发明名称 Client-server Opaque token passing apparatus and method
摘要 In the computer client-server context, typically used in the Internet for communicating between a central server and user computers (clients), a method is provided for token passing which enhances security for client-server communications. The token passing is opaque, that is tokens as generated by the client and server are different and can be generated only by one or the other but can be verified by the other. This approach allows the server to remain stateless, since all state information is maintained at the client side. This operates to authenticate the client to the server and vice versa to defeat hacking attacks, that is, penetrations intended to obtain confidential information. The token as passed includes encrypted values including encrypted random numbers generated separately by the client and server, and authentication values based on the random numbers and other verification data generated using cryptographic techniques.
申请公布号 EP2020797(A1) 申请公布日期 2009.02.04
申请号 EP20080151965 申请日期 2008.02.26
申请人 APPLE INC. 发明人 FARRUGIA, AUGUSTIN J.;FASOLI, GIANPAOLO;RIENDEAU, JEAN-FRANCOIS;BROUWER, MICHAEL L.;HENZIE, JUSTIN
分类号 H04L29/06;H04L9/32 主分类号 H04L29/06
代理机构 代理人
主权项
地址