发明授权
US06854056B1 Method and system for coupling an X.509 digital certificate with a host identity
有权
将X.509数字证书与主机标识相连接的方法和系统
- 专利标题: Method and system for coupling an X.509 digital certificate with a host identity
- 专利标题(中): 将X.509数字证书与主机标识相连接的方法和系统
-
申请号: US09667090申请日: 2000-09-21
-
公开(公告)号: US06854056B1公开(公告)日: 2005-02-08
- 发明人: Messaoud Benantar , Thomas L. Gindin , Ivan Milman
- 申请人: Messaoud Benantar , Thomas L. Gindin , Ivan Milman
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Jeffrey S. LaBaw; Joseph R. Burwell
- 主分类号: H04L9/32
- IPC分类号: H04L9/32 ; H04L9/00 ; G06F11/30
摘要:
A method or system is presented for coupling identities through the use of digital certificates, thereby allowing a client to be authenticated for a variety of services without those services having to modify their existing methods of authentication. The client generates a request for a digital certificate containing its host identity for a targeted host and secret data associated with its host identity. The secret data has been encrypted using the public key of the certifying authority that receives the request for the digital certificate. The certifying authority decrypts the secret data using its private key and encrypts the secret data using the public key of the targeted host. The digital certificate is then generated and returned to the client. At some point in time, a host receives the certificate from the client and obtains the client's host identity from the certificate, i.e. the host identity uniquely identifies the client or the user of the client to the host. Encrypted secret data associated with the host identity, such as a password, is also retrieved from the digital certificate. The host decrypts the secret data with its private key, and the host then authenticates the client using the host identity and the decrypted secret data for various services. The digital certificate may be formatted according to the X.509 standard, and the host identity and secret information may be stored in an X.509 extension within the digital certificate.
信息查询