CN102438013B - 基于硬件的证书分发 - Google Patents
基于硬件的证书分发 Download PDFInfo
- Publication number
- CN102438013B CN102438013B CN201110367796.0A CN201110367796A CN102438013B CN 102438013 B CN102438013 B CN 102438013B CN 201110367796 A CN201110367796 A CN 201110367796A CN 102438013 B CN102438013 B CN 102438013B
- Authority
- CN
- China
- Prior art keywords
- unique identifier
- remote entity
- resource
- hardware profile
- certificate
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000009826 distribution Methods 0.000 title claims description 44
- 238000000034 method Methods 0.000 claims description 35
- 238000012795 verification Methods 0.000 claims description 16
- 230000004044 response Effects 0.000 claims description 8
- 230000005611 electricity Effects 0.000 claims description 2
- 238000005516 engineering process Methods 0.000 abstract description 18
- 238000004891 communication Methods 0.000 description 15
- 238000007726 management method Methods 0.000 description 3
- 230000000694 effects Effects 0.000 description 2
- 210000003127 knee Anatomy 0.000 description 2
- 238000012360 testing method Methods 0.000 description 2
- 238000013475 authorization Methods 0.000 description 1
- 238000013500 data storage Methods 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 230000000977 initiatory effect Effects 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 230000029610 recognition of host Effects 0.000 description 1
- 230000003068 static effect Effects 0.000 description 1
- 238000010200 validation analysis Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/062—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/2866—Architectures; Arrangements
- H04L67/30—Profiles
- H04L67/303—Terminal profiles
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Storage Device Security (AREA)
- Information Transfer Between Computers (AREA)
Abstract
Description
Claims (20)
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US12/949,589 US8572699B2 (en) | 2010-11-18 | 2010-11-18 | Hardware-based credential distribution |
US12/949589 | 2010-11-18 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN102438013A CN102438013A (zh) | 2012-05-02 |
CN102438013B true CN102438013B (zh) | 2017-11-21 |
Family
ID=45985885
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201110367796.0A Active CN102438013B (zh) | 2010-11-18 | 2011-11-18 | 基于硬件的证书分发 |
Country Status (2)
Country | Link |
---|---|
US (3) | US8572699B2 (zh) |
CN (1) | CN102438013B (zh) |
Families Citing this family (22)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101909058B (zh) * | 2010-07-30 | 2013-01-16 | 天维讯达无线电设备检测(北京)有限责任公司 | 一种适合可信连接架构的平台鉴别策略管理方法及系统 |
US8572699B2 (en) | 2010-11-18 | 2013-10-29 | Microsoft Corporation | Hardware-based credential distribution |
JP5880401B2 (ja) * | 2012-11-15 | 2016-03-09 | 富士ゼロックス株式会社 | 通信装置及びプログラム |
GB2527276B (en) * | 2014-04-25 | 2020-08-05 | Huawei Tech Co Ltd | Providing network credentials |
US9942237B2 (en) | 2015-08-28 | 2018-04-10 | Bank Of America Corporation | Determining access requirements for online accounts based on characteristics of user devices |
US10346710B2 (en) * | 2016-09-29 | 2019-07-09 | Datacolor Inc. | Multi-agent training of a color identification neural network |
