×

Data communications

  • US 7,233,997 B1
  • Filed: 06/26/1998
  • Issued: 06/19/2007
  • Est. Priority Date: 06/26/1997
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of operating an authenticating server system for authenticating a user of a client application provided on a client terminal having no unique IP address via a data communications network, the server system being arranged to control access to a document stored on a resource server connected to said data communications network, said method comprising performing the following steps in said server system:

  • receiving at the resource server a request for said document generated by said client application provided on the terminal having no unique IP address;

    evaluating at the resource server client-side persistent information accompanying said request including;

    checking if the client-side persistent information contains an address token previously issued by the resource server which uniquely identifies the user, and performing the following steps at the resource server;

    i) if no address token which uniquely identifies the user is contained in the client-side persistent information accompanying said request;

    generating an address token which uniquely identifies the terminal address of the user, the generated address token replacing an IP address of the client terminal as a way of subsequently re-identifying the terminal address of the user;

    transmitting the generated address token to the client application in a client-side persistent information packet so that the address token can be used to uniquely re-identify the user when re-transmitted with user authentication data to the resource server; and

    storing said address token for the user; and

    ii) if an address token is received which accompanies user authentication data, using said address token to uniquely re-identify the address of the terminal from which the original document request was received;

    validating the address token using said user authentication data received from the client terminal in said client-side persistent information by reference to user authentication data already stored on said resource server;

    updating the validated address token for an authenticated user with access status of the authenticated user associated with the validated address token;

    transmitting a client-side persistent information packet containing the updated validated address token to the client terminal; and

    iii) if an address token which uniquely identifies the user is contained in the client-side persistent information accompanying said request and the address token is a validated address token, using said validated address token to enable said resource server to validate said request for said document by checking if said stored access status for said user includes access to said document.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×