发明名称 Authentication based on previous authentications
摘要 A method and system for authenticating a user to a target server. A request is received from a user computer system to authenticate the user for access to a target server at level N of N levels (N≧2). Each record of a stored authentication plan associated with the user has authentication records each having expected information relating to authentication of the user for access to the N−1 target servers at respective levels 1 through N−1. Each record of a received current authentication plan for the user has authentication records each having current information relating to authentication of the user for access to the N−1 target servers at respective levels 1 through N−1. It is determined that that there is at least a partial match between the stored and current authentication plans, and in response, the user is authenticated for access to the target server at level N.
申请公布号 US9094393(B2) 申请公布日期 2015.07.28
申请号 US201314076392 申请日期 2013.11.11
申请人 International Business Machines Corporation 发明人 Hamilton, II Rick A.;O'Connell Brian M.;Pavesi John R.;Walker Keith R.
分类号 G06F17/30;H04L29/06;G06F21/41 主分类号 G06F17/30
代理机构 Schmeiser, Olsen & Watts, LLP 代理人 Schmeiser, Olsen & Watts, LLP ;Vallone Mark C.
主权项 1. A method for authenticating a user to a target server, the method comprising: receiving, by a computer system having at least one processor coupled to memory, a request from a user computer system to authenticate the user for access to a target server at level N of N levels, wherein N is a positive integer of at least 2, wherein N target servers are sequentially nested at respective levels of the N levels denoted as levels 1 through N sequenced from lowest level to highest level, and wherein authentication of the user for access to the target server at level N requires prior authentication of the user for access to the target server at level 1 if N is 2 or for access to the N−1 target servers at the respective levels 1 through N−1 if N is at least 3; accessing, by the computer system, a stored authentication plan associated with the user, the stored authentication plan having one or more authentication records each having expected information relating to authentication of the user for access to the N−1 target servers at the respective levels 1 through N−1; receiving, by the computer system, an indication of whether a current authentication plan exists in an authentication store, the current authentication plan having one or more authentication records, each authentication record having current information relating to authentication of the user for access to the N−1 target servers at the respective levels 1 through N−1; in response to having received a determination that the current authentication plan exists, (i) requesting, by the computer system, the current authentication plan and (ii) receiving, by the computer system, the current authentication plan from the authentication store; determining, by the computer system, that there is at least a partial match between the stored authentication plan and the current authentication plan; and authenticating in response to said determining that there is at least the partial match, by the computer system, the user for access to the target server at level N.
地址 Armonk NY US