发明名称 Establishing secure, mutually authenticated communication credentials
摘要 Establishing secure, mutually authenticated communication between a trusted network and a perimeter network. Servers on the perimeter network may be securely and automatically configured to communicate with the trusted network. Servers not functioning properly may be stopped from communicating with the other servers. Credential information relating to a perimeter server may be automatically, and regularly, updated without intervention.
申请公布号 US9160740(B2) 申请公布日期 2015.10.13
申请号 US201314017481 申请日期 2013.09.04
申请人 Microsoft Technology Licensing, LLC 发明人 Zhang Hao;Kay Jeffrey B.;Pearson Malcolm E.;Tribble Eric D.
分类号 H04L29/00;H04L29/06;H04L9/32 主分类号 H04L29/00
代理机构 代理人 Bowman Louise;Andrews David;Minhas Micky
主权项 1. A method for automatically updating credential information between a trusted server residing on a trusted network and an edge server residing on a perimeter network outside the trusted network, at least one server in the trusted network administering a distributed directory service, said method comprising: reading, by the trusted server, current credential information associated with the edge server residing on the perimeter network outside the trusted network, wherein the credential information includes a public key created by the edge server and a password created by the edge server, said public key and said password being associated with the edge server; determining, by the trusted server, an expiration status of the current credential information associated with the edge server; storing replacement credential information in an edge configuration object in the distributed directory service when a replacement criteria is met, said replacement credential information including a replacement password created by and associated with the edge server, said replacement password being encrypted; propagating, by any trusted server in the trusted network, the replacement credential information stored in the edge configuration object from the distributed directory service to the edge server in the perimeter network, wherein said trusted server secures the authenticity of the replacement credential information by digitally signing the credential information with a private key created by and associated with said trusted server; verifying, at the edge server, that the replacement credential information received from the propagating trusted server has been digitally signed by said propagating trusted server, whereby the replacement credential information is rejected when said verifying fails; and utilizing, by the trusted server, the replacement credential information when an attempt to utilize the current credential information fails.
地址 Redmond WA US