首页> 外国专利> System and method for providing masquerade protection in a computer network using hardware and timestamp-specific single use keys

System and method for providing masquerade protection in a computer network using hardware and timestamp-specific single use keys

机译:使用硬件和时间戳专用的一次性密钥在计算机网络中提供假面保护的系统和方法

摘要

An authentication session key is generated on a trusted machine based upon an identifier of its CPU, hardware configuration, and a timestamp. The trusting machine retrieves this same information about the trusted machine, and then generates session locks for the machine which are valid for a predetermined time interval. If the incoming session key matches one of the session locks, and the incoming session key is not on the list of used keys, the session key is appended to a list of keys which will no longer thereafter be valid, and access is then granted, thereby employing single-use keys. Because the locks and keys are also generated during a timestamp, a user may request service from the same machine multiple times by waiting no more than a predetermined time between requests, or front ends to the masquerade protection tools could be written that re- try until successful. Because the keys generated are specific to the hardware characteristics of the trusted machine upon which they are generated, attempts to gain access from an imposter machine will generate unusable session keys.
机译:身份验证会话密钥是根据受信机器的CPU标识符,硬件配置和时间戳在受信机器上生成的。信任计算机检索有关受信任计算机的相同信息,然后为该计算机生成在预定时间间隔内有效的会话锁。如果传入的会话密钥与会话锁之一匹配,并且传入的会话密钥不在使用过的密钥列表中,则将该会话密钥附加到密钥列表中,此后该密钥将不再有效,然后授予访问权限,从而使用一次性钥匙。由于锁和密钥也是在时间戳期间生成的,因此用户可以在两次请求之间等待的时间不超过预定时间,从而多次请求同一台机器提供服务,或者可以编写化装保护工具的前端,直到成功。由于生成的密钥特定于生成密钥的受信任机器的硬件特性,因此尝试从冒名顶替者的机器获取访问权限将生成不可用的会话密钥。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号