- 专利标题: Securely operating a process using user-specific and device-specific security constraints
-
申请号: US14538514申请日: 2014-11-11
-
公开(公告)号: US09871821B2公开(公告)日: 2018-01-16
- 发明人: Nicolas Ponsini , Eric Vetillard
- 申请人: Oracle International Corporation
- 申请人地址: US CA Redwood Shores
- 专利权人: ORACLE INTERNATIONAL CORPORATION
- 当前专利权人: ORACLE INTERNATIONAL CORPORATION
- 当前专利权人地址: US CA Redwood Shores
- 代理机构: Fish IP Law, LLC
- 主分类号: G06F15/00
- IPC分类号: G06F15/00 ; G06F13/00 ; H04L29/06 ; G06F9/445 ; H04L9/32
摘要:
A method for enforcing secure processes between a user and a device involves determining that the user has initiated installation of a secure application, installing the RA part of the secure application, triggering a trusted UI session upon realization that the TA part of the secure application is not installed, receiving, via the trusted UI session, user credentials for authenticating the user and enforcing user-specific and device-specific security, cryptographically signing combined user credentials with a cryptographic signature to obtain an authentication object, passing the authentication object to a service provider associated with the secure application for extraction of the user credentials, and generating an authorization token permitting the installation of the TA part of the secure application upon verification of the cryptographically signed authentication object.
公开/授权文献
信息查询