首页> 外国专利> Authenticating user access to a network server without communicating user authentication cookie to the network server

Authenticating user access to a network server without communicating user authentication cookie to the network server

机译:验证用户对网络服务器的访问权限而无需将用户身份验证cookie传递给网络服务器

摘要

A system determines whether to grants access to a network server by a user. Initially, a user attempts to gain access to a network server, such as a web server. Prior to granting access to the network server, the network server authenticates the user by sending an authentication request to an authentication server. The authentication server determines whether the user was already authenticated by the authentication server. If the user was already authenticated by the authentication server, then the network server is notified that the user is authenticated. The network server then grants the user access to the network server. If the user was not already authenticated by the authentication server, then login information is retrieved from the user and compared to authentication information maintained by the authentication server. If the retrieved login information matches the authentication information, then the network server is notified that the user is authenticated. The retrieved login information and the authentication information is concealed from the network server. If the user is authenticated, then a user profile is communicated to the network server along with the notification that the user is authenticated. If the user is successfully authenticated, then a cookie is provided to an Internet browser operated by the user. The cookie contains information regarding user authentication, the user's profile, and a list of network servers previously visited by the user.
机译:系统确定是否授予用户访问网络服务器的权限。最初,用户尝试获得对网络服务器(例如Web服务器)的访问权限。在授予对网络服务器的访问权限之前,网络服务器通过向身份验证服务器发送身份验证请求来对用户进行身份验证。认证服务器确定用户是否已被认证服务器认证。如果用户已经通过身份验证服务器进行身份验证,则通知网络服务器该用户已通过身份验证。然后,网络服务器向用户授予对网络服务器的访问权限。如果用户尚未通过身份验证服务器进行身份验证,则从用户检索登录信息,并将其与身份验证服务器维护的身份验证信息进行比较。如果检索到的登录信息与身份验证信息匹配,则通知网络服务器用户已通过身份验证。从网络服务器隐藏了检索到的登录信息和认证信息。如果用户通过了身份验证,则用户配置文件将与用户通过身份验证的通知一起传送到网络服务器。如果用户成功通过身份验证,则向用户操作的Internet浏览器提供cookie。 Cookie包含有关用户身份验证,用户个人资料以及用户先前访问过的网络服务器列表的信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号