Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

48 results about "Client certificate" patented technology

In cryptography, a client certificate is a type of digital certificate that is used by client systems to make authenticated requests to a remote server. Client certificates play a key role in many mutual authentication designs, providing strong assurances of a requester's identity.

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

Mechanism for enforcing access control at scale to an internet service using transport layer security (TLS)

Systems and methods are provided for a scalable load balancer to enable client certificate access control using mutual transport layer security authentication comprising hardware configured to receive trust store files including a certificate authority (CA) bundle and a certificate revocation list (CRL), generate a single trust store file based on the trust store files, distribute a snapshot of the single trust store file to one or more nodes of the scalable load balancer, verify, using the snapshot, a client certificate from a client device by searching for a trusted CA from the CA bundle in the snapshot, determine whether the CRL contained in the snapshot includes the client certificate, and upon verifying the client certificate and determining that the CRL does not contain the client certificate, transmit connection data from the client device to an application target.
Owner:AMAZON TECH INC

Distributed node unified identity authentication method and system based on QUIC protocol

The invention relates to a QUIC protocol-based distributed node unified identity authentication method and system, belongs to the technical field of network security, is applied to a client, and comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and pre-storing a server certificate chain; generating a QUIC initial data packet according to the target server domain name identifier and the client certificate, and sending the QUIC initial data packet to the server; receiving a QUIC handshake data packet returned by the server; verifying the legality of the server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to the client DH private key and the server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to a server; and synchronously using the 1-RTT session key to encrypt the application layer data with the server, and transmitting the data to the server in the 1-RTT encryption space of the QUIC protocol. According to the invention, the reliability of node identities and the confidentiality of data are ensured.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Identity authentication unloading method and system based on intelligent network card

The invention relates to the field of network security, and discloses an identity authentication unloading method and system based on an intelligent network card. The method comprises the following steps: presetting a master key in an intelligent network card; presetting a master key in the intelligent network card; receiving client request data forwarded by the application layer and extracting a service identifier; generating a private key of the corresponding service through the service identifier and the master key; acquiring a local authentication message, signing the local authentication message by using the private key, generating a server signature value, and sending the server signature value to the client through the application layer to trigger a client authentication process; receiving client certificate data forwarded by the application layer and extracting a certificate signature value; and verifying the certificate signature value by using a preset certificate issuing mechanism public key and generating a verification result, and outputting feedback information based on the verification result. According to the method, a hardware-level unloading function in an identity authentication process is realized through the intelligent network card, and the problems of high calculation overhead and poor expansibility of traditional TLS bidirectional authentication are solved.
Owner:JIHUA LAB

Secure provisioning and rotation of certificates for edge devices

A certificate management service (CMS) may securely provision and rotate certificates for edge devices. The CMS may pre-register a unique device ID of an edge device (e.g., provided by the device manufacturer). When the edge device is installed at the client's remote network, it is provisioned with a common bootstrap certificate that allows the edge device to initially establish a secure to connection to a local hub device and to request a client certificate. The CMS receives the request for the client certificate, which includes the unique device ID. Since the unique device ID was pre-registered at the CMS, the CMS authenticates the request for the client certificate. The CMS causes a signed client certificate to be delivered back to the edge device, which may be used by the edge device to establish subsequent secure connections.
Owner:AMAZON TECH INC

Customized network interface card oriented to intranet security access and design method thereof

The invention discloses a network interface card with autonomous access authentication, and provides an integrated hardware authentication mechanism. The EAP-TLS client protocol stack is integrated on the bottom layer of the network card, so that the defect that an authentication module depends on a host system, manual intervention and the like in the existing scheme is overcome, TLS handshake and certificate verification are independently completed on the network card side, and authentication interaction is automatically initiated. The network interface card serves as a unique identity certificate of an access network, a client certificate and a corresponding private key are embedded in the network interface card and are stored in a protected nonvolatile area, and data confidentiality is effectively enhanced. The network card is used as an identity certificate and network access equipment at the same time, and the integrated design reduces the dependence on the service capability of management personnel. A traditional physical network card and an automatic authentication protocol are fused, and the method is suitable for application environments with high requirements for access control and authentication safety, such as an enterprise intranet and a government affair private network.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Certificate generation and access authentication method based on host fingerprint

