出或重新协商SSL会话操作。在基于证书的身份验证过程中,可执行模块通过SSL会话从服务器下载到客户端,然后服务器通过SSL会话接收由可执行模块使用数字证书在服务器上生成的数字签名。客户。响应于在服务器上成功验证数字签名,服务器提供对所请求资源的访问。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号