-
公开(公告)号:US20050223217A1
公开(公告)日:2005-10-06
申请号:US10817154
申请日:2004-04-01
申请人: John Howard , Daniel Schiappa , Khaja Ahmed , Kyle Young
发明人: John Howard , Daniel Schiappa , Khaja Ahmed , Kyle Young
CPC分类号: H04L63/0807 , G06F21/31 , G06F2221/2115 , H04L63/0884
摘要: A user is authenticated for a relying computing entity (e.g., an enterprise) through an authentication broker service, wherein a trust relationship exists between the relying computing entity and the authentication broker service. The authentication broker service has a trust relationship with the relying computing entity and the authentication service that issued the identity of the user. The relying computing entity asks the authentication broker service to authenticate the identity of the user. The authentication broker service captures the user's credential (or directs the authentication service to do so) and sends an authentication response (e.g., a token) to the relying computing entity in order to authenticate the identity of the user to the relying computing entity. The relying computing entity verifies the authentication response based on the trust relationship between the relying computing entity and the authentication broker service.
摘要翻译: 用户通过认证代理服务为依赖计算实体(例如,企业)进行认证,其中在依赖计算实体和认证代理服务之间存在信任关系。 认证代理服务与依赖计算实体和颁发用户身份的认证服务具有信任关系。 依赖计算实体请求认证代理服务验证用户的身份。 认证代理服务捕获用户的凭证(或指示认证服务来执行),并将认证响应(例如,令牌)发送到依赖计算实体,以便向依赖计算实体认证用户的身份。 依赖计算实体根据依赖计算实体和认证代理服务之间的信任关系来验证认证响应。
-
公开(公告)号:US07167985B2
公开(公告)日:2007-01-23
申请号:US09845221
申请日:2001-04-30
申请人: Khaja Ahmed
发明人: Khaja Ahmed
IPC分类号: H04L9/00
CPC分类号: H04L63/0823 , G06Q30/06 , G06Q40/00 , H04L63/0853 , H04L63/12 , H04L2463/102
摘要: A system and method for providing trusted browser verification services. In a preferred embodiment, these services are provided within the context of a four-corner trust model comprising a subscribing customer and a relying customer, engaged in an on-line transaction. The subscribing and relying customers are preferably customers of first and second financial institutions, respectively, that issue to them hardware tokens for their respective private keys and digital certificates. The buyer is preferably provided with a Web browser to conduct electronic transactions. A distinct-trusted verifier or other entity ensures in a verifiable manner that the browser used by the subscribing customer does not contain any code that is not trusted by verifying the digital signatures on each running browser component of the subscribing customer's browser and ensuring that the signature was applied by an entity that is authorized to certify the trustworthiness of the component.
摘要翻译: 一种用于提供可信赖的浏览器验证服务的系统和方法。 在优选实施例中,这些服务是在包括从事在线交易的订阅客户和依赖客户的四角信任模型的上下文中提供的。 订阅和依赖客户最好分别是第一和第二金融机构的客户,向他们发送他们各自的私钥和数字证书的硬件令牌。 买方最好有一个网页浏览器进行电子交易。 不同信任的验证者或其他实体以可验证的方式确保订阅客户使用的浏览器不包含通过验证订阅客户浏览器的每个运行的浏览器组件上的数字签名而不被信任的任何代码,并确保签名 被授权验证组件的可信赖性的实体应用。
-
公开(公告)号:US20060123227A1
公开(公告)日:2006-06-08
申请号:US11341078
申请日:2006-01-26
申请人: Lawrence Miller , Guy Tallent , Khaja Ahmed
发明人: Lawrence Miller , Guy Tallent , Khaja Ahmed
IPC分类号: H04L9/00
CPC分类号: G06Q20/3829 , G06Q20/02 , G06Q20/367 , G06Q20/38215 , G06Q20/3825 , G06Q20/389 , G06Q20/40 , G06Q30/06 , G06Q30/0609
摘要: A system and method are disclosed for transparently providing certificate validation and other services without requiring a separate service request by either a relying customer or subscribing customer. In a preferred embodiment, after the subscribing customer digitally signs a document (e.g., a commercial document such as a purchase order), it forwards the document to a trusted messaging entity which validates the certificates of both the subscribing customer and relying customer and the respective system participants of which they are customers. If the certificates are valid, the trusted messaging entity appends a validation message to the digitally-signed document and forwards the document to the relying customer. A validation message is also preferably appended to a digitally-signed receipt from the relying customer and transmitted to the subscribing customer. In this way, both the relying customer and subscribing customer obtain certification of their respective counterparty to the transaction.
-
-