The invention provides a certificate generation and access authentication method based on host fingerprints, and aims to improve authentication security by combining hardware fingerprints and certificate management. In the traditional EAP-TLS authentication, the user identity completely depends on a client certificate and a private key, is easy to copy or leak and has potential safety hazards, and when the private key is captured, an attacker can disguise as a user to access an intranet. According to the method, hardware fingerprints are dynamically calculated at a client side (an SHA256 Hash value is generated based on information of a network card, a hard disk, an SMBIOS, a mainboard and the like) to verify a certificate, and the certificate is sent to an authentication server. Meanwhile, on the basis of EAP-TLS bidirectional authentication, the matching condition of the certificate fingerprint and the client host is additionally checked, strong binding of the certificate and the host is achieved, and the related certificate can only be used on the corresponding host. In order to further enhance the protection of the certificate, the client stores the certificate and the private key as EFI variables. The method is widely applicable to various wireless network authentication scenes, and has wide applicability and remarkable economic benefits.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Cloud service authentication method and cloud service system

The invention provides a cloud service authentication method and a cloud service system, the method is applied to the cloud service system, and the cloud service system comprises at least one trust anchor and a plurality of application configurations; the method comprises the steps that a request of a first user for obtaining a temporary certificate is received, the request comprises a client certificate of the first user and information of a first role requested by the first user, and the client certificate of the first user comprises a subject identifier of the first user; determining that the first user accesses the cloud service system according to the client certificate of the first user and the root certificate in the first trust anchor; according to the main body identifier of the first user, determining the permission of the first user to obtain the first application configuration; acquiring the permission of the first user to use the first role in the first application configuration; acquiring a temporary voucher; and sending the temporary credential to the first user. According to the embodiment of the invention, the risk that illegal applications invade cloud resources can be reduced.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Certificate authority verification system, certificate authority verification method, and program

PCT designated stageWO2026176551A1Self-signed certificateInternet privacy
This certificate authority verification system includes: a verification device; a local certificate authority device that operates under an isolated execution environment; a certificate presenter device that serves as a server or a client and uses a server certificate or a client certificate; and a certificate verifier device that serves as a server or a client and verifies a presented certificate. The certificate authority device includes a self-certificate generation unit that generates a self-certificate which is a certificate of the certificate authority device itself, an evidence generation unit that generates evidence of the self-certificate, and a reference value registration request unit that executes a reference value registration request together with a reference value of the self-certificate. The verification device includes a reference value registration unit that registers the reference value of the self-certificate.
Owner:NT T INC

System and methods for agentless managed device identification as part of setting a security policy for a device

Systems, methods, and apparatuses directed to efficiently determining whether a device making a request to access an application or service is a managed device and using that information to set an appropriate security policy for the device or the request to access the application or service. In some embodiments, a service or server (referred to as a Managed Device Identification Service) is configured to request a client certificate from a device that is requesting access to a cloud-based application or service as part of a protocol handshake. If a certificate is received, it is compared to a stored certificate to determine if the device is a managed device and as a result, the appropriate security policy.
Owner:GOLDMAN SACHS BANK USA

BMC login method, system and device and computer readable storage medium

The invention discloses a BMC login method, system and device and a computer readable storage medium. The BMC login method comprises the steps that a user name, a login password and a client certificate uploaded by a login terminal are received; verifying whether the user name, the login password and the client certificate are all valid or not, and obtaining a verification result; and if the verification result is all valid, allowing the login terminal to log in the BMC system. According to the BMC login method provided by the embodiment of the invention, the login terminal is allowed to log in the BMC system only by verifying that the user name, the login password and the client certificate are all valid, and compared with the prior art that login is allowed only after the user name is verified to be matched with the password, a process of verifying the client certificate is added during login, so that the login efficiency is improved, and the user experience is improved. Meanwhile, compared with an operation mode of verifying login by using a user name, a password and a dynamic code, the method disclosed by the invention is simpler and more convenient, and login can be carried out without downloading and installing an identity verifier by the login terminal.
Owner:TONG TAIYI INFORMATION TECHNOLOGY (FUJIAN) CO LTD

Methods and systems for client certificate extraction in device authentication

Embodiments of a device and method are disclosed. In an embodiment, a method of communications involves at a network device, receiving an authentication message from a client, at the network device, extracting a payload from the authentication message, and sending a copy of the payload to a Transport Layer Security (TLS) microserver of the network device for client certificate extraction, where the TLS microserver is implemented in a side signal channel.
Owner:NILE GLOBAL INC

