A system and method of exploiting the security of a secure communication channel to secure a non-secure communication channel
Abstract
The present invention features a system and method for establishing a secure communication channel between a client and an application server. In one embodiment, a ticket service generates a ticket having an identifier and a session key. A communications device obtains the ticket from the ticket service and transmits the ticket to a client over a secure communication channel. The client transmits the identifier of the ticket to an application server over an application communication channel. The application server then obtains a copy of the session key of the ticket from the ticket service. Communications exchanged between the client and the application server over the application communication channel are then encrypted using the session key to establish the application communication channel as a secure communication channel.
Claims
exact text as granted — not AI-modified1 . A method for establishing a secure communication channel between a client and an application server, the method comprising the steps of:
(a) obtaining, by a web server, a MIME type document and a ticket associated with a client, the MIME type document comprising a client application program, the ticket having an identifier and a session key; (b) receiving, by a web browser, the MIME type document and the ticket from the web server; (c) invoking, by the web browser, the received client application program; (d) establishing an application communication channel between the client and the application server; (e) transmitting, by the client application program, the identifier from the ticket to the application server over the application communication channel; (f) obtaining, by the application server, a copy of the session key from the web server using the identifier; and (g) encrypting communications between the client application program and the application server over the application communication channel using the session key.
2 . The method of claim 1 wherein step (a) further consists of establishing a secure web communication channel between the web browser and the web server.
3 . The method of claim 1 wherein step (c) further consists of transferring, by the web browser, the ticket to the client application program.
4 . The method of claim 1 wherein step (g) further comprises decrypting communications between the client application program and the application server using the session key.
5 . The method of claim 1 wherein step (a) further comprises receiving, at the web server, a request from the client to have an application program executed on the application server and to have output from the application program executing on the application server transmitted to the client application program.
6 . The method of claim 5 wherein step (g) further comprises executing, by the application server, the application program identified in the request, and transmitting, by the application server, the output of the application program over the application communication channel via a remote display protocol.
7 . The method of claim 1 wherein step (a) further comprises obtaining a MIME type document having a remote display client for the client application program.
8 . The method of claim 1 wherein step (c) further comprises installing the client application program for a first time on the client.
9 . The method of claim 1 wherein step (a) further comprises obtaining a ticket having an application server certificate for the identifier.
10 . The method of claim 1 wherein step (a) further comprises obtaining a ticket having a session key substantially equivalent to a null value.
11 . The method of claim 1 wherein step (a) further comprises obtaining a ticket granting access for a single use.
12 . The method of claim 1 wherein step (a) further comprises obtaining a ticket granting access to a previously authorized resource.
13 . The method of claim 1 wherein step (e) further comprises transmitting a password to the application server.
14 . The method of claim 1 wherein step (a) further comprises obtaining the MIME type document from the application server.
15 . The method of claim 6 wherein step (g) further comprises using the Independent Computing Architecture protocol for the remote display protocol.
16 . The method of claim 6 wherein step (g) further comprises using the Remote Display Protocol for the remote display protocol.
17 . A client system for establishing a secure communication channel with an application server, the client system comprising:
a web browser associated with a client; a web server in communication with the web browser over a web communication channel, the web server obtaining a MIME type document and a ticket associated with the client, the MIME type document comprising a client application program, the ticket having an identifier and a session key; the web browser receiving, from the web server, the ticket and the MIME type document, the web browser invoking the received client application program; an application server, in communication with the client over an application communication channel, receiving the identifier from the client application program, and the application server, in communication with the web server, obtaining a copy of the session key by using the identifier; and the application server and the client application program encrypting communications over the application communication channel using the session key.
18 . The system of claim 17 wherein the web communication channel is secure.
19 . The system of claim 17 wherein the web browser transfers the ticket to the client application program.
20 . The system of claim 17 wherein the application server and the client application program decrypt communications over the application communication channel using the session key.
21 . The system of claim 17 wherein the web server receives a request from the client to have an application program executed on the application server and to have output from the application program executing on the application server transmitted to the client application program.
22 . The system of claim 21 wherein the application server executes the application program identified in the request, and transmits the output of the application program to the client application program over the application communication channel via a remote display protocol.
