The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 12, 2016

Filed:

Sep. 13, 2014
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

John Y-C. Chang, Austin, TX (US);

Ching-Yun CHao, Austin, TX (US);

Bertrand Be-Chung Chiu, Austin, TX (US);

Ki Hong Park, Research Triangle Park, NC (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/32 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
H04L 9/3247 (2013.01); H04L 9/3213 (2013.01); H04L 63/0815 (2013.01); H04L 63/0823 (2013.01); H04L 63/08 (2013.01);
Abstract

Exposure of sensitive information to users is controlled using a first security token containing user identity and user credentials to represent the user who requests services, and a second security token containing two other identities, one identifying the token issuer and the other identifying the owning process. When requesting services, the token-owning process sends a security token to indicate who is making the request, and uses its key to digitally sign the request. The token-owning process signs the request to indicate that it endorses the request. A receiving server accepts a request if (1) the token-owning process endorses the request by signing the request; (2) the token is valid (token is signed by its issuer and the digital signature is verified and unexpired); (3) user entity, which can be a real user or a deployment or a server process, that is represented by the token has the authorization to access the specified resources; and (4) the token-owning process is authorized to endorse the user entity represented by the token to access the specified resources.


Find Patent Forward Citations

Loading…