发明名称 Multi-domain access control
摘要 A multi-domain resource access control mechanism uses a single access control system to manage access by users to resources that belong to multiple domains. A server is associated with each domain in a set of domains. Access to resources in the domains is governed by an access control system. A first server for a first domain transmits a data token to a client seeking access to a resource in a second domain. The client transmits the data token to a second server in the other domain. The second server uses the data token to verify that the user is authentic, that is, authorized to access resources protected by the access control system. Once determining that the user is authorized to access resources, access control cookies are transmitted to client. When the client requests access to a resource in the second domain, and the request did not include access control cookies for the second domain, data is transmitted to the browser causing it to generate another request to the first server. The first server ensures that the user has been authenticated before transmitting the data token to the browser. In addition, the first server may cause copies of access control cookies for the user to be stored for later transmission to the second server.
申请公布号 US6339423(B1) 申请公布日期 2002.01.15
申请号 US20000535080 申请日期 2000.03.23
申请人 ENTRUST, INC. 发明人 SAMPSON LAWRENCE;BELMONTE EMILIO;FANTI MARCO;MEDINA RAUL
分类号 G05B19/042;G06F21/00;H04L9/00;H04L29/06;(IPC1-7):G06F12/00 主分类号 G05B19/042
代理机构 代理人
主权项
地址