23 . The system of claim 17 wherein the client application program is a remote display client.
24 . The system of claim 17 wherein the client application program is installed for a first time on the client.
25 . The system of claim 17 wherein the identifier is an application server certificate.
26 . The system of claim 17 wherein the session key is substantially equivalent to a null value.
27 . The system of claim 17 wherein the ticket grants access for a single use.
28 . The system of claim 17 wherein the ticket grants access to a previously authorized resource.
29 . The system of claim 17 wherein the client transmits a password to the application server.
30 . The system of claim 17 wherein the web server obtains the MIME type document from the application server.
31 . The system of claim 22 wherein the remote display protocol is the Independent Computing Architecture protocol.
32 . The system of claim 22 wherein the remote display protocol is the Remote Display Protocol.
33 . A method for establishing a secure communication channel with an application server, the method comprising the steps of:
(a) receiving a MIME type document and a ticket from the web server, the ticket having an identifier and a session key, and the MIME type document comprising a client application program; (b) invoking the received client application program; (c) establishing an application communication channel with an application server; (d) transmitting the identifier from the ticket to the application server over the application communication channel to provide the application server with information for obtaining a copy of the session key; and (e) encrypting communications to the application server over the application communication channel using the session key.
34 . The method of claim 33 wherein step (e) further comprises decrypting communications from the application server using the session key.
35 . The method of claim 33 wherein step (a) further comprises establishing a secure web communication channel between a web browser and the web server.
36 . The method of claim 35 wherein step (g) further comprises transferring the ticket from the web browser to the client application program.
37 . The method of claim 33 wherein step (a) further comprises sending, to the web server, a request to have an application program executed on the application server and to receive output from the application program executing on the application server.
38 . The method of claim 37 wherein step (e) further comprises executing, by the application server, the application program identified in the request, and transmitting, by the application server, the output of the application program over the application communication channel via a remote display protocol.
39 . The method of claim 33 wherein step (e) further comprises obtaining a MIME type document having a remote display client for the client application program.
40 . The method of claim 33 wherein step (a) further comprises installing the client application program for a first time.
41 . The method of claim 33 wherein step (a) further comprises obtaining a ticket having an application server certificate for the identifier.
42 . The method of claim 33 wherein step (a) further comprises obtaining a ticket having a session key substantially equivalent to a null value.
43 . The method of claim 33 wherein step (a) further comprises obtaining a ticket granting access for a single use.
44 . The method of claim 33 wherein step (a) further comprises obtaining a ticket granting access to a previously authorized resource.
45 . The method of claim 33 wherein step (d) further comprises transmitting a password to the application server.
46 . The method of claim 38 wherein step (e) further comprises using the Independent Computing Architecture protocol for the remote display protocol.
47 . The method of claim 38 wherein step (e) further comprises using the Remote Display Protocol for the remote display protocol.
48 . A client system for establishing a secure communication channel with a client, the client system comprising:
a web browser in communication with a web server over a web communication channel, the web browser receiving, from the web server, a MIME type document and a ticket, the MIME type document comprising a client application program, the ticket having an identifier and a session key; a client application program invoked by the web browser; and the client application program establishing an application communication channel with the application server, the client application program transmitting the identifier over the application communication channel, and the client application program encrypting communications to the application server over the application communication channel using the session key.
49 . The system of claim 48 wherein the client application program decrypts communications from the application server over the application communication channel using the session key.
50 . The system of claim 48 wherein the web browser transfers the ticket to the client application program.
51 . The system of claim 48 wherein the web browser transmits a request to have an application program executed on the application server and to have output of the application program executing on the application server transmitted to the client application program.
52 . The system of claim 51 wherein the application server executes the application program identified in the request, and transmits the output of the application program to the client application program over the application communication channel via a remote display protocol.
53 . The system of claim 48 wherein the client application program is a remote display client.
54 . The system of claim 48 wherein the client application program is installed for a first time on the client.
55 . The system of claim 48 wherein the identifier is an application server certificate.
56 . The system of claim 48 wherein the session key is substantially equivalent to a null value.
57 . The system of claim 48 wherein the ticket grants access for a single use.
58 . The system of claim 48 wherein the ticket grants access to a previously authorized resource.