Connection management device and common API

A connection management device may be used to with a common API to allow a host device of a client to securely connect to a remote provider network. The host device may only be able to use a connection management device by using a defined set of commands of a common API. A hardware root of trust may be pre-provisioned with security data (e.g., client certificate, encryption keys). A connection command may be used that is not specific to any particular communication protocol (e.g., WiFi, cellular, wired protocol). In response to receiving the connection command from a host device, the connection management device may perform commands specific to the communication protocol of the connection management device to connect to a remote provider network, use the security data for authentication, and establish a connection in accordance with the communication protocol based on the authentication.
Owner:AMAZON TECH INC

Access authentication method for binding switch port and host

The invention provides an access authentication method for binding a switch port and a host, which is used for solving the problems that a server is difficult to judge the correctness of the port and the management complexity is high when a multi-port client is accessed. According to the method, switch port information (a switch identifier and a port number) is aggregated into a logic user, and the logic user is bound with a client certificate, so that unified authentication is realized. A client can obtain current port information through a link layer discovery protocol, and submits an authentication request in the form of'switch identifier-port number '; and the authentication server carries out verification according to the stored port information, the logic user and the certificate public key, and if the connection port does not accord with the binding relationship, the access is refused. The authentication request carries the network port MAC information of the first accessed switch so as to prevent the switch from being counterfeited. According to the technology, the security and flexibility of authentication are effectively improved, and when the network configuration is changed, only the binding relationship needs to be updated at the server without modifying the configuration of the client, so that the management burden is remarkably reduced.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Role-based authorization for wireless network management services

Technology for mesh network management including role-based authorization for wireless network management services is described. In one embodiment, a wireless mesh device receives, from a requesting device, a request to establish a secure communication session, authenticates the client certificate and establishes the secure communication session. The wireless mesh device further receives, from the requesting device via the secure communication session, a request directed to a service of a plurality of services provided by the wireless mesh device, where the request comprises the client certificate associated with the requesting device, identifies a root certificate used to cryptographically sign the client certificate, wherein the root certificate is associated with a role assigned to the requesting device, identifies role information associated with the requesting device and the client certificate, and responsive to determining that the role information indicates that the requesting device has permission to access the service, forwards the request to the service.
Owner:AMAZON TECH INC

Client certificates to communicate trusted information

ActiveUS12323407B2Securing communicationEngineeringClient certificate
A device comprises: a receiver configured to receive a client certificate; a processor coupled to the receiver and configured to: authenticate the client certificate, extract, in response to the authentication, attributes from the client certificate, and create, in response to the extraction, a message comprising reformatted attributes based on the attributes, wherein the reformatted attributes can be trusted; and a transmitter coupled to the processor and configured to transmit the message. A device comprises: a processor configured to: process a client certificate comprising a certificate identifier (ID) attribute, a tenant ID attribute, and a role ID attribute, and package the client certificate in a request for a shared service; and a transmitter coupled to the processor and configured to transmit the request.
Owner:BLACKHAWK NETWORK INC

General-purpose device identifiers and signal exchange integration

In certain aspects of this disclosure, a computer implementation method includes registering at least one managed device in a mobile device management service. This method includes receiving a client certificate on at least one managed device. This method includes integrating a generic device identifier SDK via a trusted ecosystem vendor app on at least one managed device. This method includes obtaining a pre-salted device identifier address associated with at least one managed device by the generic device identifier SDK based on a request from the trusted ecosystem vendor app. This method includes at least one managed device sending the pre-salted device identifier address to a security vendor service via a trusted ecosystem vendor to generate a generic device identifier address. This method includes at least one managed device receiving a generic device identifier address from the security vendor service via a trusted ecosystem vendor.
Owner:JAMF SOFTWARE LLC

Automatic OpenVPN account management method based on approval linkage

The invention provides an automatic OpenVPN account management method based on examination and approval linkage, and relates to the technical field of network communication, and the method comprises the steps: checking VPN application information filled by an applicant, and generating an examination and approval form based on the VPN application information passing the examination and approval; calling a Python API (Application Program Interface), and mapping parameters in the approval form into OpenVPN (Open Virtual Private Network) configuration parameters; a client certificate and a private key are generated based on an EasyRSA component, and certificate generation is completed through non-interactive password input; according to the authority level, dynamically updating an authority rule in an OpenVPN configuration directory, and distributing a main IP address and a standby IP address from a preset IP address pool; and forming VPN information by the certificate, the authority rule, the main IP rule and the standby IP rule, and sending the VPN information to the applicant.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Intelligent mobile terminal digital certificate issuing method and system based on ACME specification

