首页> 外国专利> System and method for secure initial program load for diskless workstations

System and method for secure initial program load for diskless workstations

机译:用于无盘工作站的安全初始程序加载的系统和方法

摘要

A client workstation generates a network request for an initial program load. The request is serviced by a server which preferably includes in the reply to the client the addresses of an authentication server (AS), client, and a secure initial program load server (SECIPL). The client then requests an SECIPL service ticket from the AS, also sending a common identifier known to the AS and the client, preferably stored in the client ROM. This identifier is utilized by the AS to validate the ticket request as originating from a bona fide client, whereupon the ticket is provided by the AS to the client, the SECIPL service ticket is then presented by the client to the SECIPL server which then authenticates that the ticket is bona fide and was received by the client from the AS. The SECIPL then provides a secure kernel to the client, either encrypted with a key known to the SECIPL and client, or otherwise secured by a cryptographic checksum utilizing a key known to the client and the SECIPL. In this manner, the client workstation is thereby assured that an authenticated boot image has been received through potentially non-secure communication links.
机译:客户工作站为初始程序加载生成网络请求。该请求由服务器服务,该服务器优选地在对客户端的答复中包括认证服务器(AS),客户端和安全初始程序加载服务器(SECIPL)的地址。然后,客户端从AS请求SECIPL服务票证,还发送AS和客户端已知的公共标识符,最好存储在客户端ROM中。 AS使用此标识符来验证票证请求是否源自善意的客户端,然后由AS将票证提供给客户端,然后由客户端将SECIPL服务票证提供给SECIPL服务器,该服务器随后对SECIPL服务器进行身份验证该票证是真实的,是由客户从AS收到的。 SECIPL然后向客户端提供安全的内核,该内核可以使用SECIPL和客户端已知的密钥进行加密,或者通过使用客户端和SECIPL已知的密钥的加密校验和来保护。以此方式,确保客户端工作站已经通过潜在的非安全通信链路接收到了经过身份验证的启动映像。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号