发明名称 System and method for automatic negotiation of a security protocol
摘要 A protocol negotiation platform permits a computer or other node lying outside of a security-enabled domain to negotiate a supported security protocol with a server or other node within that domain. Active Directory(TM), Kerberos and other secure network technologies permit agents or nodes within a domain to communicate securely with each other, using default, protocols and key, certificate or other authentication techniques. In the past external agents however had no transparent way to enter the domain, requiring the manual selection of protocols for use across the domain boundary. According to the invention either of an external agent or an internal agent may initiate an attempt to establish a secure session across the domain boundary, transmitting a request including a set of supported protocols to the recipient machine. A negotiation engine may then compare the available protocols on both of the agents, nodes or machines at either end of the session, and select a compatible protocol when found. The internal and external agents may likewise authenticate each other using a key, certificate or other mechanism.
申请公布号 US7526640(B2) 申请公布日期 2009.04.28
申请号 US20030608334 申请日期 2003.06.30
申请人 MICROSOFT CORPORATION 发明人 BAZAN BEJARANO DARIO
分类号 G06F21/20;H04L9/00;G06F15/16;G06K19/00;H04L9/32;H04L12/28;H04L29/06;H04L29/08 主分类号 G06F21/20
代理机构 代理人
主权项
地址