US10609037B2 (en) * | 2017-03-28 | 2020-03-31 | Ca, Inc. | Consolidated multi-factor risk analysis |
US11917070B2 (en) | 2018-02-17 | 2024-02-27 | Carrier Corporation | Method and system for managing a multiplicity of credentials |
US10715327B1 (en) * | 2018-05-30 | 2020-07-14 | Architecture Technology Corporation | Software credential token issuance based on hardware credential token |
CN110677250B (zh) | 2018-07-02 | 2022-09-02 | 阿里巴巴集团控股有限公司 | 密钥和证书分发方法、身份信息处理方法、设备、介质 |
CN110795774B (zh) | 2018-08-02 | 2023-04-11 | 阿里巴巴集团控股有限公司 | 基于可信高速加密卡的度量方法、设备和系统 |
CN110795742B (zh) | 2018-08-02 | 2023-05-02 | 阿里巴巴集团控股有限公司 | 高速密码运算的度量处理方法、装置、存储介质及处理器 |
CN110874478B (zh) | 2018-08-29 | 2023-05-02 | 阿里巴巴集团控股有限公司 | 密钥处理方法及装置、存储介质和处理器 |
US11232209B2 (en) | 2019-01-18 | 2022-01-25 | International Business Machines Corporation | Trojan detection in cryptographic hardware adapters |
US11032381B2 (en) * | 2019-06-19 | 2021-06-08 | Servicenow, Inc. | Discovery and storage of resource tags |
EP3808049B1 (en) * | 2019-09-03 | 2022-02-23 | Google LLC | Systems and methods for authenticated control of content delivery |
CN111259347A (zh) * | 2020-01-19 | 2020-06-09 | 苏州浪潮智能科技有限公司 | 一种判断机器唯一性的授权方法及装置 |
US11954181B2 (en) * | 2020-12-16 | 2024-04-09 | Dell Products L.P. | System and method for managing virtual hardware licenses of hardware resources accessed via application instances |
CN112511569B (zh) * | 2021-02-07 | 2021-05-11 | 杭州筋斗腾云科技有限公司 | 网络资源访问请求的处理方法、系统及计算机设备 |
US11843707B2 (en) * | 2021-07-12 | 2023-12-12 | Dell Products, L.P. | Systems and methods for authenticating hardware of an information handling system |
EP4181462A1 (de) * | 2021-11-11 | 2023-05-17 | Siemens Aktiengesellschaft | Verfahren für ein zertifikatsmanagement für heterogene anlagen, computersystem und computerprogrammprodukt |
CN114584318B (zh) * | 2022-03-07 | 2023-08-11 | 亿咖通(湖北)技术有限公司 | 一种证书和密钥的访问控制方法、电子设备和存储介质 |
Family Cites Families (63)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
GB1494736A (en) * | 1974-01-21 | 1977-12-14 | Chubb Integrated Syst Ltd | Token-control |
US5560008A (en) * | 1989-05-15 | 1996-09-24 | International Business Machines Corporation | Remote authentication and authorization in a distributed data processing system |
US5311513A (en) * | 1992-09-10 | 1994-05-10 | International Business Machines Corp. | Rate-based congestion control in packet communications networks |
EP0781068A1 (en) * | 1995-12-20 | 1997-06-25 | International Business Machines Corporation | Method and system for adaptive bandwidth allocation in a high speed data network |
US6226743B1 (en) * | 1998-01-22 | 2001-05-01 | Yeda Research And Development Co., Ltd. | Method for authentication item |
US6754820B1 (en) * | 2001-01-30 | 2004-06-22 | Tecsec, Inc. | Multiple level access system |
US6233341B1 (en) * | 1998-05-19 | 2001-05-15 | Visto Corporation | System and method for installing and using a temporary certificate at a remote site |
JP2000032048A (ja) * | 1998-07-14 | 2000-01-28 | Fujitsu Ltd | ネットワーク装置 |
US7106756B1 (en) * | 1999-10-12 | 2006-09-12 | Mci, Inc. | Customer resources policy control for IP traffic delivery |
US6748435B1 (en) * | 2000-04-28 | 2004-06-08 | Matsushita Electric Industrial Co., Ltd. | Random early demotion and promotion marker |
