首页> 外国专利> SYSTEM AND METHOD FOR AUTHENTICATING CLIENTS IN A CLIENT-SERVER ENVIRONMENT

SYSTEM AND METHOD FOR AUTHENTICATING CLIENTS IN A CLIENT-SERVER ENVIRONMENT

机译:在客户端服务器环境中对客户端进行身份验证的系统和方法

摘要

The idea of the present invention is to replace the existing password/user ID based authentication process by a new digital signature authentication process in which preferably the first HTTP-request header is extended by the client authentication information independently of the authentication process used by the destination server and without server requesting authentication information. The authentication information preferably includes the client certificate containing the client public key, signed by certification authority, and preferably a hash value calculated over the HTTP-request header data being sent in the request, and encrypted with the Client's private key. The certificate and digital signature may be added during the creation of the HTTP-request header in the client system itself, or may be added later in a server acting as a gateway, proxy, or tunnel. A destination server that does not support the new digital signature authentication process will simply ignore the certificate and digital signature in the HTTP-request header and will automatically initiate its own authentication process. The present invention simplifies the existing digital signature authentication process and concurrently allows the coexistence of different authentication processes without changing the HTTP-protocol or causing unnecessary network traffic.
机译:本发明的思想是用新的数字签名认证过程代替现有的基于口令/用户ID的认证过程,其中优选地,第一HTTP请求报头由客户端认证信息扩展,而与目的地使用的认证过程无关。服务器且服务器不请求认证信息。认证信息优选地包括客户端证书,该客户端证书包含由证书颁发机构签名的,包含客户端公共密钥的客户端证书,并且优选地包括根据在请求中发送的HTTP请求头数据计算出的,并用客户端的私钥加密的哈希值。证书和数字签名可以在客户端系统本身的HTTP请求标头创建过程中添加,也可以稍后在充当网关,代理或隧道的服务器中添加。不支持新的数字签名身份验证过程的目标服务器将仅忽略HTTP请求标头中的证书和数字签名,并将自动启动其自己的身份验证过程。本发明简化了现有的数字签名认证过程,并同时允许不同认证过程的共存,而无需改变HTTP协议或引起不必要的网络业务。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号