首页> 外国专利> Certificate-based authentication system for heterogeneous environments

Certificate-based authentication system for heterogeneous environments

机译:基于证书的异构环境认证系统

摘要

In one embodiment, methods and apparatus for an operator of a console to authenticate to a system of heterogeneous computers by logging in only once to a representative computer or “core”. After logging in, the operator acquires a session certificate (e.g., an X.509-based certificate), allowing the operator to prove identity and group membership information to other nodes on a network. The core, before signing session certificates, embeds data in an extended data area of the certificates. The extended data includes the operator's username and groups to which the operator belongs, and possibly other information such operator context (or domain). The username, group membership, and other extended data is based on the namespace of the core computer, and other devices on the network need not belong to that namespace or even use the same network operating system. Manageable devices can authenticate and authorize access to themselves based on the extended data submitted to them by the bearer of a session certificate. Authenticity and ownership of the certificate is verified using standard public key cryptosystem methods. In some embodiments, manageable devices verify operator authorization by cross-referencing operator identity and group membership information in the certificate with an appropriate access control list (or equivalent data structure). In some embodiments, manageable devices are pre-configured to trust at least one core by giving it the public key of the core, and the core can direct the manageable device to trust other cores.
机译:在一个实施例中,一种用于控制台的操作员通过仅登录一次代表计算机或“核心”而向异构计算机系统进行认证的方法和装置。登录后,运营商获取会话证书(例如,基于X.509的证书),从而允许运营商向网络上的其他节点证明身份和组成员身份信息。在签署会话证书之前,核心将数据嵌入证书的扩展数据区域中。扩展数据包括操作员的用户名和操作员所属的组,以及可能的其他信息,例如操作员上下文(或域)。用户名,组成员身份和其他扩展数据基于核心计算机的名称空间,并且网络上的其他设备不必属于该名称空间,甚至不必使用相同的网络操作系统。可管理设备可以根据会话证书的持有者提交给他们的扩展数据来认证和授权对其自身的访问。证书的真实性和所有权使用标准的公共密钥密码系统方法进行验证。在一些实施例中,可管理设备通过将证书中的操作员身份和组成员信息与适当的访问控制列表(或等效数据结构)进行交叉引用来验证操作员授权。在一些实施例中,可管理设备被预先配置为通过向其提供内核的公共密钥来信任至少一个内核,并且该内核可以引导该可管理设备信任其他内核。

著录项

  • 公开/公告号US6754829B1

    专利类型

  • 公开/公告日2004-06-22

    原文格式PDF

  • 申请/专利权人 INTEL CORPORATION;

    申请/专利号US19990461157

  • 发明设计人 PAUL B. HILLYARD;JIN SU;ALAN B. BUTT;

    申请日1999-12-14

  • 分类号G06F113/00;H04L90/00;

  • 国家 US

  • 入库时间 2022-08-21 23:16:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号