DE60023490T2 (de) * | 2000-08-18 | 2006-07-13 | Alcatel | Markierungsapparat zum Kreieren und Einfügen einer Priorität in ein Datenpaket |
US7028179B2 (en) | 2001-07-03 | 2006-04-11 | Intel Corporation | Apparatus and method for secure, automated response to distributed denial of service attacks |
US7571239B2 (en) * | 2002-01-08 | 2009-08-04 | Avaya Inc. | Credential management and network querying |
US7379982B2 (en) * | 2002-04-15 | 2008-05-27 | Bassam Tabbara | System and method for custom installation of an operating system on a remote client |
EP1574009B1 (en) * | 2002-11-18 | 2011-07-13 | Trusted Network Technologies, Inc. | Systems and apparatuses using identification data in network communication |
AU2003900413A0 (en) * | 2003-01-31 | 2003-02-13 | Mckeon, Brian Bernard | Regulated issuance of digital certificates |
US7590695B2 (en) * | 2003-05-09 | 2009-09-15 | Aol Llc | Managing electronic messages |
US7287076B2 (en) * | 2003-12-29 | 2007-10-23 | Microsoft Corporation | Performing threshold based connection status responses |
KR100666980B1 (ko) * | 2004-01-19 | 2007-01-10 | 삼성전자주식회사 | 트래픽 폭주 제어 방법 및 이를 구현하기 위한 장치 |
US20050174944A1 (en) * | 2004-02-10 | 2005-08-11 | Adc Broadband Access Systems, Inc. | Bandwidth regulation |
US20050181765A1 (en) * | 2004-02-13 | 2005-08-18 | Gerald Mark | System and method of controlling access and credentials for events |
WO2005096767A2 (en) * | 2004-04-05 | 2005-10-20 | Comcast Cable Holdings, Llc | Method and system for provisioning a set-top box |
US7363513B2 (en) | 2004-04-15 | 2008-04-22 | International Business Machines Corporation | Server denial of service shield |
US7653199B2 (en) * | 2004-07-29 | 2010-01-26 | Stc. Unm | Quantum key distribution |
JP2006139747A (ja) * | 2004-08-30 | 2006-06-01 | Kddi Corp | 通信システムおよび安全性保証装置 |
US8615653B2 (en) * | 2004-09-01 | 2013-12-24 | Go Daddy Operating Company, LLC | Methods and systems for dynamic updates of digital certificates via subscription |
US20060075042A1 (en) * | 2004-09-30 | 2006-04-06 | Nortel Networks Limited | Extensible resource messaging between user applications and network elements in a communication network |
US8006288B2 (en) * | 2004-11-05 | 2011-08-23 | International Business Machines Corporation | Method and apparatus for accessing a computer application program |
US7607164B2 (en) * | 2004-12-23 | 2009-10-20 | Microsoft Corporation | Systems and processes for managing policy change in a distributed enterprise |
US8700729B2 (en) * | 2005-01-21 | 2014-04-15 | Robin Dua | Method and apparatus for managing credentials through a wireless network |
US20060212407A1 (en) * | 2005-03-17 | 2006-09-21 | Lyon Dennis B | User authentication and secure transaction system |
US7706778B2 (en) * | 2005-04-05 | 2010-04-27 | Assa Abloy Ab | System and method for remotely assigning and revoking access credentials using a near field communication equipped mobile phone |
KR101019002B1 (ko) * | 2005-10-26 | 2011-03-04 | 퀄컴 인코포레이티드 | 자원 이용 메시지를 이용하여 무선 채널에 대한 최소레이트 보증 |
US7631131B2 (en) * | 2005-10-27 | 2009-12-08 | International Business Machines Corporation | Priority control in resource allocation for low request rate, latency-sensitive units |
WO2007055683A2 (en) * | 2005-11-04 | 2007-05-18 | The Board Of Trustees Of The Leland Stanford Junior University | Differential phase shift keying quantum key distribution |
