首页> 外国专利> Method and system for network single-sign-on using a public key certificate and an associated attribute certificate

Method and system for network single-sign-on using a public key certificate and an associated attribute certificate

机译:使用公钥证书和关联的属性证书进行网络单点登录的方法和系统

摘要

A methodology is presented for a network single sign-on (SSO) authentication process using digital certificates. A user has access to protected resources, such as legacy applications, that require verification of a user's authentication data prior to providing access. The user's authentication data is encrypted using the public key of the user, and an attribute certificate containing the encrypted authentication data is generated by an attribute-certificate-issuing authority. When a user requires access to the protected resource, an SSO agent performs an initial authentication process against the user. The SSO agent then retrieves the user's attribute certificate, and for subsequent authentication requests for other protected resources, the SSO agent uses the authentication data from the attribute certificate that corresponds to the targeted protected resource. The SSO agent forwards the required authentication data to the protected resource, and the protected resource then authenticates a user based on the provided authentication data.
机译:提出了一种使用数字证书的网络单点登录(SSO)身份验证过程的方法。用户可以访问受保护的资源,例如旧版应用程序,这些资源需要在提供访问权限之前验证用户的身份验证数据。使用用户的公共密钥对用户的认证数据进行加密,并且由属性证书发布机构来生成包含加密的认证数据的属性证书。当用户要求访问受保护的资源时,SSO代理将对用户执行初始身份验证过程。然后,SSO代理检索用户的属性证书,并且对于其他受保护资源的后续身份验证请求,SSO代理将使用来自与目标保护资源相对应的属性证书的身份验证数据。 SSO代理将所需的身份验证数据转发到受保护的资源,然后受保护的资源根据提供的身份验证数据对用户进行身份验证。

著录项

  • 公开/公告号US8185938B2

    专利类型

  • 公开/公告日2012-05-22

    原文格式PDF

  • 申请/专利权人 MESSAOUD BENANTAR;

    申请/专利号US20010821064

  • 发明设计人 MESSAOUD BENANTAR;

    申请日2001-03-29

  • 分类号G06F7/04;

  • 国家 US

  • 入库时间 2022-08-21 17:28:01

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号