CA2400623C - Mecanisme d'authentification base sur le web et possedant une procedure d'ouverture unique - Google Patents

Mecanisme d'authentification base sur le web et possedant une procedure d'ouverture unique Download PDF

Info

Publication number
CA2400623C
CA2400623C CA002400623A CA2400623A CA2400623C CA 2400623 C CA2400623 C CA 2400623C CA 002400623 A CA002400623 A CA 002400623A CA 2400623 A CA2400623 A CA 2400623A CA 2400623 C CA2400623 C CA 2400623C
Authority
CA
Canada
Prior art keywords
user
service
token
gateway
connection
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CA002400623A
Other languages
English (en)
Other versions
CA2400623A1 (fr
Inventor
Igor Balabine
Partha P. Dutta
Mahesh M. Kumar
Alex Tselovalnikov
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
AT&T Corp
Original Assignee
AT&T Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by AT&T Corp filed Critical AT&T Corp
Publication of CA2400623A1 publication Critical patent/CA2400623A1/fr
Application granted granted Critical
Publication of CA2400623C publication Critical patent/CA2400623C/fr
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0815Network architectures or network communication protocols for network security for authentication of entities providing single-sign-on or federations

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer And Data Communications (AREA)
  • Telephonic Communication Services (AREA)
  • Information Transfer Between Computers (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

L'invention concerne un procédé et un dispositif comportant une procédure d'ouverture unique afin d'accéder à une pluralité de services distribués sur un réseau dans lequel la fonctionnalité relative à l'authentification est séparée des services et dans lequel l'authentification n'a pas besoin d'être renégociée pour accéder à un nouveau service parmi la pluralité de services pendant une session. D'autres avantages de l'invention consistent en la notification de la pluralité de services quand l'utilisateur a terminé une session et en l'utilisation de jetons d'authentification courts et sécurisés servant à vérifier l'identité de l'utilisateur pour un accès ultérieur à la pluralité de services. Ce procédé consiste à recevoir une demande d'un utilisateur d'autorisation d'accès à un service; à transmettre un jeton à l'utilisateur correspondant à ce service; à recevoir le jeton correspondant au service par l'utilisateur; à déterminer si l'utilisateur est autorisé à recevoir le service basé sur le jeton; et à mettre en contact l'utilisateur avec le service si cet utilisateur est autorisé à utiliser ce service.
CA002400623A 2000-03-17 2001-03-07 Mecanisme d'authentification base sur le web et possedant une procedure d'ouverture unique Expired - Fee Related CA2400623C (fr)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US52818900A 2000-03-17 2000-03-17
US09/528,189 2000-03-17
PCT/US2001/007282 WO2001072009A2 (fr) 2000-03-17 2001-03-07 Mecanisme d'authentification base sur le web et possedant une procedure d'ouverture unique

Publications (2)

Publication Number Publication Date
CA2400623A1 CA2400623A1 (fr) 2001-09-27
CA2400623C true CA2400623C (fr) 2007-03-20

Family

ID=24104602

Family Applications (1)

Application Number Title Priority Date Filing Date
CA002400623A Expired - Fee Related CA2400623C (fr) 2000-03-17 2001-03-07 Mecanisme d'authentification base sur le web et possedant une procedure d'ouverture unique

Country Status (3)

Country Link
EP (1) EP1264463A2 (fr)
CA (1) CA2400623C (fr)
WO (1) WO2001072009A2 (fr)

