发明名称 METHOD AND SYSTEM FOR STEPPING UP TO CERTIFICATE-BASED AUTHENTICATION WITHOUT BREAKING AN EXISTING SSL SESSION
摘要 A method is presented for performing authentication operations. When a clien t requests a resource from a server, a non-certificate~based authentication operation is performed through an SSL (Secure Sockets Layer) session between the server and the client, When the client requests another resource, the server determines to step up to a more restrictive level of authentication, and a certificate-based authentication operation is performed through the SS L session without exiting or renegotiating the SSL session prior to completion of the certificate-based authentication operation. During the certificate- based authentication procedure, an executable module is downloaded to the client from the server through the SSL session, after which the server receives through the SSL session a digital signature that has been generated by the executable module using a digital certificate at the client. In response to successfully verifying the digital signature at the server, the server provides access to a requested resource.
申请公布号 CA2528486(A1) 申请公布日期 2005.02.17
申请号 CA20042528486 申请日期 2004.07.09
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 MUPPIDI, SRIDHAR;VANDENWAUVER, MARK;ASHLEY, PAUL ANTHONY
分类号 H04L29/06;G06F21/00;H04L9/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址