Authentication and authorization pipeline architecture for use in a web server
    7.
    发明授权
    Authentication and authorization pipeline architecture for use in a web server 有权
    用于Web服务器的认证和授权流水线架构

    公开(公告)号:US06985946B1

    公开(公告)日:2006-01-10

    申请号:US09569464

    申请日:2000-05-12

    IPC分类号: G06F15/173

    CPC分类号: G06F21/31 Y10S707/99939

    摘要: A method, system, and article of manufacture for providing an authentication and authorization pipeline for use in a web server to grant access to web resources to users. The server creates an entry within an userID to roles database for each user who may access resources present on the web server and creates an entry within the roles to resource database for each resource that may be accessed on the web server. The server then authenticates the identify of each user accessing a resource on the web server using a userID, one or more authentication parameters, and a resource access request, creates a data object having an authenticated userID and one or more roles corresponding to the authenticated userID obtained from the userID to roles database, and authorizes access to a resource identified within the resource access request if one or more roles within the data object correspond to an access role corresponding to the roles listed within the roles to resource database for the identified resource.

    摘要翻译: 一种方法,系统和制品,用于提供在web服务器中使用的认证和授权流程,以向用户授予对web资源的访问。 服务器将userID内的一个条目创建给角色数据库,每个用户可以访问Web服务器上存在的资源,并在角色到资源数据库中创建可在Web服务器上访问的每个资源的条目。 然后,服务器使用用户ID,一个或多个认证参数和资源访问请求来验证访问Web服务器上的资源的每个用户的标识,创建具有经认证的用户ID和与被认证的用户ID相对应的一个或多个角色的数据对象 从用户ID获得到角色数据库,并授权访问资源访问请求中标识的资源,如果数据对象中的一个或多个角色对应于与所标识资源的角色资源数据库中列出的角色对应的访问角色。

    Authentication and authorization pipeline architecture for use in a server
    8.
    发明授权
    Authentication and authorization pipeline architecture for use in a server 有权
    用于服务器的认证和授权流水线架构

    公开(公告)号:US07266605B2

    公开(公告)日:2007-09-04

    申请号:US11273374

    申请日:2005-11-14

    IPC分类号: G06F15/173 G06F7/00 G06F17/30

    CPC分类号: G06F21/31 Y10S707/99939

    摘要: A method, system, and article of manufacture for providing an authentication and authorization pipeline for use in a web server to grant access to web resources to users. The server creates an entry within an userID to roles database for each user who may access resources present on the web server and creates an entry within the roles to resource database for each resource that may be accessed on the web server. The server then authenticates the identify of each user accessing a resource on the web server using a userID, one or more authentication parameters, and a resource access request, creates a data object having an authenticated userID and one or more roles corresponding to the authenticated userID obtained from the userID to roles database, and authorizes access to a resource identified within the resource access request if one or more roles within the data object correspond to an access role corresponding to the roles listed within the roles to resource database for the identified resource.

    摘要翻译: 一种方法,系统和制品,用于提供在web服务器中使用的认证和授权流程,以向用户授予对web资源的访问。 服务器将userID内的一个条目创建给角色数据库,每个用户可以访问Web服务器上存在的资源,并在角色到资源数据库中创建可在Web服务器上访问的每个资源的条目。 然后,服务器使用用户ID,一个或多个认证参数和资源访问请求来验证访问Web服务器上的资源的每个用户的标识,创建具有经认证的用户ID和与被认证的用户ID相对应的一个或多个角色的数据对象 从用户ID获得到角色数据库,并授权访问资源访问请求中标识的资源,如果数据对象中的一个或多个角色对应于与所标识资源的角色资源数据库中列出的角色对应的访问角色。

    Authentication and authorization pipeline architecture for use in a server
    9.
    发明申请
    Authentication and authorization pipeline architecture for use in a server 有权
    用于服务器的认证和授权流水线架构

    公开(公告)号:US20060080440A1

    公开(公告)日:2006-04-13

    申请号:US11273374

    申请日:2005-11-14

    IPC分类号: G06F15/173

    CPC分类号: G06F21/31 Y10S707/99939

    摘要: A method, system, and article of manufacture for providing an authentication and authorization pipeline for use in a web server to grant access to web resources to users. The server creates an entry within an userID to roles database for each user who may access resources present on the web server and creates an entry within the roles to resource database for each resource that may be accessed on the web server. The server then authenticates the identify of each user accessing a resource on the web server using a userID, one or more authentication parameters, and a resource access request, creates a data object having an authenticated userID and one or more roles corresponding to the authenticated userID obtained from the userID to roles database, and authorizes access to a resource identified within the resource access request if one or more roles within the data object correspond to an access role corresponding to the roles listed within the roles to resource database for the identified resource.

    摘要翻译: 一种方法,系统和制品,用于提供在web服务器中使用的认证和授权流程,以向用户授予对web资源的访问。 服务器将userID内的一个条目创建给角色数据库,每个用户可以访问Web服务器上存在的资源,并在角色到资源数据库中创建可在Web服务器上访问的每个资源的条目。 然后,服务器使用用户ID,一个或多个认证参数和资源访问请求来验证访问Web服务器上的资源的每个用户的标识,创建具有经认证的用户ID和与被认证的用户ID相对应的一个或多个角色的数据对象 从用户ID获得到角色数据库,并授权访问资源访问请求中标识的资源,如果数据对象中的一个或多个角色对应于与所标识资源的角色资源数据库中列出的角色对应的访问角色。

    System and method for protecting configuration settings in distributed text-based configuration files
    10.
    发明授权
    System and method for protecting configuration settings in distributed text-based configuration files 有权
    用于保护分布式文本配置文件中配置设置的系统和方法

    公开(公告)号:US07543145B2

    公开(公告)日:2009-06-02

    申请号:US11072733

    申请日:2005-03-03

    摘要: System and methods for protecting sensitive data stored in a text-based configuration file. In a web server application, data associated with sensitive information such as connection information for a remote database may be stored within a configuration file and accessed whenever a request for information from that database is received. To prevent unwanted access to remote database, the portion of the configuration file with sensitive information is encrypted. A decryption provider selected by the requesting server or client application decrypts the sensitive data using the decryption key, retrieves protected data from the remote database, and the configuration server provides a response based on the sensitive data protecting access to the remote database. The encryption/decryption process is transparent to the web server application consuming the configuration.

    摘要翻译: 用于保护存储在基于文本的配置文件中的敏感数据的系统和方法。 在Web服务器应用中,与诸如远程数据库的连接信息的敏感信息相关联的数据可以被存储在配置文件中,并且每当接收到来自该数据库的信息的请求时被访问。 为了防止不必要的访问远程数据库,具有敏感信息的配置文件的部分被加密。 由请求服务器或客户端应用程序选择的解密提供者使用解密密钥解密敏感数据,从远程数据库检索受保护的数据,配置服务器根据保护对远程数据库的访问的敏感数据提供响应。 加密/解密过程对于消耗配置的Web服务器应用程序是透明的。