System console device authentication in a network environment
    2.
    发明授权
    System console device authentication in a network environment 失效
    网络环境中的系统控制台设备认证

    公开(公告)号:US06981144B2

    公开(公告)日:2005-12-27

    申请号:US09828548

    申请日:2001-04-06

    IPC分类号: H04L9/08 H04L9/00

    摘要: A method for providing secure access to console functions of a computer system and authentication of a console device is disclosed. The method comprises first initiating a first EKE sequence to generate a unique shared secret per device utilizing a default device identifier and associated default shared secret on a system-attached device from which a console operation is desired to be enabled. Then, a shared secret is generated from the first EKE sequence, and the generated shared secret is utilized in place of the default device shared secret in subsequent console authentication procedures for that device. Following, the shared secret is securely stored within a storage location of the system and on the system-attached device. The device's shared secret is subsequently replaced on each connection from that device.

    摘要翻译: 公开了一种用于提供对计算机系统的控制台功能的安全访问和控制台设备的认证的方法。 该方法包括首先启动第一EKE序列以使用期望启用控制台操作的系统附接设备上的默认设备标识符和相关联的默认共享秘密来生成每个设备的唯一共享秘密。 然后,从第一EKE序列生成共享秘密,并且在随后的该设备的控制台认证过程中利用所生成的共享秘密来代替默认设备共享密钥。 以下,共享秘密被安全地存储在系统的存储位置和系统附接的设备上。 该设备的共享密钥随后在该设备的每个连接上被替换。

    User authentication system and method for multiple process applications
    10.
    发明授权
    User authentication system and method for multiple process applications 有权
    多进程应用程序的用户验证系统和方法

    公开(公告)号:US06898711B1

    公开(公告)日:2005-05-24

    申请号:US09229733

    申请日:1999-01-13

    摘要: A user within a multiple process environment is initially authenticated, such as by verifying the user's identification and password. A first process, such as a client, requests a profile token representative of the user in response to authenticating the user. The profile token has associated with it one or more usage limitations. The profile token is transferred from the first process to a second process, such as a server. The second process, upon receiving a valid profile token, is allowed to perform one or more tasks on behalf of the user within the token's usage limitations. A profile token is invalidated upon violation of a usage limitation, such as a preestablished time-out period. One or more lookup tables are used to manage the profile tokens and to store certain user and profile token information, providing increased processing security.

    摘要翻译: 最初对多进程环境中的用户进行身份验证,例如通过验证用户的身份和密码。 响应于认证用户,诸如客户端的第一进程请求表示用户的简档令牌。 配置文件令牌与其关联一个或多个使用限制。 配置文件令牌从第一个进程转移到第二个进程,如服务器。 允许第二进程在接收到有效的简档令牌之后,在令牌的使用限制内代表用户执行一个或多个任务。 配置文件令牌违反使用限制(例如预先建立的超时期限)无效。 一个或多个查找表用于管理配置文件令牌并存储特定用户和配置文件令牌信息,从而提供增加的处理安全性。