METHODS AND APPARATUSES FOR AVOIDING DAMAGE IN NETWORK ATTACKS
    51.
    发明公开
    METHODS AND APPARATUSES FOR AVOIDING DAMAGE IN NETWORK ATTACKS 审中-公开
    用于避免网络攻击中的损害的方法和设备

    公开(公告)号:EP3193523A1

    公开(公告)日:2017-07-19

    申请号:EP17159302.3

    申请日:2011-07-06

    IPC分类号: H04W12/04 H04L29/06

    摘要: Methods and apparatuses in a client terminal (400) and a web server (402) for enabling safe communication between said terminal and server. When the terminal obtains a web page from the server in a session, the terminal creates a context specific key, Ks_NAF', based on one or more context parameters, P1,...Pn, pertaining to said session and/or web page. The terminal then indicates the context specific key in a login request to the server, and the server determines a context specific key, Ks_NAF', in the same manner to verify the client if the context specific key determined in the web server matches the context specific key received from the client terminal. The context specific key is thus bound to and valid for the present context or session only and cannot be used in other contexts or sessions.

    摘要翻译: 客户终端(400)和网络服务器(402)中的方法和装置,用于实现所述终端和服务器之间的安全通信。 当终端在会话中从服务器获得网页时,终端基于与所述会话和/或网页有关的一个或多个上下文参数P1 ... Pn创建上下文特定密钥Ks_NAF'。 然后,终端在向服务器的登录请求中指示上下文特定的密钥,并且服务器以相同的方式确定上下文特定的密钥Ks_NAF'以验证客户端,如果在网络服务器中确定的上下文特定的密钥匹配上下文特定的 密钥从客户端接收。 上下文特定键因此仅与当前上下文或会话绑定并且有效,并且不能用于其他上下文或会话中。