Invention Grant
- Patent Title: Providing identity-related information and preventing man-in-the-middle attacks
- Patent Title (中): 提供身份相关信息和防止中间人的袭击
-
Application No.: US10638184Application Date: 2003-08-08
-
Publication No.: US07240362B2Publication Date: 2007-07-03
- Inventor: Birgit M. Pfitzmann , Michael Waidner
- Applicant: Birgit M. Pfitzmann , Michael Waidner
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Scully, Scott, Murphy & Presser, P.
- Agent Lisa M. Yamonaco
- Priority: EP02405761 20020903
- Main IPC: H04L9/32
- IPC: H04L9/32

Abstract:
This invention provides identity-related information about a client application to an honest requesting entity, ensuring identity of client applications and preventing man-in-the-middle attacks. An example method comprises transferring identity-related information hosted on an identity provider about a client application to an honest requesting entity by: the client application receiving from a particular entity a request to forward an inner request comprising an identifier of the honest requesting entity to an identity provider selected by the client application; the client application forwards the inner request to the identity provider holding the identity-related information; the client application receives from the identity provider a response envelope instructing the client application to forward an inner response comprising the identity-related information requested in the inner request and the identifier; the client application derives an address of the honest requesting entity having the identifier; and the client application forwards the inner response to the derived address.
Public/Granted literature
- US20040064687A1 Providing identity-related information and preventing man-in-the-middle attacks Public/Granted day:2004-04-01
Information query