CN109076054B - 用于管理单点登录应用程序的加密密钥的系统和方法 - Google Patents
用于管理单点登录应用程序的加密密钥的系统和方法 Download PDFInfo
- Publication number
- CN109076054B CN109076054B CN201680083810.5A CN201680083810A CN109076054B CN 109076054 B CN109076054 B CN 109076054B CN 201680083810 A CN201680083810 A CN 201680083810A CN 109076054 B CN109076054 B CN 109076054B
- Authority
- CN
- China
- Prior art keywords
- key
- cloud service
- decrypting
- service
- master key
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3228—One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0815—Network architectures or network communication protocols for network security for authentication of entities providing single-sign-on or federations
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0822—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
Abstract
Description
Claims (14)
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US15/083,032 US10367643B2 (en) | 2016-03-28 | 2016-03-28 | Systems and methods for managing encryption keys for single-sign-on applications |
US15/083032 | 2016-03-28 | ||
PCT/US2016/069036 WO2017171955A1 (en) | 2016-03-28 | 2016-12-28 | Systems and methods for managing encryption keys for single-sign-on applications |
Publications (2)
Publication Number | Publication Date |
---|---|
CN109076054A CN109076054A (zh) | 2018-12-21 |
CN109076054B true CN109076054B (zh) | 2021-06-11 |
Family
ID=57799929
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201680083810.5A Active CN109076054B (zh) | 2016-03-28 | 2016-12-28 | 用于管理单点登录应用程序的加密密钥的系统和方法 |
Country Status (5)
Country | Link |
---|---|
US (1) | US10367643B2 (zh) |
EP (1) | EP3449607B1 (zh) |
JP (1) | JP6669929B2 (zh) |
CN (1) | CN109076054B (zh) |
WO (1) | WO2017171955A1 (zh) |
Families Citing this family (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US10356079B2 (en) * | 2016-12-05 | 2019-07-16 | Keeper Security, Inc. | System and method for a single sign on connection in a zero-knowledge vault architecture |
FR3096161B1 (fr) * | 2019-05-14 | 2021-09-24 | Orange | Procédé, dispositif et système de sécurisation de données et de clés de chiffrement d'un objet connecté. |
US11582036B1 (en) * | 2019-10-18 | 2023-02-14 | Splunk Inc. | Scaled authentication of endpoint devices |
CN111526249B (zh) * | 2020-04-16 | 2022-02-01 | 维沃移动通信(杭州)有限公司 | 一种信息处理方法和电子设备 |
CN114124422B (zh) * | 2020-08-31 | 2023-09-12 | 北京书生网络技术有限公司 | 一种密钥管理方法及装置 |
CN113190878A (zh) * | 2021-05-12 | 2021-07-30 | 广东康宝莱智慧水务有限公司 | 一种国密加密算法与水务物联采集系统 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102271037A (zh) * | 2010-06-03 | 2011-12-07 | 微软公司 | 基于在线密钥的密钥保护装置 |
CN103248476A (zh) * | 2013-05-02 | 2013-08-14 | 华为数字技术(苏州)有限公司 | 数据加密密钥的管理方法、系统及终端 |
CN103959302A (zh) * | 2011-06-01 | 2014-07-30 | 安全第一公司 | 用于安全分布式存储的系统与方法 |
EP2784717A1 (en) * | 2012-10-17 | 2014-10-01 | Box, Inc. | Remote key management in a cloud-based environment |
Family Cites Families (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2005209118A (ja) * | 2004-01-26 | 2005-08-04 | Nippon Telegr & Teleph Corp <Ntt> | 情報分散ストレージシステムとこのシステムに用いられる全体認証サーバ装置、認証サーバ装置及び分散ストレージサーバ装置及び情報分散ストレージ方法 |
US20050172127A1 (en) | 2004-01-31 | 2005-08-04 | Frank Hartung | System and method for transcoding encrypted multimedia messages transmitted between two devices |
BRPI0513195A (pt) * | 2004-07-09 | 2008-04-29 | Matsushita Electric Ind Co Ltd | sistemas para administrar autenticação e autorização de usuário, e para suportar o usuário, métodos para administrar autenticação e autorização de usuário, para acessar serviços de múltiplas redes, para o controlador de autenticação processar uma mensagem de pedido de autenticação, selecionar a combinação de controladores de autenticação do resultado de busca, autenticar um usuário, e descobrir o caminho a um domìnio tendo relação empresarial com o domìnio doméstico, para o controlador de autorização processar a mensagem de pedido de autorização de serviço, e executar autorização de serviço, para um controlador de autenticação e autorização executar autenticação e autorização de serviço, para proteger o sìmbolo de usuário, e para a autoridade de controle de acesso no domìnio doméstico do usuário prover ao controlador de autenticação uma informação de perfil de assinatura limitada do usuário, para alcançar autenticação e autorização rápidas, e para alcançar registro único para acessar múltiplas redes, e, formatos para informação de capacidade de assinatura, para um sìmbolo de usuário, para um domìnio tendo relação empresarial com o domìnio doméstico de um usuário para pedir afirmação de autenticação e de autorização, e para um terminal de usuário indicar suas credenciais para acessar múltiplas redes em múltiplos domìnios administrativos |
JP2008124649A (ja) * | 2006-11-09 | 2008-05-29 | Toshiba Corp | 権利付きコンテンツの移動方法 |
WO2009003708A1 (en) | 2007-07-05 | 2009-01-08 | Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V. | Device and method for digital rights management |
US8856512B2 (en) * | 2008-12-30 | 2014-10-07 | Intel Corporation | Method and system for enterprise network single-sign-on by a manageability engine |
