System, method and computer program product for authenticating users using a lightweight directory access protocol (LDAP) directory server
First Claim
Patent Images
1. A system for authorizing client access to a network resource, comprising:
- a server having at least one directory that can be accessed using a network protocol, said at least one directory being configured to store information concerning an entity'"'"'s organization; and
a firewall that is configured to intercept network resource requests from a plurality of client users on an internal network, said firewall being operative to authorize a network resource request based upon a comparison of the contents of at least part of one or more entries in said at least one directory to an authorization filter, wherein said authorization filter is generated based on a directory schema that is predefined by said entity.
16 Assignments
0 Petitions
Accused Products
Abstract
A system, method and computer program product for providing authentication to a firewall using a lightweight directory access protocol (LDAP) directory server is disclosed. The firewall can be configured through a graphical user interface to implement an authentication scheme. The authentication scheme is based upon a determination of whether at least part of one or more LDAP entries satisfy an authorization filter.
124 Citations
15 Claims
-
1. A system for authorizing client access to a network resource, comprising:
-
a server having at least one directory that can be accessed using a network protocol, said at least one directory being configured to store information concerning an entity'"'"'s organization; and a firewall that is configured to intercept network resource requests from a plurality of client users on an internal network, said firewall being operative to authorize a network resource request based upon a comparison of the contents of at least part of one or more entries in said at least one directory to an authorization filter, wherein said authorization filter is generated based on a directory schema that is predefined by said entity. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. An authentication method at a firewall, comprising the steps of:
-
(a) receiving a network resource request from a client user at an internal network; (b) querying, using a network protocol, at least one directory that is configured to store information concerning an entity'"'"'s organization, wherein said query is based upon an authorization filter that is generated based on a directory schema that is predefined by said entity; (c) determining, based on the results of said query, whether the contents of at least part of one or more entries in said at least one directory satisfy said authorization filter; and (d) permitting said network resource request through said firewall if said authorization filter is satisfied. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
-
15. A computer program product for enabling a processor in a computer system to implement an authentication process, said computer program product comprising:
-
a computer usable medium having computer readable program code embodied in said medium for causing a program to execute on the computer system, said computer readable program code comprising; first computer readable program code for enabling the computer system to receive a network resource request from a client user at an internal network; second computer readable program code for enabling the computer system to query, using a network protocol, at least one directory that is configured to store information concerning an entity'"'"'s organization, wherein said query is based upon an authorization filter that is generated based on a directory schema that is predefined by said entity; third computer readable program code for enabling the computer system to determine, based on the results of said query, whether the contents of at least part of one or more entries in said at least one directory satisfy said authorization filter; and fourth computer readable program code for enabling the computer system to permit said network resource request through a firewall if said authorization filter is satisfied.
-
Specification