首页> 外国专利> Computer system employing dual-band authentication using file operations by trusted and untrusted mechanisms

Computer system employing dual-band authentication using file operations by trusted and untrusted mechanisms

机译:通过受信任和不受信任机制使用文件操作来采用双频带身份验证的计算机系统

摘要

A first machine (e.g., server VM) authenticates an untrusted second machine (e.g., new client VM) as a condition to performing or allowing a protected operation. An authentication identifier is written to a file of a file system using one mechanism, and then read from the file using another mechanism. One of the mechanisms is an untrusted mechanism employing the untrusted second machine, while the other is a trusted mechanism performed by the first machine either alone or in combination with a trusted management component that has privileged access to the file system. If the written and read values match, it can be inferred that the second machine is authentic, because the trusted management component has identified and accessed an existing file system that is also separately accessed by the second machine.
机译:第一机器(例如,服务器VM)认证不可信的第二机器(例如,新的客户端VM),作为执行或允许受保护的操作的条件。身份验证标识符使用一种机制写入文件系统的文件,然后使用另一种机制从文件中读取。其中一种机制是使用不受信任的第二台机器的不受信任机制,而另一种机制是由第一台机器单独执行或与特权访问文件系统的受信任管理组件结合执行的受信任机制。如果写入值和读取值匹配,则可以推断出第二台机器是真实的,因为可信管理组件已识别并访问了也由第二台机器单独访问的现有文件系统。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号