发明名称 User and device authentication in enterprise systems
摘要 Methods and systems for authenticating users of client devices to allow access of resources and services in enterprise systems are described herein. An authentication device may validate a user based on authentication credentials received from a client device. Validation data stored by the authentication device, and a corresponding access token transmitted to the client device, may be used to authenticate the user for future resource access requests. A user secret also may be stored by the authentication device and used to validate the user for future resource access requests. Additionally, after validating a user with a first set of authentication credentials, additional sets of credentials for the user may be retrieved and stored at an access gateway for future requests to access other services or resources in an enterprise system.
申请公布号 US9098687(B2) 申请公布日期 2015.08.04
申请号 US201313886518 申请日期 2013.05.03
申请人 Citrix Systems, Inc. 发明人 Hayton Richard
分类号 G06F21/00;G06F21/31;G06F21/32;G06F21/41;H04L29/06 主分类号 G06F21/00
代理机构 Banner & Witcoff, Ltd. 代理人 Banner & Witcoff, Ltd.
主权项 1. A method, comprising: receiving, by an authentication computing system and from a client device, authentication credentials, received by the client device from a user, for a secure resource associated with the authentication computing system; receiving, by the authentication computing system and from the client device, a reusable user secret, received by the client device from the user via a prompt generated by the client device in response to the client device receiving the authentication credentials, for the authentication computing system, the reusable user secret being different from the authentication credentials; encrypting, by the authentication computing system and using a cryptographic key, first validation data comprising the authentication credentials and the reusable user secret; transmitting, by the authentication computing system and to the client device, the cryptographic key; receiving, by the authentication computing system and from the client device: a request to access the secure resource; data comprising the cryptographic key; and authentication data received by the client device from the user; and responsive to determining by the authentication computing system that the authentication data corresponds to a portion of the validation data, decrypted by the authentication computing system using the data comprising the cryptographic key, comprising the reusable user secret, authenticating, by the authentication computing system, the request using a portion of the validation data, decrypted by the authentication computing system using the data comprising the cryptographic key, comprising the authentication credentials.
地址 Fort Lauderdale FL US