发明授权
- 专利标题: Method and apparatus for preventing rogue implementations of a security-sensitive class interface
- 专利标题(中): 防止安全敏感类接口的恶意实现的方法和装置
-
申请号: US11867015申请日: 2007-10-04
-
公开(公告)号: US07925881B2公开(公告)日: 2011-04-12
- 发明人: Peter Daniel Birk , Ching-Yun Chao , Hyen Vui Chung
- 申请人: Peter Daniel Birk , Ching-Yun Chao , Hyen Vui Chung
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Yee & Associates, P.C.
- 代理商 Justin M. Dillon
- 主分类号: H04L9/00
- IPC分类号: H04L9/00
摘要:
A method and apparatus for preventing rogue implementations of a security-sensitive class interface are provided. With the method and apparatus, a unique identifier (UID) is created by a server process when the server process is started. Anytime the server process, i.e. a server runtime environment, instantiates a new credential object following start-up of the server process, the encrypted UID is placed into a private field within the new credential object. In addition, the UID is encrypted and stored in a private class of the server runtime environment. A verification class is provided within the server runtime environment which includes one or more methods that receive the credential object as a parameter and return true or false as to the validity of the credential object. These one or more methods determine the validity of the credential object by retrieving the encrypted UID from the private class stored in the server runtime environment, decrypting the UID and comparing it to the decrypted UID stored in the private field of the credential object. If the two UIDs match, a determination is made that the credential object was created by the server runtime environment rather than a rogue application. If the two UIDs do not match, or if there is no UID in the credential object, then a false result will be returned by the verification class.
公开/授权文献
信息查询