发明名称 Consolidated authentication
摘要 A method and system for authenticating a user at a first computer to first and second applications installed in a second computer. The second computer receives from the user a first request to access the first application, and in response, the second computer redirects the first request to a third computer, and in response, the third computer determines that the user was previously authenticated and so notifies the second computer, and in response, the second computer returns a first session key to the third computer. The first session key enables a session with the first application but not with the second application. The second computer receives from the user a second request with a second session key to access the first and/or second application, and in response the second computer determines that the user is authentic and notifying the first and/or second application that the user is authentic.
申请公布号 US9319399(B2) 申请公布日期 2016.04.19
申请号 US201414505520 申请日期 2014.10.03
申请人 International Business Machines Corporation 发明人 Doleh Yaser K.;Kalamaras Christopher G.;Marzorati Mauro
分类号 H04L29/06;G06F21/33;G06F21/41 主分类号 H04L29/06
代理机构 Schmeiser, Olsen & Watts, LLP 代理人 Schmeiser, Olsen & Watts, LLP ;Quinn David M.
主权项 1. A method for authenticating a user at a first computer to first and second applications installed in a second computer, the method comprising: said second computer receiving from the user a first request to access the first application, and in response, the second computer redirecting the first request to a third computer, and in response, the third computer determining that the user was previously authenticated and notifying the second computer that the user is authentic, and in response, the second computer returning a first session key to the third computer, said first session key enabling a session with the first application but not with the second application, said first, second, and third computers being three different computers, said first and second applications installed in the second computer being different applications; and said second computer receiving from the user a second request with a second session key to access the first application, the second application, or both the first application and the second application, and in response the second computer determining that the user is authentic and notifying the first application, the second application, or both the first application and the second application that the user is authentic so that the first application, the second application, or both the first application and the second application can send, to the first computer, a response to the second request, wherein the second session key was generated by the third computer, and sent by the third computer to the first computer, prior to the second computer having received the second request and in response to the third computer having received the first session key, and wherein the second session key enables a session with both the first application and the second application.
地址 Armonk NY US