发明名称 A method for secure user authentication in a dynamic network
摘要 The application aims to solve the problem of the prior art Kerberos authentication protocol when a service to fulfill a clients request is not known in advance. Disclosed is a method, apparatus and computer program for secure user authentication in a network having a dynamic set of services Di..Dn. The method comprises a client C authenticating with an edge service S; and a client C generating a query key KQ. It further comprises the edge service S issuing a request to the dynamic set of services Di ..Dn the request comprising (i) an identifier associated with the client C, the identifier being encrypted with a query key KQ, (ii) a private portion Rpriv of the request being encrypted with a query key KQ and (iii) a public portion Rpub, of the request. One or more of said dynamic set of services Di..Dn, having ascertained from said public portion Rpub, of the request that it is able to respond to the request, responds to the edge service S with (i) an identifier Dx, associated with the one or more of said dynamic set of services Di..Dn and (ii) the identifier associated with the client C, this identifier being encrypted with the query key KQ. The edge service S authenticates with the one or more of said dynamic set of services Di..D„, that is able to respond to the request, including generating a session key KS,Dx and the edge service S sends the query key KQ to said one or more of said dynamic set of services Di..Dn encrypted using a session key KS,Dx.
申请公布号 GB2512062(A) 申请公布日期 2014.09.24
申请号 GB20130004916 申请日期 2013.03.18
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 DOMINIC PETER HARRIES;GRAHAM ANTHONY BENT
分类号 G06F21/33;G06F9/50;H04L9/32 主分类号 G06F21/33
代理机构 代理人
主权项
地址