×

Access control in a distributed computer system

  • US 5,220,603 A
  • Filed: 02/25/1992
  • Issued: 06/15/1993
  • Est. Priority Date: 03/08/1991
  • Status: Expired due to Term
First Claim
Patent Images

1. A data processing system comprising:

  • (a) a plurality of initiator entries, each having a set of initiator qualifier attributes associated therewith,(b) a plurality of target entities, connected to and accessible by said initiator entries,(c) authentication means coupled to said target entities for issuing each target entity, on request, with a privilege attribute certificate (PAC) indicating access rights granted to that target entity,(d) PAC validation means, coupled to said target entities, for validating PACs on behalf of said target entities,(e) key distribution means, coupled to said initiator entities, for issuing to each initiator entity, on request, with(i) a first key, for communicating with the PAC validation means, the first key being encrypted under a second key known to both the initiator entity and the key distribution means,(ii) a package comprising said first key, and the initiator qualifier attributes of the initiator entity, encrypted together under a third key known only to the key distribution means and to the PAC validation means,(f) connection means for interconnecting each initiator entity to the PAC validation means to permit the initiator entity to present said package to the PAC validation means, and(g) a table associated with the PAC validation means, for recording an association between the first key and the initiator qualifier attributes in said package.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×