Re: Simple resource protection with public keys
From: Henrick Hellström (henrick.hellstrm_at_telia.com)
Date: 04/28/03
- Next message: Tom St Denis: "Re: Anonymous Encrypted weblog service"
- Previous message: Tim Goodwin: "Simple resource protection with public keys"
- In reply to: Tim Goodwin: "Simple resource protection with public keys"
- Next in thread: Ernst Lippe: "Re: Simple resource protection with public keys"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 28 Apr 2003 11:11:53 GMT
Tim Goodwin wrote:
> I have devised the following protocol.
>
> The client sends a message comprising (the client's idea of) the
> current time to 1-second resolution, and a signature over that
> timestamp made with the client's private key.
>
> The server verifies the signature, and checks that the timestamp
> is within a small delta of (the server's idea of) the current
> time. If both tests pass, access to the resource is granted.
The server should also record the last time stamp and reject any
requests with time stamps not strictly later than the last time stamp
for that client.
- Next message: Tom St Denis: "Re: Anonymous Encrypted weblog service"
- Previous message: Tim Goodwin: "Simple resource protection with public keys"
- In reply to: Tim Goodwin: "Simple resource protection with public keys"
- Next in thread: Ernst Lippe: "Re: Simple resource protection with public keys"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|