The invention discloses an intelligent mobile terminal digital certificate issuing method based on an ACME specification, and the method comprises the steps: S1, enabling a client to request to create an order, and enabling the identification type to be a mobile phone number; s2, the server generates an order and returns the order to an authorized object list; s3, the client accesses the authorized object and obtains access URLs of two challenge objects of short message authentication and voice dialing authentication; s4, the client selects one authentication mode to access the corresponding challenge object; s5, the server side sends an authentication token value through a short message or voice dialing according to the selection of the client side; s6, the client calculates an authentication information value based on the token and the account key and returns the authentication information value; s7, the server verifies the authentication information, and waits for the client certificate application if the verification is passed; and S8, executing a certificate application and downloading process by the client. According to the invention, an automatic digital certificate issuing service can be provided for the intelligent mobile terminal, the number changing software is effectively prevented from counterfeiting a mobile phone number, and the security is improved.
Owner:GUANGDONG ELECTRONIC CERTIFICATION AUTHORITY CO LTD

A method for secure communication based on quantum keys

The application provides a kind of quantum key-based secure communication method, it is related to cryptographic application technical field.The method comprises: obtaining the serial number of target refilling key from the security chip in the communication module, and generating client handshake information;Client handshake information is sent to gateway device, so that gateway device obtains target refilling key from quantum cryptography management service platform according to the serial number of target refilling key, and generates server handshake message, receives the server handshake message and server certificate sent by gateway device;Call security chip to authenticate server certificate, generate first working key, send the client certificate of communication module to gateway device, so that gateway device authenticates client certificate through quantum cryptography management service platform, and generates second working key;Finally, according to the first working key and the second working key, VPN tunnel between communication module and gateway device is established, which is used for service data packet transmission.
Owner:中电信量子信息科技集团有限公司

Integrated trust platform modules, device attestation, and device management for live zero trust network access

Systems, apparatus, and methods for device attestation are disclosed. An example apparatus includes communication circuitry to obtain a request to access an organization resource and a client certificate including a device identifier and a certificate authority issuer, at least one memory storing machine readable instructions, and programmable circuitry to execute the machine readable instructions to determine that the certificate authority issuer is a trusted issuer, compare the device identifier against device identifiers in a database storing trusted device identifiers of an organization protecting the organization resource, in response to determining that an instance of the device identifier exists in the database, determine that a client device associated with the device identifier is authorized to access the organization resource based on checking a policy of the organization, and grant the client device access to the organization resource.
Owner:JAMF SOFTWARE LLC

Multi-protocol compatible communication method and related devices

This application provides a multi-protocol compatible communication method and related equipment. The multi-protocol compatible communication method includes: obtaining a target client certificate; determining the encryption algorithm of the target client certificate; determining a target communication protocol based on the encryption algorithm of the target client certificate; and establishing a connection with a server using the target communication protocol. The technical solution of this application automatically selects a suitable protocol through certificate analysis, eliminating compatibility issues that may occur in traditional protocol selection. The client and server can automatically adjust the communication protocol they use based on the encryption algorithm information contained in the client certificate, ensuring that both the client and server use compatible protocols in the same communication, effectively avoiding authentication failures or connection problems caused by mismatched protocols. Automated protocol selection ensures that both parties can use a matching protocol for authentication, reducing the chance of configuration errors and improving overall communication security.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Certificate management system and method and electronic equipment

The invention discloses a certificate management system and method and electronic equipment. The system comprises a certificate registration module used for receiving a certificate set registration request and sending the certificate set registration request to a certificate authentication module after the certificate set registration request passes verification; the certificate authentication module is used for receiving the certificate set registration request passing the verification and feeding back a certificate set to the certificate registration module so as to send the certificate set to the client based on the certificate registration module, the certificate set comprises at least two certificates to be used, the time ranges applicable to the at least two certificates to be used are different, and the time ranges are partially overlapped; the certificate management module is used for acquiring a certificate set and service information of the certificate set, analyzing the certificate set and the service information and then sending the certificate set and the service information to the certificate configuration module; and the certificate configuration module is used for sending the analyzed certificate set and the business information to the certificate service module so as to provide certificate service for the client based on the certificate service module, thereby realizing comprehensive management of issuing and using the certificate set and the like, and improving the certificate management efficiency.
Owner:AGRICULTURAL BANK OF CHINA