Families Citing this family (41)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FR2821685A1 (fr) * 2001-03-01 2002-09-06 Couponet S A Systeme d'echange d'informations entre des ordinateurs par l'intermediaire d'un reseau
US7590859B2 (en) 2001-08-24 2009-09-15 Secure Computing Corporation System and method for accomplishing two-factor user authentication using the internet
US20030084302A1 (en) * 2001-10-29 2003-05-01 Sun Microsystems, Inc., A Delaware Corporation Portability and privacy with data communications network browsing
US7100197B2 (en) * 2001-12-10 2006-08-29 Electronic Data Systems Corporation Network user authentication system and method
DE10392283T5 (de) * 2002-02-28 2005-04-14 Telefonaktiebolaget Lm Ericsson System, Verfahren und Vorrichtung für verbündete einzelne Dienstleistungen mit Anmeldeverfahren beziehungsweise Sign-On-Dienstleistungen
US7221935B2 (en) * 2002-02-28 2007-05-22 Telefonaktiebolaget Lm Ericsson (Publ) System, method and apparatus for federated single sign-on services
NO318842B1 (no) * 2002-03-18 2005-05-09 Telenor Asa Autentisering og tilgangskontroll
US7360096B2 (en) * 2002-11-20 2008-04-15 Microsoft Corporation Securely processing client credentials used for Web-based access to resources
ES2281599T3 (es) * 2003-06-26 2007-10-01 Telefonaktiebolaget Lm Ericsson (Publ) Aparato y metodo para la autentificacion de identificacion unica a traves de una red de acceso no confiable.
CN100461780C (zh) * 2003-07-17 2009-02-11 华为技术有限公司 一种基于媒体网关控制协议的安全认证方法
JP2008506139A (ja) * 2004-07-09 2008-02-28 松下電器産業株式会社 ユーザ認証及びサービス承認を管理し、シングル・サイン・オンを実現して、複数のネットワーク・インタフェースにアクセスするためのシステム及び方法
KR100813791B1 (ko) * 2004-09-30 2008-03-13 주식회사 케이티 유무선 통합서비스 망에서의 개인 이동성을 위한 통합인증 처리 장치 및 그 방법
GB0423301D0 (en) 2004-10-20 2004-11-24 Fujitsu Ltd User authorization for services in a wireless communications network
US7954141B2 (en) 2004-10-26 2011-05-31 Telecom Italia S.P.A. Method and system for transparently authenticating a mobile user to access web services
US7748046B2 (en) 2005-04-29 2010-06-29 Microsoft Corporation Security claim transformation with intermediate claims
US7690026B2 (en) 2005-08-22 2010-03-30 Microsoft Corporation Distributed single sign-on service
GB0523871D0 (en) * 2005-11-24 2006-01-04 Ibm A system for updating security data
US8458775B2 (en) 2006-08-11 2013-06-04 Microsoft Corporation Multiuser web service sign-in client side components
US7856104B2 (en) 2007-02-05 2010-12-21 Sony Corporation System and method for ensuring secure communication between TV and set back box
US8539559B2 (en) 2006-11-27 2013-09-17 Futurewei Technologies, Inc. System for using an authorization token to separate authentication and authorization services
GB2445172A (en) * 2006-12-29 2008-07-02 Symbian Software Ltd Use of an interaction object in transactions
US8099597B2 (en) 2007-01-09 2012-01-17 Futurewei Technologies, Inc. Service authorization for distributed authentication and authorization servers
US8429713B2 (en) 2007-04-02 2013-04-23 Sony Corporation Method and apparatus to speed transmission of CEC commands
US8510798B2 (en) 2007-04-02 2013-08-13 Sony Corporation Authentication in an audio/visual system having multiple signaling paths
US8285990B2 (en) 2007-05-14 2012-10-09 Future Wei Technologies, Inc. Method and system for authentication confirmation using extensible authentication protocol
RU2393541C2 (ru) * 2008-06-30 2010-06-27 Валерий Иванович Стародубцев Система заказов и продажи товаров и услуг (варианты), способ предложения к продаже и оформления заказов, способ продажи товаров и услуг
US8806201B2 (en) * 2008-07-24 2014-08-12 Zscaler, Inc. HTTP authentication and authorization management
US8151333B2 (en) 2008-11-24 2012-04-03 Microsoft Corporation Distributed single sign on technologies including privacy protection and proactive updating
US8924569B2 (en) 2009-12-17 2014-12-30 Intel Corporation Cloud federation as a service
WO2011078723A1 (fr) * 2009-12-25 2011-06-30 Starodubtsev Valeriy Ivanovich Système de commande et d'achat de produits et de services (variantes), procédé de mise à la vente et de passage de commande, et procédé de vente de produits et de services
US9081951B2 (en) * 2011-09-29 2015-07-14 Oracle International Corporation Mobile application, identity interface
JP5485246B2 (ja) * 2011-11-05 2014-05-07 京セラドキュメントソリューションズ株式会社 画像形成装置
US8769651B2 (en) * 2012-09-19 2014-07-01 Secureauth Corporation Mobile multifactor single-sign-on authentication
US9479490B2 (en) 2013-06-07 2016-10-25 Apple Inc. Methods and systems for single sign-on while protecting user privacy
US10237732B2 (en) 2013-06-12 2019-03-19 Telecom Italia S.P.A. Mobile device authentication in heterogeneous communication networks scenario
US10129243B2 (en) 2013-12-27 2018-11-13 Avaya Inc. Controlling access to traversal using relays around network address translation (TURN) servers using trusted single-use credentials
US9769668B1 (en) 2016-08-01 2017-09-19 At&T Intellectual Property I, L.P. System and method for common authentication across subscribed services
CN113439427B (zh) * 2019-07-24 2023-10-27 Oppo广东移动通信有限公司 一种资源发布方法和设备
CN111917732B (zh) * 2020-07-10 2022-04-26 杭州海康威视数字技术股份有限公司 一种大数据组件的访问方法、装置、系统及电子设备
CN115051809A (zh) * 2022-06-15 2022-09-13 道和邦(广州)电子信息科技有限公司 SMG-wscomm-Msession-ECToken一种基于加密CookieToken免登录认证动态令牌技术
US12526268B2 (en) 2023-08-24 2026-01-13 Lumenore Inc. Single sign-on (SSO) authentication system for enabling digital communication between multiple entities

