发明名称 Authenticating user access to a network server without communicating user authentication cookie to the network server
摘要 A system determines whether to grants access to a network server by a user. Initially, a user attempts to gain access to a network server, such as a web server. Prior to granting access to the network server, the network server authenticates the user by sending an authentication request to an authentication server. The authentication server determines whether the user was already authenticated by the authentication server. If the user was already authenticated by the authentication server, then the network server is notified that the user is authenticated. The network server then grants the user access to the network server. If the user was not already authenticated by the authentication server, then login information is retrieved from the user and compared to authentication information maintained by the authentication server. If the retrieved login information matches the authentication information, then the network server is notified that the user is authenticated. The retrieved login information and the authentication information is concealed from the network server. If the user is authenticated, then a user profile is communicated to the network server along with the notification that the user is authenticated. If the user is successfully authenticated, then a cookie is provided to an Internet browser operated by the user. The cookie contains information regarding user authentication, the user's profile, and a list of network servers previously visited by the user.
申请公布号 US7016960(B2) 申请公布日期 2006.03.21
申请号 US20030427080 申请日期 2003.04.30
申请人 MICROSOFT CORPORATION 发明人 HOWARD JOHN HAL;KUNINS JEFFREY C.;ANDERSON DARREN L.;BATTLE RYAN W.;METRAL MAX E.
分类号 G06F15/173;G06F21/00;H04L29/06 主分类号 G06F15/173
代理机构 代理人
主权项
地址