CN100419773C (zh) * | 2006-03-02 | 2008-09-17 | 王清华 | 一种电子文档的许可认证方法和系统 |
US8347376B2 (en) * | 2006-03-06 | 2013-01-01 | Cisco Technology, Inc. | Techniques for distributing a new communication key within a virtual private network |
US7760641B2 (en) * | 2006-07-10 | 2010-07-20 | International Business Machines Corporation | Distributed traffic shaping across a cluster |
US8949933B2 (en) * | 2006-08-15 | 2015-02-03 | International Business Machines Corporation | Centralized management of technical records across an enterprise |
US10671706B2 (en) * | 2006-09-21 | 2020-06-02 | Biomedical Synergies, Inc. | Tissue management system |
US7546405B2 (en) * | 2006-09-26 | 2009-06-09 | Sony Computer Entertainment Inc. | Methods and apparatus for dynamic grouping of requestors of resources in a multi-processor system |
US8347378B2 (en) * | 2006-12-12 | 2013-01-01 | International Business Machines Corporation | Authentication for computer system management |
JP4953801B2 (ja) * | 2006-12-25 | 2012-06-13 | パナソニック株式会社 | パスワード設定方法、映像受信システム、プログラム、および記録媒体 |
JP2007164806A (ja) * | 2007-01-23 | 2007-06-28 | Fujitsu Ltd | データ資源を配付する方法 |
KR101075724B1 (ko) * | 2007-07-06 | 2011-10-21 | 삼성전자주식회사 | 통신 시스템에서 패킷 전송 속도 제한 장치 및 방법 |
US20090135817A1 (en) * | 2007-08-24 | 2009-05-28 | Assa Abloy Ab | Method for computing the entropic value of a dynamical memory system |
US8295306B2 (en) * | 2007-08-28 | 2012-10-23 | Cisco Technologies, Inc. | Layer-4 transparent secure transport protocol for end-to-end application protection |
US20090109941A1 (en) * | 2007-10-31 | 2009-04-30 | Connect Spot Ltd. | Wireless access systems |
US8024782B2 (en) * | 2008-04-09 | 2011-09-20 | Zscaler, Inc. | Cumulative login credit |
US20090313337A1 (en) * | 2008-06-11 | 2009-12-17 | Linkool International, Inc. | Method for Generating Extended Information |
EP2144421A1 (en) * | 2008-07-08 | 2010-01-13 | Gemplus | Method for managing an access from a remote device to data accessible from a local device and corresponding system |
ES2485501T3 (es) * | 2008-08-14 | 2014-08-13 | Assa Abloy Ab | Lector de RFID con heurísticas de detección de ataques incorporadas |
US8359643B2 (en) * | 2008-09-18 | 2013-01-22 | Apple Inc. | Group formation using anonymous broadcast information |
US8504504B2 (en) | 2008-09-26 | 2013-08-06 | Oracle America, Inc. | System and method for distributed denial of service identification and prevention |
JP4650556B2 (ja) * | 2008-10-31 | 2011-03-16 | ブラザー工業株式会社 | ネットワーク装置 |
US8364766B2 (en) * | 2008-12-04 | 2013-01-29 | Yahoo! Inc. | Spam filtering based on statistics and token frequency modeling |
US8255685B2 (en) * | 2009-03-17 | 2012-08-28 | Research In Motion Limited | System and method for validating certificate issuance notification messages |
US20110113242A1 (en) * | 2009-06-09 | 2011-05-12 | Beyond Encryption Limited | Protecting mobile devices using data and device control |
US9742560B2 (en) * | 2009-06-11 | 2017-08-22 | Microsoft Technology Licensing, Llc | Key management in secure network enclaves |
US8578504B2 (en) * | 2009-10-07 | 2013-11-05 | Ca, Inc. | System and method for data leakage prevention |
