首页> 外国专利> Method and system for globally restricting client access to a secured web site

Method and system for globally restricting client access to a secured web site

机译:用于全局限制客户端访问安全网站的方法和系统

摘要

A method and system are provided for restricting client access to a web site. A first web server receives a client login and, in response, allocates a cookie to the client containing an access credential having at least one client role-based attribute. A second web server hosts the secured web site, the web site having an associated security file containing at least one client role-based access privilege. In response to the client's HTTP request at the second server, the cookie is retrieved, decoded and the access credential is compared to the at least one client role-based access privilege. If the access credential has at least one role-based attribute in common with the at least one client role-based access privilege, the client is granted access to the site. Alternately, a site owner defines a token access credential attribute and security file privilege for hierarchal group access to the secured web site.
机译:提供了一种用于限制客户端访问网站的方法和系统。第一网络服务器接收客户端登录,并且作为响应,向客户端分配cookie,该cookie包含具有至少一个基于客户端角色的属性的访问凭证。第二个网络服务器托管受保护的网站,该网站具有关联的安全文件,该文件包含至少一个基于客户端角色的访问特权。响应于第二服务器上客户端的HTTP请求,对cookie进行检索,解码,并将访问凭据与至少一个基于客户端角色的访问特权进行比较。如果访问凭证具有至少一个基于角色的属性与至少一个基于客户端角色的访问特权,则向客户端授予对该站点的访问权限。或者,网站所有者定义令牌访问凭据属性和安全文件特权,以用于对受保护网站的分层组访问。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号