发明名称 System and method of user authentication for network communication through a policy agent
摘要 A policy agent of a network performs an out-of-band user authentication process to verify the identity of a user of a client computer and associates the network data received from the client computer with the user. When the client computer initiates a network data connection to or through the policy agent, the policy agent sends an encrypted challenge to the client computer. The challenge is encrypted with a private key of the policy agent. When the client computer receives the challenge, it decrypts the challenge and prepares a message digest value based on the challenge and the network data sent by the user. The message digest value is then encrypted with the private key of the user to form a response, and the response is sent to the policy agent. The policy agent decrypts the response with the public key of the user to obtain the message digest value and calculates a digest value based on the challenge and the received network data. The policy agent then compares the calculated digest value with the decrypted digest value. A match between the two digest values indicates that the user is successfully authenticated and that the received network data are associated with the user. The policy agent may then apply network policies based on the credentials of the authenticated user.
申请公布号 US7039713(B1) 申请公布日期 2006.05.02
申请号 US19990436135 申请日期 1999.11.09
申请人 MICROSOFT CORPORATION 发明人 VAN GUNTER DAVID;WATERS LESTER L.
分类号 G06F15/16 主分类号 G06F15/16
代理机构 代理人
主权项
地址