首页> 外国专利> Method and system for a flexible lightweight public-key-based mechanism for the GSS protocol

Method and system for a flexible lightweight public-key-based mechanism for the GSS protocol

机译:GSS协议的基于灵活轻量级基于公钥的机制的方法和系统

摘要

A method for establishing a secure context for communicating messages between a client and a server is presented that is compliant with the Generic Security Service application programming interface (GSS-API). The client sends to the server a first message containing a first symmetric secret key generated by the client and an authentication token; the first message is secured with the public key from the server's public key certificate. After the server authenticates the client based on the authentication token, the client then receives from the server a second message that has been secured with the first symmetric secret key and that contains a second symmetric secret key. The client and the server employ the second symmetric secret key to secure subsequent messages sent between the client and the server. The authentication token may be a public key certificate associated with the client, a username-password pair, or a secure ticket.
机译:提出了一种用于建立在客户端和服务器之间传递消息的安全上下文的方法,该方法符合通用安全服务应用程序编程接口(GSS-API)。客户端向服务器发送第一消息,该第一消息包含客户端生成的第一对称密钥和认证令牌;第一条消息由服务器的公共密钥证书中的公共密钥保护。服务器根据身份验证令牌对客户端进行身份验证之后,客户端便会从服务器接收第二消息,该消息已由第一对称密钥保护并包含第二对称密钥。客户端和服务器使用第二对称密钥来保护客户端和服务器之间发送的后续消息。认证令牌可以是与客户端关联的公钥证书,用户名-密码对或安全票证。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号