发明名称 Method and system for network single sign-on using a public key certificate and an associated attribute certificate
摘要 A methodology is presented for a network single sign-on (SSO) authentication process using digital certificates. A user has access to protected resources, such as legacy applications, that require verification of a user's authentication data prior to providing access. The user's authentication data is encrypted using the public key of the user, and an attribute certificate containing the encrypted authentication data is generated by an attribute-certificate-issuing authority. When a user requires access to the protected resource, an SSO agent performs an initial authentication process against the user. The SSO agent then retrieves the user's attribute certificate, and for subsequent authentication requests for other protected resources, the SSO agent uses the authentication data from the attribute certificate that corresponds to the targeted protected resource. The SSO agent forwards the required authentication data to the protected resource, and the protected resource then authenticates a user based on the provided authentication data.
申请公布号 US2002144119(A1) 申请公布日期 2002.10.03
申请号 US20010821064 申请日期 2001.03.29
申请人 IBM CORPORATION 发明人 BENANTAR MESSAOUD
分类号 G06F21/00;H04L9/32;(IPC1-7):H04L9/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址