Apparatus, system, and method for transparent end-to-end security of storage data in a client-server environment
    7.
    发明授权
    Apparatus, system, and method for transparent end-to-end security of storage data in a client-server environment 失效
    用于在客户机 - 服务器环境中存储数据的透明端到端安全性的装置,系统和方法

    公开(公告)号:US07899189B2

    公开(公告)日:2011-03-01

    申请号:US11008403

    申请日:2004-12-09

    IPC分类号: H04K1/00

    CPC分类号: H04L63/0428 H04L9/0894

    摘要: The present invention includes one or more clients in communication with a server. The client desires to send a storage construct to the server for storage. The client negotiates a transmission key with the server. The client generates a storage key associated specifically with the storage construct. The client encrypts the storage construct using the storage key and encrypts the storage key using the transmission key. The encrypted storage construct and encrypted storage key are sent to the server. The server decrypts the storage key using the transmission key. The server stores the storage construct on a storage device separate from a storage device storing the storage key. Preferably, any changes to the storage construct location, the storage key location, or the storage construct name are tracked and proper modifications are made to an association relating the location of the storage construct and the location for the corresponding storage key.

    摘要翻译: 本发明包括与服务器通信的一个或多个客户端。 客户端希望将存储结构发送到服务器进行存储。 客户端与服务器协商传输密钥。 客户端生成与存储结构特别相关的存储密钥。 客户端使用存储密钥加密存储结构,并使用传输密钥加密存储密钥。 加密存储结构和加密存储密钥被发送到服务器。 服务器使用传输密钥解密存储密钥。 服务器将存储结构存储在与存储存储密钥的存储设备分开的存储设备上。 优选地,跟踪对存储构造位置,存储密钥位置或存储构造名称的任何改变,并且对存储结构的位置和对应的存储密钥的位置的关联进行适当的修改。

    System and method for command routing and execution in a multiprocessing system
    10.
    发明授权
    System and method for command routing and execution in a multiprocessing system 失效
    多处理系统中命令路由和执行的系统和方法

    公开(公告)号:US06389543B1

    公开(公告)日:2002-05-14

    申请号:US09143820

    申请日:1998-08-31

    IPC分类号: G06F900

    CPC分类号: H04L63/104

    摘要: Any node in a multi-node processing system may be employed to route commands to a selected group of one or more nodes, and initiate local command execution if permitted by local security provisions. The system includes multiple application nodes interconnected by a network, and one or more administrator nodes each coupled to at least one application node. Each administrator node has assigned security credentials. The process starts when the administrator node transmits input to one of the application nodes (an “entry” node). The input includes a command and routing information specifying a list of desired application nodes (“destination” nodes) to execute the command. In response to this input, the entry node transmits messages to all destination nodes to (1) log-in to the destination nodes as the originating administrator node, and (2) request the destination nodes to execute the command. Consulting locally stored security information, each destination node determines whether the entry node's log-in should succeed. If so, the destination node consults locally stored authority information to determine whether the initiating administrator node has authority to execute the requested command. If so, the destination node executes the command. The destination node sends the entry node a response representing the outcome of command execution. The entry node organizes such responses and provides a representative output.

    摘要翻译: 可以使用多节点处理系统中的任何节点来将命令路由到所选择的一个或多个节点的组,并且如果被本地安全规定允许,则启动本地命令执行。 系统包括由网络互连的多个应用节点,以及每个耦合到至少一个应用节点的一个或多个管理员节点。 每个管理员节点都分配了安全凭证。 当管理员节点向其中一个应用节点(“条目”节点)发送输入时,该过程开始。 输入包括指定用于执行命令的期望的应用节点(“目的地”节点)的列表的命令和路由信​​息。 响应于该输入,入口节点将消息发送到所有目的地节点,以(1)作为始发管理员节点登录到目的地节点,以及(2)请求目的节点执行该命令。 咨询本地存储的安全信息,每个目标节点确定入口节点的登录是否应该成功。 如果是,则目的地节点查询本地存储的权限信息,以确定发起管理员节点是否具有执行请求的命令的权限。 如果是,则目的节点执行该命令。 目的地节点向入口节点发送表示命令执行结果的响应。 入口节点组织此类响应并提供代表性的输出。