Technique for handling subsequent user identification and password requests with identity change within a certificate-based host session
    1.
    发明授权
    Technique for handling subsequent user identification and password requests with identity change within a certificate-based host session 失效
    用于在基于证书的主机会话内处理后续用户标识和密码请求的技术用于身份更改

    公开(公告)号:US06976164B1

    公开(公告)日:2005-12-13

    申请号:US09619912

    申请日:2000-07-19

    摘要: The present invention provides a method, system, and computer program product which enables changing user credentials that are used to access legacy host applications and/or systems which provide legacy host data during a secure host access session which is authenticated using a digital certificate and is protected by a host-based security system, such as RACF (Resource Access Control Facility, a product offered by the IBM Corporation), where these changed credentials are used to authenticate a user after previously-provided credentials have been used for authentication earlier in the same session. The changed credentials may belong to the same user, where that user happens to have a different user ID and/or password for different legacy host applications and wishes to change from accessing one legacy host application to accessing another. Or, the changed credentials may be used to enable a different user to interact with the same legacy host application used by the previously-authenticated user. The disclosed technique may also be used advantageously to authenticate a user for accessing an application, when the user's credentials are not changing.

    摘要翻译: 本发明提供一种方法,系统和计算机程序产品,其能够改变用于访问传统主机应用的用户凭证和/或在使用数字证书认证的安全主机访问会话期间提供传统主机数据的系统,并且是 受基于主机的安全系统的保护,例如RACF(资源访问控制设施,IBM公司提供的产品),其中这些更改的凭据用于在之前提供的凭据在 相同的会话 已更改的凭据可能属于同一用户,其中该用户恰好具有不同的传统主机应用程序的不同用户ID和/或密码,并希望从访问一个旧主机应用程序改变为访问另一个。 或者,更改的凭证可以用于使不同的用户能够与先前认证的用户使用的相同的遗留主机应用交互。 当用户的凭证不改变时,所公开的技术也可以有利地用于认证用户访问应用。

    Technique for handling subsequent user identification and password requests within a certificate-based host session
    2.
    发明授权
    Technique for handling subsequent user identification and password requests within a certificate-based host session 有权
    在基于证书的主机会话中处理后续用户标识和密码请求的技术

    公开(公告)号:US06934848B1

    公开(公告)日:2005-08-23

    申请号:US09619205

    申请日:2000-07-19

    IPC分类号: G06F11/30 G06F21/00 H04L9/00

    摘要: The present invention provides a method, system, and computer program product for enabling a user to provide a single system sign-on for accessing one or more legacy host applications and/or one or more systems which provide legacy host data (such as legacy database systems) during a secure host access session which is authenticated using a digital certificate and is protected by a host-based security system, such as RACF (Resource Access Control Facility, a product offered by the IBM Corporation), where the same set of credentials must be provided more than once during the secure session. The subsequent provision of the credentials may be transparent to the user, and does not require change to existing legacy applications or systems.

    摘要翻译: 本发明提供了一种方法,系统和计算机程序产品,用于使用户能够提供用于访问一个或多个传统主机应用的单个系统登录和/或提供传统主机数据的一个或多个系统(诸如传统数据库 系统),在安全的主机访问会话期间,它使用数字证书进行身份验证,并受到基于主机的安全系统的保护,例如RACF(资源访问控制设施,由IBM公司提供的产品),其中相同的凭据集 必须在安全会话期间多次提供。 证书的后续提供可能对用户是透明的,并且不需要改变现有的遗留应用或系统。