发明名称 Access control
摘要 Control apparatus (30), systems and methods for enabling access to one or more information systems (36) by one or more entities (34) on a path across a supply network to be controlled, access to the or each information system (36) being policed by means of an access-policer (38), the network comprising: at least one token-issuer (32) operable to issue an access pre-authorization token, the access pre-authorization token having associated therewith an information identifier and a digital signature, and to forward the access pre-authorization token towards one or more entities (34) on a path across the network; and at least one receiver entity (34) operable to receive an access pre-authorization token issued by the at least one token-issuer (32).
申请公布号 US8781130(B2) 申请公布日期 2014.07.15
申请号 US201113576064 申请日期 2011.01.14
申请人 British Telecommunications Public Limited Company 发明人 Burbridge Trevor;Soppera Andrea
分类号 H04L9/08;G06F21/00 主分类号 H04L9/08
代理机构 Nixon & Vanderhye PC 代理人 Nixon & Vanderhye PC
主权项 1. Control apparatus for enabling access to one or more information systems by one or more entities on a path across a supply network to be controlled, access to the or each information system being policed by means of an access-policer, the network comprising: at least one token-issuer operable to issue an access pre-authorisation token, said access pre-authorisation token having associated therewith an information identifier and a digital signature, and to forward said access pre-authorisation token towards one or more entities on a path across said network; and at least one receiver entity operable to receive an access pre-authorisation token issued by said at least one token-issuer; the control apparatus comprising: a key generator, implemented using one or more computer systems and operable to generate, in respect of said at least one receiver entity: (i) a receiver entity public key/private key pair comprising a public key and a private key, the receiver entity public key enabling a digital signature guaranteeing the authenticity of a message created using the receiver entity private key to be verified; and(ii) a token translation key, said token translation key enabling translation of a digital signature created using a private key generated in respect of said at least one receiver entity into a digital signature associated with the token-issuer;the key generator being further operable to generate, in respect of said at least one token-issuer: (iii) a token-issuer public key/private key pair, said token-issuer public key enabling a digital signature guaranteeing the authenticity of a message created using said token-issuer private key to be verified; the control apparatus further comprising a key distributor, implemented using the one or more computer systems and operable to distribute: to said at least one token-issuer, the receiver entity private key generated in respect of said at least one receiver entity;to said at least one receiver entity, the token translation key generated in respect of said at least one receiver entity; andto said access-policer, said token-issuer public key.
地址 London GB