首页> 外国专利> Method and system for securely archiving core data secrets

Method and system for securely archiving core data secrets

机译:安全归档核心数据秘密的方法和系统

摘要

The invention provides central storage for core data secrets, referred to as data items. The data items are encrypted by a client computer using a client key that is derived from a logon secret, such as a password, supplied by a user during a network logon procedure. The client key is escrowed with the participation of a network supervisory computer such as a domain controller. The client sends the client key to the domain controller. The domain controller appends a user identification corresponding to the currently authenticated user of the client computer, and encrypts the resulting combination. The encrypted combination is sent back to and stored locally by the client. To recover the client key, the encrypted combination is sent to the domain controller, which decrypts the combination to obtain the data item. However, the data item is returned to the client computer only if the decrypted user identification corresponds to the currently authenticated user of the client computer.
机译:本发明提供了用于核心数据秘密的中央存储,称为数据项。客户端计算机使用从用户在网络登录过程中提供的登录密码(例如密码)派生的客户端密钥对数据项进行加密。客户端密钥在网络管理计算机(例如域控制器)的参与下被托管。客户端将客户端密钥发送到域控制器。域控制器附加与客户端计算机的当前身份验证的用户相对应的用户标识,并加密所得的组合。加密的组合发送回客户端,并由客户端本地存储。为了恢复客户端密钥,将加密的组合发送到域控制器,该域控制器解密该组合以获得数据项。但是,仅当解密的用户标识与客户端计算机的当前身份验证用户相对应时,数据项才返回到客户端计算机。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号