发明名称 Method and system for a PKI-based delegation process
摘要 A client generates a session key and a delegation ticket containing information for a requested delegation operation. The client generates a first copy of the session key and encrypts it using a public key of a proxy. The client generates a second copy of the session key and encrypts it using a public key of a server. The client then puts the encrypted session keys and delegation ticket into a first message that is sent to the proxy. The proxy extracts and decrypts its copy of the session key from the first message. The proxy then encrypts a proof-of-delegation data item with the session key and places it and the delegation ticket along with the encrypted copy of the session key for the server into a second message, which is sent to the server. The server extracts and decrypts its copy of the session key from the second message and uses the session key to obtain the proof-of-delegation data. Authority is successfully delegated to the proxy only if the server can verify the proof-of-delegation data.
申请公布号 US8340283(B2) 申请公布日期 2012.12.25
申请号 US20040881978 申请日期 2004.06.30
申请人 NADALIN ANTHONY JOSEPH;RICH BRUCE ARLAND;ZHANG XIAOYAN;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 NADALIN ANTHONY JOSEPH;RICH BRUCE ARLAND;ZHANG XIAOYAN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址