发明名称 Method and apparatus for controlling server access to a resource in a client/server system
摘要 In a client/server system, a method and apparatus for handing requests for access to a host resource purportedly on behalf of a client from an untrusted application server that may be capable of operating as a "rogue" server. Upon receiving a service request from a client, an untrusted application server creates a new thread within its address space for the client and obtains from the security server a client security context, which is anchored to the task control block (TCB) for that thread. The client security context specifies the client and indicates whether the client is an authenticated client or an unauthenticated client. When the application server makes a request for access to a host resource purportedly on behalf of the client, the security server examines the security context created for the requesting thread. If the client security context indicates that the client is an authenticated client, the security server grants access to the host resource if the client specified in the client security context is authorized to make the requested access to the host resource. If the client security context indicates that the client is an authenticated client, the security server grants access to the host resource only if both the client specified in the client security context and the application server are authorized to make the requested access to the host resource.
申请公布号 US6377994(B1) 申请公布日期 2002.04.23
申请号 US19960632251 申请日期 1996.04.15
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 AULT DONALD FRED;DAYKA JOHN CARR;FINKELSTEIN ERIC CHARLES;GUSKI RICHARD HENRY
分类号 H04L29/06;(IPC1-7):G06F15/16 主分类号 H04L29/06
代理机构 代理人
主权项
地址