首页> 外国专利> System and methods for providing stateless security management for web applications using non-HTTP communications protocols

System and methods for providing stateless security management for web applications using non-HTTP communications protocols

机译:使用非HTTP通信协议为Web应用程序提供无状态安全管理的系统和方法

摘要

A gateway server interoperates with client and remote server systems to provide stateless security management for a distributed Web application. A Web client performs an authentication challenge directed to a user of the Web-browser client where a secure token is not present in a local store instance corresponding to the client application. The authentication challenge obtains the user credentials and then exchanges the user credentials with the gateway server for a secure token. The secure token is then sent in a protocol specific connect message to the gateway server. The gateway server, in response to receipt of the connect message, initiates a WebSocket connection directed to the remote Web service by inspecting the connect message to recover the secure token, evaluating the secure token to obtain user credentials, injecting the secure token with the user credentials, and sending the connect message to the remote Web service.
机译:网关服务器与客户端和远程服务器系统进行互操作,以为分布式Web应用程序提供无状态安全管理。 Web客户端执行针对Web浏览器客户端用户的身份验证质询,其中在与客户端应用程序相对应的本地商店实例中不存在安全令牌。身份验证质询获取用户凭据,然后与网关服务器交换用户凭据以获取安全令牌。然后,将安全令牌以协议特定的连接消息发送到网关服务器。网关服务器响应于接收到连接消息,通过检查连接消息以恢复安全令牌,评估安全令牌以获得用户凭据,向用户注入安全令牌,来启动指向远程Web服务的WebSocket连接。凭据,并将连接消息发送到远程Web服务。

著录项

  • 公开/公告号AU2010253949A1

    专利类型

  • 公开/公告日2011-12-22

    原文格式PDF

  • 申请/专利权人 KAAZING CORPORATION;

    申请/专利号AU2010253949A1

  • 发明设计人 FALLOWS JOHN R.;SALIM FRANK;

    申请日2010-05-28

  • 分类号G06F15/173;

  • 国家 AU

  • 入库时间 2022-08-21 17:19:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号