US20110161663A1 (en) * | 2009-12-29 | 2011-06-30 | General Instrument Corporation | Intelligent caching for ocsp service optimization |
US8938509B2 (en) * | 2010-10-06 | 2015-01-20 | Qualcomm Incorporated | Methods and apparatus for supporting sharing of privileges in a peer to peer system |
US8572699B2 (en) | 2010-11-18 | 2013-10-29 | Microsoft Corporation | Hardware-based credential distribution |
-
2010
- 2010-11-18 US US12/949,589 patent/US8572699B2/en active Active
-
2011
- 2011-11-18 CN CN201110367796.0A patent/CN102438013B/zh active Active
-
2013
- 2013-10-25 US US14/064,004 patent/US9553858B2/en active Active
-
2017
- 2017-01-23 US US15/412,931 patent/US20170134354A1/en not_active Abandoned
Also Published As
Publication number | Publication date |
---|---|
US20120131652A1 (en) | 2012-05-24 |
US8572699B2 (en) | 2013-10-29 |
CN102438013A (zh) | 2012-05-02 |
US9553858B2 (en) | 2017-01-24 |
US20140059664A1 (en) | 2014-02-27 |
US20170134354A1 (en) | 2017-05-11 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN102438013B (zh) | 基于硬件的证书分发 | |
US8266684B2 (en) | Tokenized resource access | |
US10686768B2 (en) | Apparatus and method for controlling profile data delivery | |
JP6574168B2 (ja) | 端末識別方法、ならびにマシン識別コードを登録する方法、システム及び装置 | |
CN102281286B (zh) | 分布式混合企业的灵活端点顺从和强认证的方法和系统 | |
WO2017063523A1 (zh) | 一种业务认证的方法、装置和系统 | |
JP4818664B2 (ja) | 機器情報送信方法、機器情報送信装置、機器情報送信プログラム | |
US20040078573A1 (en) | Remote access system, remote access method, and remote access program | |
JP6963609B2 (ja) | 透過性多要素認証およびセキュリティ取り組み姿勢チェックのためのシステムおよび方法 | |
CN108650212A (zh) | 一种物联网认证和访问控制方法及物联网安全网关系统 | |
US20140157368A1 (en) | Software authentication | |
CN112000951A (zh) | 一种访问方法、装置、系统、电子设备及存储介质 | |
BR112016000122B1 (pt) | Método e sistema relacionados à autenticação de usuário para acessar redes de dados | |
CN104735054A (zh) | 数字家庭设备可信接入平台及认证方法 | |
EP3338429A1 (en) | Anonymous device operation | |
JP5278495B2 (ja) | 機器情報送信方法、機器情報送信装置、機器情報送信プログラム | |
WO2007060016A2 (en) | Self provisioning token | |
CN105991524A (zh) | 家庭信息安全系统 | |
Tiwari et al. | Design and Implementation of Enhanced Security Algorithm for Hybrid Cloud using Kerberos | |
JP2012203516A (ja) | 属性委譲システム、属性委譲方法、及び、属性委譲プログラム | |
Feng et al. | An efficient contents sharing method for DRM | |
KR101821645B1 (ko) | 자체확장인증을 이용한 키관리 방법 | |
JP2008219670A (ja) | デジタル証明書配布システム、デジタル証明書配布方法、及びデジタル証明書配布プログラム | |
JP2016071644A (ja) | ライセンス管理方法及びライセンス管理システム | |
KR20190004250A (ko) | 지정 단말을 이용한 비대면 거래 제공 방법 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
ASS | Succession or assignment of patent right |
Owner name: MICROSOFT TECHNOLOGY LICENSING LLC Free format text: FORMER OWNER: MICROSOFT CORP. Effective date: 20150616 |
|
C41 | Transfer of patent application or patent right or utility model | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20150616 Address after: Washington State Applicant after: MICROSOFT TECHNOLOGY LICENSING, LLC Address before: Washington State Applicant before: Microsoft Corp. |
|
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20240722 Address after: texas Patentee after: HEWLETT PACKARD ENTERPRISE DEVELOPMENT L.P. Country or region after: U.S.A. Address before: Washington State Patentee before: MICROSOFT TECHNOLOGY LICENSING, LLC Country or region before: U.S.A. |
|
TR01 | Transfer of patent right |