发明授权
- 专利标题: Policy-based security certificate filtering
- 专利标题(中): 基于策略的安全证书过滤
-
申请号: US11405069申请日: 2006-04-17
-
公开(公告)号: US07984479B2公开(公告)日: 2011-07-19
- 发明人: Roy F. Brabson , Barry Mosakowski , Linwood H. Overby, Jr.
- 申请人: Roy F. Brabson , Barry Mosakowski , Linwood H. Overby, Jr.
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Marcia L. Doubet
- 主分类号: G06F17/00
- IPC分类号: G06F17/00 ; H04L29/06 ; H04L9/32
摘要:
Policy filtering services are built into security processing of an execution environment for resolving how to handle a digital security certificate of a communicating entity without requiring a local copy of a root certificate that is associated with the entity through a certificate authority (“CA”) chain. Policy may be specified using a set of rules (or other policy format) indicating conditions for certificate filtering. This filtering is preferably invoked during handshaking, upon determining that a needed root CA certificate is not available. In one approach, the policy uses rules specifying conditions under which a certificate is permitted (i.e., treated as if it is validated) and other rules specifying conditions under which a certificate is blocked (i.e., treated as if it is invalid). Preferably, policy rules are evaluated and enforced in order of most-specific to least-specific.
公开/授权文献
- US20070245401A1 Policy-based security certificate filtering 公开/授权日:2007-10-18
信息查询