首页> 外国专利> User e.g. employee, authenticating method for accessing service e.g. product, involves verifying that identity level relative to user`s earlier authentication is stored with identity provider, and granting access authorization to user

User e.g. employee, authenticating method for accessing service e.g. product, involves verifying that identity level relative to user`s earlier authentication is stored with identity provider, and granting access authorization to user

机译:用户例如员工,访问服务的认证方法,例如产品,涉及验证与用户先前身份验证相关的身份级别已存储在身份提供者中,并向用户授予访问权限

摘要

The method involves verifying that an identity level relative to an earlier authentication of a user (33) is stored with an identity provider (32), and granting a service access authorization to the user if an required identity level is less than the stored level. An authentication of the user having the required level is requested and the stored level is replaced with the required level if the user is authenticated by the identity provider in order to grant the authorization to the user if the required level is less than the stored level or if no user authentication is available. Independent claims are also included for the following: (1) a tree architecture for organizing in hierarchy a set of identity levels of an entity among a group of entities (2) a device authenticating a user for accessing a service from a service provider (3) a device for requesting authentication by a service provider (4) a computer program product comprising program code instructions for implementing steps of a user authentication method (5) a signal for asserting authentication intended for exchanging an access request for a service between an identity provider and a service provider (6) a signal for requesting authentication intended for exchanging an access request for a service between an identity provider and a service provider.
机译:该方法包括验证与身份提供者(32)一起存储的相对于用户的较早认证的身份等级(33),以及如果所需的身份等级小于所存储的等级则向用户授予服务访问授权。如果具有身份级别的用户对用户进行了身份验证,则请求对具有所需级别的用户进行身份验证,并将存储的级别替换为所需的级别,以便在所需级别小于存储级别或授权级别时向用户授予授权。如果没有用户认证可用。还包括以下各项的独立权利要求:(1)树结构,用于在层次结构中组织一组实体中的一组实体的身份级别(2)验证用户身份以访问服务提供商提供的服务的设备(3 )用于请求服务提供商进行身份验证的设备(4)一种计算机程序产品,该计算机程序产品包括用于实施用户身份验证方法(5)的信号的断言程序,该信号用于声明身份验证的信号,该信号旨在在身份提供商之间交换对服务的访问请求服务提供商(6)用于请求认证的信号,该信号旨在在身份提供商和服务提供商之间交换对服务的访问请求。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号