发明申请
- 专利标题: Architecture and design for central authentication and authorization in an on-demand utility environment
- 专利标题(中): 在按需实用环境中进行中心认证和授权的体系结构和设计
-
申请号: US10782443申请日: 2004-02-19
-
公开(公告)号: US20050188420A1公开(公告)日: 2005-08-25
- 发明人: Messaoud Benantar , Yen-Fu Chen , John Dunsmoir , Randolph Forlenza , Wei Liu , Sandra Schlosser
- 申请人: Messaoud Benantar , Yen-Fu Chen , John Dunsmoir , Randolph Forlenza , Wei Liu , Sandra Schlosser
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 主分类号: G06F11/30
- IPC分类号: G06F11/30 ; H04L29/06
摘要:
A Centralized Authentication & Authorization (CAA) system that facilitates secure communication between service clients and service providers. CAA comprises a Service Request Filter (SRF), a Service Client Authentication Program (SCAP), a Service Authorization Program (SAP), and an Authorization Database (ADB). The SRF intercepts service requests, extracts the service client's identifier from a digital certificate attached to the request, and stores the identifier in memory accessible to service providers. In the preferred embodiment, the SRF forwards the service request to a web service manager. The web service manager invokes SCAP. SCAP matches the identifier with a record stored in ADB. SAP queries ADB to determine if the service request is valid for the service client. If the service request is valid, SAP authorizes the service request and the appropriate service provider processes the service request.
公开/授权文献
信息查询