发明名称 |
System and method for credential delegation using identity assertion |
摘要 |
Run-as credentials delegation using identity assertion is presented. A server receives a request from a client that includes the client's user identifier and password. The server authenticates the client and stores the client's user identifier without the corresponding password in a client credential storage area. The server determines if a run-as command is specified to communicate with a downstream server. If a run-as command is specified, the server retrieves a corresponding run-as identity which identifies whether a client credential type, a server credential type, or a specific identifier credential type should be used in the run-as command. The server retrieves an identified credential corresponding to the identified credential type, and sends the identified credential in an identity assertion token to a downstream server.
|
申请公布号 |
US7526798(B2) |
申请公布日期 |
2009.04.28 |
申请号 |
US20020286609 |
申请日期 |
2002.10.31 |
申请人 |
INTERNATIONAL BUSINESS MACHINES CORPORATION |
发明人 |
CHAO CHING-YUN;CHUNG HYEN VUI;REDDY AJAY;VENKATARAMAPPA VISHWANATH |
分类号 |
H04L9/00;G06F9/44;G06F17/00;H04K1/00;H04L9/32;H04L29/06 |
主分类号 |
H04L9/00 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|