发明名称 Method and apparatus for protecting secure credentials on an untrusted computer platform
摘要 The invention comprises a technique in which a desired computer security policy, e.g. member or corporate security policy, can be enforced by performing a host computer security assessment at the time of user authentication by means of a system configuration that comprises a managed and trusted device. In this way, a company can extend their corporate security policy to the user's desktop and verify an untrusted host, e.g. a PC, by means of a trustworthy technology, e.g. a hardened smartcard. Because the smartcard is relatively tamperproof, operations performed on the card are considered more trustworthy than those running solely on the PC. The smartcard and associated middleware running on the host perform such security-related functions as, for example, verifying that the host's anti-virus software is running and that it is not modified, verifying that the anti-virus software has the most recent virus definitions installed, verifying that the host is not currently infected and does not have dangerous and/or unpermitted remote control Trojan horses running and listening on TCP/IP ports, and checking that the host has a password-protected screen saver enabled to prevent unauthorized access to the system in the user's absence.
申请公布号 US2004103317(A1) 申请公布日期 2004.05.27
申请号 US20030383708 申请日期 2003.03.06
申请人 BURNS WILLIAM D. 发明人 BURNS WILLIAM D.
分类号 G06F11/30;G06F21/00;H04L29/06;(IPC1-7):G06F11/30 主分类号 G06F11/30
代理机构 代理人
主权项
地址