首页> 外国专利> Single sign-on for network system that includes multiple separately-controlled restricted access resources

Single sign-on for network system that includes multiple separately-controlled restricted access resources

机译:包含多个单独控制的受限访问资源的网络系统的单点登录

摘要

A method and system are provided for authenticating users in a client-server system in a way that allows a user to sign-on to numerous servers using a different password for each server, while still only having to remember a single master password. According to one aspect of the invention, a client generates a first set of server-specific authentication information for a first server based on master authentication information stored at the client and data associated with the first server. The client then supplies the first server-specific authentication information to the first server to access restricted resources controlled by the first server. The client generates a second set of second server-specific authentication information for a second server based on the same master authentication information. However, to generate the server-specific authentication information for the second server, the master resource information is combined with data associated with the second server. The client supplies the second server-specific authentication information to the second server to access restricted resources controlled by the second server. Both the first and the second server-specific authentication information are different from the master authentication information, and the first server-specific authentication information is different from the second server-specific authentication information. Thus, the administrators of the various servers do not have information that would allow them to access the user's account at the other servers.
机译:提供了一种方法和系统,用于以允许用户使用每个服务器的不同密码登录到多个服务器的方式来认证客户端-服务器系统中的用户,同时仍然只需要记住一个主密码。根据本发明的一个方面,客户端基于存储在客户端的主认证信息和与第一服务器相关联的数据,为第一服务器生成第一组服务器特定认证信息。然后,客户端将第一服务器特定的身份验证信息提供给第一服务器,以访问由第一服务器控制的受限资源。客户端基于相同的主身份验证信息为第二个服务器生成第二组第二服务器特定的身份验证信息。然而,为了生成用于第二服务器的服务器特定的认证信息,将主资源信息与与第二服务器相关联的数据组合。客户端将第二服务器特定的身份验证信息提供给第二服务器,以访问由第二服务器控制的受限资源。第一和第二服务器特定的认证信息均与主认证信息不同,并且第一服务器特定的认证信息与第二服务器特定的认证信息不同。因此,各种服务器的管理员没有可让他们访问其他服务器上的用户帐户的信息。

著录项

  • 公开/公告号EP1081914B1

    专利类型

  • 公开/公告日2006-05-17

    原文格式PDF

  • 申请/专利权人 SUN MICROSYSTEMS INC;

    申请/专利号EP20000303400

  • 发明设计人 GUY GADI;

    申请日2000-04-20

  • 分类号H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-21 21:31:52

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号