59 . The system of claim 52 wherein the remote display protocol is the Independent Computing Architecture protocol.
60 . The system of claim 52 wherein the remote display protocol is the Remote Display Protocol.
61 . A method for establishing a secure communication channel with a client, the method comprising the steps of:
(a) obtaining, by a web server, a MIME type document and a ticket associated with a client, the MIME type document comprising a client application program, the ticket having an identifier and a session key; (b) transmitting, by the web server, the MIME type document and the ticket to a web browser over a web communication channel; (c) invoking, by the web browser, the received client application program; (d) establishing an application communication channel with the client; (e) receiving, from the client application program, the identifier from the ticket over the application communication channel; (f) obtaining a copy of the session key from the web server using the identifier; and (g) encrypting communications to the client application program over the application communication channel using the session key.
62 . The method of claim 61 wherein step (g) further comprises decrypting communications from the client application program using the session key.
63 . The method of claim 61 wherein step (b) further comprises establishing a secure web communication channel between a web browser and the web server.
64 . The method of claim 63 wherein step (b) further comprises transferring, by the web browser, the ticket to the client application program.
65 . The method of claim 61 wherein step (a) further comprises receiving, at the web server, a request from the client to have an application program executed on the client's behalf and to have output from the application program, as it is executing, transmitted to the client application program.
66 . The method of claim 65 wherein step (g) further comprises executing the application program identified in the request, and transmitting the output of the application program over the application communication channel via a remote display protocol.
67 . The method of claim 61 wherein step (g) further comprises using a remote display client for the client application program.
68 . The method of claim 61 wherein step (e) further comprises installing the client application program for a first time on the client.
69 . The method of claim 61 wherein step (a) further comprises obtaining a ticket having an application server certificate for an identifier.
70 . The method of claim 61 wherein step (b) further comprises obtaining a ticket having a session key substantially equivalent to a null value.
71 . The method of claim 61 wherein step (a) further comprises obtaining a ticket granting access for a single use.
72 . The method of claim 61 wherein step (a) further comprises obtaining a ticket granting access to a previously authorized resource.
73 . The method of claim 61 wherein step (e) further comprises receiving a password from the client.
74 . The method of claim 61 wherein step (a) further comprises obtaining the MIME type document from an application server.
75 . The method of claim 66 wherein step (g) further comprises using the Independent Computing Architecture protocol for the remote display protocol.
76 . The method of claim 66 wherein step (g) further comprises using the Remote Display Protocol for the remote display protocol.
77 . A server system for establishing a secure communication channel with a client, the server system comprising:
a ticket service generating a ticket associated with a client, the ticket having an identifier and a session key; a web server in communication with the ticket service, the web server transmitting a MIME type document and the ticket to the client over a web communication channel, the MIME type document comprising a client application program; and an application server receiving the identifier from the ticket from the client, obtaining a copy of the session key from the web server, establishing an application communication channel with the client, and encrypting communications to the client over the application communication channel using the session key.
78 . The system of claim 77 wherein the application server decrypts communications from the client over the application communication channel using the session key.
79 . The system of claim 77 wherein the web server receives a request from the client to have an application program executed on the client's behalf and to have output from the application program, as it is executing, transmitted to the client.
80 . The system of claim 77 wherein the application server executes the application program identified in the request, and transmits the output of the application program to the client application program over the application communication channel via a remote display protocol.
81 . The system of claim 77 wherein the client application program is a remote display client.
82 . The system of claim 77 wherein the client application program is installed for a first time on the client.
83 . The system of claim 77 wherein the identifier is an application server certificate.
84 . The system of claim 77 wherein the session key is substantially equivalent to a null value.
85 . The system of claim 77 wherein the ticket grants access for a single use.
86 . The system of claim 77 wherein the ticket grants access to a previously authorized resource.
87 . The system of claim 77 wherein the application server receives a password from the client.
88 . The system of claim 77 wherein the web server obtains the MIME type document from the application server.
89 . The system of claim 80 wherein the remote display protocol is the Independent Computing Architecture protocol.
90 . The system of claim 80 wherein the remote display protocol is the Remote Display Protocol.Join the waitlist — get patent alerts
Track US2005050317A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.