FEDERATED REALM DISCOVERY
First Claim
1. A method of identifying a home security authority for authenticating a security principal within a federation, the method comprising:
- receiving through a login user interface of a non-home security authority on a user device at least a portion of a security principal identifier of the security principal;
requesting identification of the home security authority of the security principal based on the at least a portion of the security principal identifier;
receiving the identification of the home security authority of the security principal, responsive to the requesting operation.
3 Assignments
0 Petitions
Accused Products
Abstract
A federated realm discovery system within a federation determines a “home” realm associated with a portion of the user'"'"'s credentials before the user'"'"'s secret information (such as a password) is passed to a non-home realm. A login user interface accepts a user identifier and, based on the user identifier, can use various methods to identify an account authority service within the federation that can authenticate the user. In one method, a realm list of the user device can be used to direct the login to the appropriate home realm of the user. In another method, an account authority service in a non-home realm can look up the user'"'"'s home realm and provide realm information directing the user device to login at the home realm.
-
Citations
20 Claims
-
1. A method of identifying a home security authority for authenticating a security principal within a federation, the method comprising:
-
receiving through a login user interface of a non-home security authority on a user device at least a portion of a security principal identifier of the security principal; requesting identification of the home security authority of the security principal based on the at least a portion of the security principal identifier; receiving the identification of the home security authority of the security principal, responsive to the requesting operation. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A computer-readable storage medium having computer-executable instructions for performing a computer process that submits user credentials of a security principal to a home security authority within a federation, the computer process comprising:
-
presenting to the security principal a login user interface from a non-home security authority within the federation; receiving via the login user interface at least a portion of a security principal identifier of the security principal; receiving identification of the home security authority of the security principal based on the at least a portion of the security principal identifier; transmitting the user credentials of the security principal, including the security principal identifier and associated secret information of the security principal, to the identified home security authority without transmitting the associated secret information of the security principal to the non-home security authority. - View Dependent Claims (10, 11, 12, 13, 14, 15, 16)
-
-
17. A method of identifying a home security authority for authenticating a security principal within a federation, the method comprising:
-
receiving at a non-home security authority a request from a security principal requesting identification of the home security authority of the security principal based on at least a portion of a security principal identifier of the security principal provided with the request; evaluating a realm list providing one or more mappings between security principal identifiers or portions thereof and realm information, the realm information identifying the home security authority corresponding to the security principal identifier or portion thereof, sending from the non-home security authority to the security principal an identification of the home security authority of the security principal corresponding to the security principal identifier or a portion thereof that matches the at least a portion of the security principal identifier of the security principal. - View Dependent Claims (18, 19, 20)
-
Specification