发明名称 METHOD AND SYSTEM FOR PROVIDING ACCESS TO ENCRYPTED DATA FILES FOR MULTIPLE FEDERATED AUTHENTICATION PROVIDERS AND VERIFIED IDENTITIES
摘要 The embodiments herein disclose a method and system for providing access to an encrypted data tile by separating the concerns of Authentication, Identity Resolution and Authorization from Encryption thereby allowing for multiple federated authentication providers and verified identities. The method comprises of creating an encrypted data file, embedding a file usage policy to the data file, sharing the encrypted data file with an identity of an intended content recipient and an allowed authentication provider specified in the file usage policy, activating a client application installed in a user device to open the encrypted data file, fetching and updating the data file usage policy from an application server, prompting the user to authenticate with the allowed authentication provider, authenticating the user with a specified authentication provider, verifying if the authenticated user is allowed to open the data file, opening the data file on successful verification and enforcing the file usage policy.
申请公布号 US2015067802(A1) 申请公布日期 2015.03.05
申请号 US201314010726 申请日期 2013.08.27
申请人 BASKARAN PRAKASH 发明人 BASKARAN PRAKASH
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method of providing access to an encrypted data file, the method comprises: creating the encrypted data file by at least one of a content generation system or a content owner; embedding a file usage policy to the data file; sharing the encrypted data file with at least one identity of an intended content recipient and an allowed authentication provider specified in the file usage policy; activating a client application installed in a user device to open the encrypted data file; fetching and updating the data file usage policy from an application server by a client application; prompting the user to authenticate with at least one of the allowed authentication provider; authenticating the user with a specified authentication provider; verifying if the authenticated user is allowed to open the data file in an identity resolution server; opening the data file on successful user verification; and enforcing the file usage policy;wherein the method herein separates concerns of Authentication, Identity Resolution and Authorization from Encryption thereby allowing for a plurality of federated authentication providers and a plurality of verified identities.
地址 ASHBURN VA US