Computer system employing dual-band authentication using file operations by trusted and untrusted mechanisms
    9.
    发明授权
    Computer system employing dual-band authentication using file operations by trusted and untrusted mechanisms 有权
    计算机系统采用通过信任和不信任机制进行文件操作的双频带认证

    公开(公告)号:US08601544B1

    公开(公告)日:2013-12-03

    申请号:US13333233

    申请日:2011-12-21

    IPC分类号: H04L29/06

    CPC分类号: H04L63/101 G06F21/44

    摘要: A first machine (e.g., server VM) authenticates an untrusted second machine (e.g., new client VM) as a condition to performing or allowing a protected operation. An authentication identifier is written to a file of a file system using one mechanism, and then read from the file using another mechanism. One of the mechanisms is an untrusted mechanism employing the untrusted second machine, while the other is a trusted mechanism performed by the first machine either alone or in combination with a trusted management component that has privileged access to the file system. If the written and read values match, it can be inferred that the second machine is authentic, because the trusted management component has identified and accessed an existing file system that is also separately accessed by the second machine.

    摘要翻译: 第一机器(例如,服务器VM)将不可信的第二机器(例如,新的客户机VM)认证为执行或允许受保护的操作的条件。 使用一种机制将认证标识符写入文件系统的文件,然后使用其他机制从文件读取。 其中一种机制是采用不受信任的第二机器的不受信任的机制,而另一种是由第一机器单独执行或与具有对文件系统的特权访问的可信管理组件的可信机制。 如果写入和读取值匹配,则可以推断出第二机器是真实的,因为可信管理组件已经识别并访问也被第二机器单独访问的现有文件系统。