A data interaction method and device

The application provides a data interaction method and device, and relates to the technical field of cloud computing. A data interaction method is applied to a client and includes the following steps: obtaining a CA certificate and a client certificate issued by a private cloud; performing handshake information verification with a public cloud according to the CA certificate and the client certificate; and performing data interaction with the public cloud after the handshake information verification is successful. According to the embodiment of the application, the client can perform handshake with the public cloud through the certificate issued by the private cloud, and the private cloud can perform identity verification on the client through the handshake process.
Owner:HANGZHOU TUYA INFORMATION TECH CO LTD

Secure provisioning of an edge device using a fiducical marker

An update deployment service performs secure provisioning of an edge device using a fiducial marker. A client registers an edge device with a provisioning service of a remote service provider network by providing a unique device ID. When the edge device is turned on, the edge device detects, based on input from a camera of the device, a fiducial marker that was generated by the provisioning service. The edge device decodes a network address (URL) and security credentials represented by the fiducial marker. The edge device sends the device ID and credentials to the provisioning service. The provisioning service authenticates the credentials and sends, to the edge device, a client certificate that can be used by the edge device for authentication by one or more other services of the provider network.
Owner:AMAZON TECH INC

Identity authentication offloading method and system based on smart network card

The present invention relates to the field of network security, and discloses an identity authentication unloading method based on a smart network card and its system. The method includes: pre-setting a master key in the smart network card; pre-setting a master key in the smart network card; receiving client request data forwarded by the application layer and extracting a service identifier; generating a private key for the corresponding service through the service identifier and the master key; obtaining a local authentication message, signing the local authentication information with a private key, generating a server signature value, and sending the server signature value to the client through the application layer to trigger the client authentication process; receiving client certificate data forwarded by the application layer and extracting the certificate signature value; verifying the certificate signature value with a preset certificate authority public key and generating a verification result, and outputting feedback information based on the verification result. The present invention implements the hardware-level unloading function of the identity authentication process through a smart network card, solving the problems of high computational overhead and poor scalability of traditional TLS two-way authentication.
Owner:JIHUA LAB

Communication configuration method, device and medium based on DPU centralized service mesh

The application relates to a communication configuration method and device based on a DPU centralized service grid and a medium, in particular to the technical field of centralized service grids. The application is applied to a client node, the client node comprises a client host and a client data processing unit (DPU), the client host deploys a client preset adaptation component, and the client DPU deploys a client data plane agent; the method comprises the following steps: the client preset adaptation component receives a key discovery service request sent by the client data plane agent, generates a certificate signature request and sends the certificate signature request to a server control plane component, so that the server control plane component issues a client certificate; the client preset adaptation component receives the client certificate; and after the client preset adaptation component performs format conversion on the client certificate, the client preset adaptation component sends the client certificate to the client data plane agent, so that the client data plane agent performs bidirectional transport layer security communication by using the client certificate.
Owner:YUSUR TECH CO LTD

Digital certificate automatic distribution method and system

The invention provides a digital certificate automatic distribution method and system, and the method comprises the steps: carrying out the identity verification based on a certificate signature request file indicated by a certificate application request when an auditing node group receives the certificate application request sent by a target client, and obtaining an identity verification result, the target client is any one client in the at least one client; the certificate issuing node group reads the certificate signature request file when the identity verification result is used for indicating that the identity verification is passed; generating a target digital certificate based on the certificate signature request file, and writing the target digital certificate into a certificate block chain; and the target client downloads the target digital certificate from the certificate block chain. According to the embodiment of the invention, the digital certificate can be conveniently and automatically distributed, so that the distribution efficiency of the digital certificate is improved.
Owner:DUXIAOMAN TECH (BEIJING) CO LTD

A virtual machine migration method, device, equipment and medium

The application discloses a virtual machine migration method, device, equipment and medium, and belongs to the technical field of servers. The method comprises the following steps: when OpenStack is required to perform a virtual machine migration operation, a target libvirt container image is acquired; a target computing node for deploying the target libvirt container image is specified in the OpenStack, and it is judged whether the target libvirt container image needs to perform the migration operation by using a national secret algorithm according to a global configuration file; if yes, a central certificate is generated according to the national secret algorithm, and a corresponding relationship between the target computing node and the central certificate is stored into a libvirt pod; a client certificate and a server certificate are generated according to the central certificate, and each certificate is stored into a specified directory, so as to deploy the target libvirt container image on the target computing node. By the method, the safety and reliability of the virtual machine in the migration process can be further ensured.
Owner:JINAN INSPUR DATA TECH CO LTD