发明名称 Mutual internet authentication between a client and server utilizing a dummy IOP request
摘要 Mutual authentication between a client and server over the Internet utilizing the IOP protocol in its current state is enabled by first engaging in a "dummy" request when a client initiates a request to a new target server for the first time. This provides the means for creating a two way authentication mechanism. Rather than creating an object reference for the dummy request, the object reference at hand in the client, which the client is about to utilize for a request, is reused by extracting a proxy object from the request. The request is intercepted in the client and the proxy object passed to the interception method. The client next issues a two-way remote method already defined for the proxy object, such as the "non_existent( )" method defined on the CORBA object. The client then computes a security token, and sends the dummy request to the server. The server intercepts the dummy request, validates the security token received in the dummy request, and acquires a new authentication token to be returned to the client. Upon interception of the outgoing message, the new security token is marshalled in the security service context and sent to the client on the response message. The client intercepts the reply message and demarshals the security service context to recover the security token and complete mutual authentication.
申请公布号 US6895510(B1) 申请公布日期 2005.05.17
申请号 US19970976778 申请日期 1997.11.24
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BENANTAR MESSAOUD;ALBAUGH VIRGIL;ACKER LIANE ELIZABETH HAYBNES
分类号 G06F13/00;G06F21/00;H04L29/06;(IPC1-7):G06F13/00 主分类号 G06F13/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利