×

Delegated authentication using a generic application-layer network protocol

  • US 7,412,720 B1
  • Filed: 11/02/2001
  • Issued: 08/12/2008
  • Est. Priority Date: 11/02/2001
  • Status: Expired due to Term
First Claim
Patent Images

1. A computer-implemented method for use in a network environment including an enterprise server, comprising:

  • storing at the enterprise server multiple security credentials for a remote user to access respective secure resources residing on a network employing a generic application layer network protocol;

    maintaining a map between a plurality of resource servers and a type of security credential required to access each resource server, including maintaining a true/false flag and storing a path/domain for each of the plurality of resource servers;

    receiving at the enterprise server a signal representing a request from the remote user for a first of the secure resources, wherein the request includes a logon credential for the remote user;

    determining, by referring to the map and without the intervention of the user, that the type of security credential for the remote user that is required to access the first secure resource comprises a first of the security credentials corresponding to a first path/domain for a first of the resource servers for which the map indicates a true flag, and wherein the determining includes matching the first path/domain with a stored path/domain corresponding to said first of the resource servers;

    sending from the enterprise server a signal representing a second request to retrieve the first secure resource, the second request including a first of the security credentials for the user of the type required to access the first secure resource;

    receiving at the enterprise server a signal representing a first single-sign-on (SSO) credential generated by a first SSO provider based on the logon credential;

    sending from the enterprise server a signal representing the first SSO credential to retrieve the first secure resource when the type of credential required to access the first secure resource includes the first SSO credential; and

    sending from the enterprise server a signal representing the first SSO credential to retrieve the first secure resource when the type of credential required to access the first secure resource includes a second SSO credential corresponding to a second SSO provider having a trust relationship with the first SSO provider.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×