发明名称 METHOD AND SYSTEM FOR AUTHENTICATING USERS
摘要 <p>A method and apparatus for authenticating users. Prior art mechanisms require each individual application (running on an "application server") that the user is accessing to provide for the ability to use the various authentication mechanisms. One or more embodiments of the invention externalize the authentication mechanism from the application in the form of a login server. Only the login server needs to be configured to handle authentication mechanisms. The application server checks if a request has an active and valid session (e.g., a valid session may exist when there is active communication between a client and server that has not expired). If there is not a valid session, the application server redirects the user to the login server. The login server attempts to authenticate the user using any desired authentication mechanism. Once authenticated, the login server redirects the user back to the application server. The application server verifies the authentication directly with the login server. Once verified, the application server processes the user's request and responds accordingly. One or more embodiments of the invention may utilize cookies to aid in the authentication process. Thus, applications on the application server need not be concerned about authenticating a given user. The application server merely knows how to work with the login server to authenticate the user. Further, communications between the application server and login server are transparent (or without any interaction from) the user (although the user may see the browser communicating with each server).</p>
申请公布号 EP1177654(B1) 申请公布日期 2012.06.20
申请号 EP20000932080 申请日期 2000.05.04
申请人 ORACLE AMERICA, INC. 发明人 GUPTA, ABHAY;FERRIS, CHRIS;ABDELNUR, ALEJANDRO
分类号 H04L29/06;G06F1/00;G06F21/00;H04L9/32;H04L29/08 主分类号 H04L29/06
代理机构 代理人
主权项
地址