发明名称 Generalized certificate use in policy-based secure messaging environments
摘要 Within a secure messaging environment, a determination is made that a request to send a message has been generated by a user. A message protection policy configured to process the message within the secure messaging environment is identified. The message protection policy specifies that, within the secure messaging environment, a secured digital certificate, other than a user-assigned digital certificate of the user, is configured with an associated private key to digitally sign the message on behalf of the user. Based upon the message protection policy, a determination is made to digitally sign the message using the private key of the secured digital certificate. The message is signed on behalf of the user using the private key of the secured digital certificate.
申请公布号 US9282108(B2) 申请公布日期 2016.03.08
申请号 US201414222203 申请日期 2014.03.21
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 Dixon Bret W.
分类号 H04L9/32;H04L29/06 主分类号 H04L9/32
代理机构 Lee Law, PLLC 代理人 Lee Law, PLLC ;Lee Christopher B.
主权项 1. A method, comprising: determining, within a secure messaging environment, that a request to send a message has been generated by a message sender; identifying a message protection policy configured to process the message within the secure messaging environment, where the message protection policy specifies that, within the secure messaging environment, a secured digital certificate, other than a digital certificate of the message sender, is configured with an associated private key to digitally sign the message on behalf of the message sender; determining, based upon the message protection policy, to digitally sign the message using the private key of the secured digital certificate; signing the message on behalf of the message sender using the private key of the secured digital certificate; determining whether the message protection policy specifies a single recipient or a plurality of recipients; encrypting the message for the single recipient using a public key of the secured digital certificate in response to determining that the message protection policy specifies the single recipient; and encrypting the message for the plurality of recipients using the public key of the secured digital certificate in response to determining that the message protection policy specifies the plurality of recipients.
地址 Armonk NY US