首页> 外国专利> Cryptographic system and methodology for creating and managing crypto policy on certificate servers

Cryptographic system and methodology for creating and managing crypto policy on certificate servers

机译:用于在证书服务器上创建和管理密码策略的密码系统和方法

摘要

A cryptosystem having a Certificate (Key) Server for storing and maintaining certificate or key information in a certificate database is described. The Certificate Server allows clients to submit and retrieve keys from a database based on a set of policy constraints which are set for one's particular site (e.g., company). Access to the Certificate Server is maintained by a Certificate Policy Agent, which makes sure that the policy is enforced for a given site based on the information supplied during the configuration. During operation, the Certificate Server responds to client requests to add, search for, and retrieve certificates. The server accepts or rejects certificates based on configurable parameters enforced by a Certificate Policy Agent. When a certificate is submitted to the server, the Certificate Policy Agent checks to see if it meets the criteria for a given site based on the settings specified during the configuration. Exemplary types of checks that the Certificate Policy Agent can enforce include checking to see if the key has been signed by the appropriate entities and checking to see if the signatures or User IDs associated with a key are approved for submission. If the submission criteria established during the configuration are met, the key is accepted by the server. If the key being submitted does not pass the policy requirements, it is rejected and (optionally) a copy is placed in a “pending bucket” where the key can subsequently be examined by the system administrator to determine if the key should be allowed on the server.
机译:描述了一种具有证书(密钥)服务器的密码系统,该证书服务器用于在证书数据库中存储和维护证书或密钥信息。证书服务器允许客户基于针对一个人的特定站点(例如,公司)设置的一组策略约束来从数据库提交和检索密钥。证书策略代理维护对证书服务器的访问,该证书策略代理根据配置​​期间提供的信息,确保为给定站点强制实施策略。在操作过程中,证书服务器会响应客户端添加,搜索和检索证书的请求。服务器根据证书策略代理强制实施的可配置参数接受或拒绝证书。将证书提交到服务器后,证书策略代理会根据配置期间指定的设置进行检查,以查看它是否满足给定站点的条件。证书策略代理可以强制执行的检查的示例类型包括:检查是否已由适当的实体对密钥进行签名;以及检查是否已批准与密钥相关联的签名或用户ID提交。如果满足在配置过程中建立的提交标准,则服务器接受密钥。如果提交的密钥未通过政策要求,则将其拒绝,并将副本(可选)放置在“待处理的存储区”中。系统管理员随后可以在其中检查密钥,以确定是否应在服务器上允许该密钥。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号