US8713589B2 (en) | 2010-12-23 | 2014-04-29 | Microsoft Corporation | Registration and network access control |
US20130017347A1 (en) * | 2011-07-12 | 2013-01-17 | Baker Hughes Incorporated | Scale inhibiting surface texture |
US20130173477A1 (en) * | 2011-08-19 | 2013-07-04 | Geoffrey I. Cairns | Storing and forwarding credentials securely from one RFID device to another |
US9270459B2 (en) | 2011-09-20 | 2016-02-23 | Cloudbyte, Inc. | Techniques for achieving tenant data confidentiality from cloud service provider administrators |
JP6098087B2 (ja) * | 2012-09-21 | 2017-03-22 | 富士通株式会社 | 解析方法、解析装置および解析プログラム |
WO2015042547A1 (en) * | 2013-09-20 | 2015-03-26 | Oracle International Corporation | Web-based interface integration for single sign-on |
JP6190720B2 (ja) * | 2013-12-27 | 2017-08-30 | Kddi株式会社 | 監視装置、監視方法およびプログラム |
US9529733B1 (en) | 2014-09-18 | 2016-12-27 | Symantec Corporation | Systems and methods for securely accessing encrypted data stores |
-
2016
- 2016-03-28 US US15/083,032 patent/US10367643B2/en active Active
- 2016-12-28 CN CN201680083810.5A patent/CN109076054B/zh active Active
- 2016-12-28 WO PCT/US2016/069036 patent/WO2017171955A1/en active Application Filing
- 2016-12-28 EP EP16826654.2A patent/EP3449607B1/en active Active
- 2016-12-28 JP JP2019500214A patent/JP6669929B2/ja active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102271037A (zh) * | 2010-06-03 | 2011-12-07 | 微软公司 | 基于在线密钥的密钥保护装置 |
CN103959302A (zh) * | 2011-06-01 | 2014-07-30 | 安全第一公司 | 用于安全分布式存储的系统与方法 |
EP2784717A1 (en) * | 2012-10-17 | 2014-10-01 | Box, Inc. | Remote key management in a cloud-based environment |
CN103248476A (zh) * | 2013-05-02 | 2013-08-14 | 华为数字技术(苏州)有限公司 | 数据加密密钥的管理方法、系统及终端 |
Also Published As
Publication number | Publication date |
---|---|
JP2019511890A (ja) | 2019-04-25 |
EP3449607B1 (en) | 2021-11-10 |
US20170279613A1 (en) | 2017-09-28 |
WO2017171955A1 (en) | 2017-10-05 |
EP3449607A1 (en) | 2019-03-06 |
CN109076054A (zh) | 2018-12-21 |
JP6669929B2 (ja) | 2020-03-18 |
US10367643B2 (en) | 2019-07-30 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US9258122B1 (en) | Systems and methods for securing data at third-party storage services | |
US9076004B1 (en) | Systems and methods for secure hybrid third-party data storage | |
CN109076054B (zh) | 用于管理单点登录应用程序的加密密钥的系统和方法 | |
JP6182589B2 (ja) | 安全な第三者データ記憶のためのシステム及び方法 | |
US9202076B1 (en) | Systems and methods for sharing data stored on secure third-party storage platforms | |
US8966287B2 (en) | Systems and methods for secure third-party data storage | |
US9203815B1 (en) | Systems and methods for secure third-party data storage | |
US9529733B1 (en) | Systems and methods for securely accessing encrypted data stores | |
US10157290B1 (en) | Systems and methods for encrypting files | |
US11223636B1 (en) | Systems and methods for password breach monitoring and notification | |
US20170331818A1 (en) | Systems and methods for location-restricting one-time passcodes | |
US10015173B1 (en) | Systems and methods for location-aware access to cloud data stores | |
US10397216B2 (en) | Systems and methods for performing secure backup operations | |
US9313185B1 (en) | Systems and methods for authenticating devices | |
US9548971B2 (en) | Systems and methods for smart cipher selection | |
US8667281B1 (en) | Systems and methods for transferring authentication credentials | |
US11080385B1 (en) | Systems and methods for enabling multi-factor authentication for seamless website logins | |
US10645073B1 (en) | Systems and methods for authenticating applications installed on computing devices | |
US9749299B1 (en) | Systems and methods for image-based encryption of cloud data | |
US10033732B1 (en) | Systems and methods for detecting cloning of security tokens | |
US11184169B1 (en) | Systems and methods for crowd-storing encrypiion keys | |
US10462113B1 (en) | Systems and methods for securing push authentications | |
US10192056B1 (en) | Systems and methods for authenticating whole disk encryption systems | |
US10469457B1 (en) | Systems and methods for securely sharing cloud-service credentials within a network of computing devices | |
US11438378B1 (en) | Systems and methods for protecting against password attacks by concealing the use of honeywords in password files |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information | ||
CB02 | Change of applicant information |
Address after: California, USA Applicant after: Norton weifuke Co. Address before: California, USA Applicant before: Symantec Corp. |
|
CB02 | Change of applicant information | ||
CB02 | Change of applicant information |
Address after: Arizona, USA Applicant after: Norton weifuke Co. Address before: California, USA Applicant before: Norton weifuke Co. |
|
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CP01 | Change in the name or title of a patent holder | ||
CP01 | Change in the name or title of a patent holder |
Address after: Arizona Patentee after: Keane Digital Co. Address before: Arizona Patentee before: Norton weifuke Co. |