首页> 外国专利> Policy enforcement and introspection on an authentication system

Policy enforcement and introspection on an authentication system

机译:身份验证系统的策略实施与反思

摘要

An authentication system handles authentication requests to apply introspection and policy enforcement. A policy server obtains a client security policy and an authenticator security policy. The policy server obtains an encrypted credential request with client metadata from a client and determines whether the client metadata satisfies the client security policy. The policy server provides the encrypted credential request to an authenticator device and obtains an encrypted credential response with authenticator metadata in response. The policy server determines whether the authenticator metadata satisfies the authenticator security policy. The policy server processes the encrypted credential response, without decrypting the encrypted credential request or the encrypted credential response, based on a determination of whether the client metadata satisfies the client security policy and the authenticator metadata satisfies the authenticator security policy.
机译:身份验证系统处理身份验证请求以应用自省和策略实施。策略服务器获取客户端安全策略和验证器安全策略。策略服务器从客户端获取带有客户端元数据的加密凭据请求,并确定客户端元数据是否满足客户端安全策略。策略服务器向验证器设备提供加密的凭据请求,并获得加密的凭据响应,其中验证器元数据作为响应。策略服务器确定验证器元数据是否满足验证器安全策略。策略服务器基于客户端元数据是否满足客户端安全策略和验证器元数据是否满足验证器安全策略的确定来处理加密的凭证响应,而不解密加密的凭证请求或加密的凭证响应。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号