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5684950A (en) * 1996-09-23 1997-11-04 Lockheed Martin Corporation Method and system for authenticating users to multiple computer servers via a single sign-on
US6000033A (en) * 1997-11-26 1999-12-07 International Business Machines Corporation Password control via the web

Also Published As

Publication number Publication date
WO2001072009A3 (fr) 2002-04-11
WO2001072009A2 (fr) 2001-09-27
EP1264463A2 (fr) 2002-12-11
CA2400623A1 (fr) 2001-09-27

Similar Documents

Publication Publication Date Title
CA2400623C (fr) Mecanisme d'authentification base sur le web et possedant une procedure d'ouverture unique
US7100054B2 (en) Computer network security system
US7197568B2 (en) Secure cache of web session information using web browser cookies
US7313816B2 (en) Method and system for authenticating a user in a web-based environment
EP1766840B1 (fr) Authentification graduee dans un systeme de gestion d'identites
JP5926441B2 (ja) マルチパーティシステムにおける安全な認証
US9998448B2 (en) Delegating authorizations
US8219808B2 (en) Session-based public key infrastructure
JP4867663B2 (ja) ネットワーク通信システム
US6993652B2 (en) Method and system for providing client privacy when requesting content from a public server
US20170244696A1 (en) Delegating authorizations
EP0940960A1 (fr) Authentification entre serveurs
US20030097592A1 (en) Mechanism supporting wired and wireless methods for client and server side authentication
JP5602165B2 (ja) ネットワーク通信を保護する方法および装置
KR20070083965A (ko) 멀티미디어 멀티캐스팅 인증 방법 및 시스템
WO2002093377A1 (fr) Procede et appareil pour desservir un contenu depuis un serveur semi-securise
EP3788758B1 (fr) Procédé et système pour autoriser une connexion sécurisée via un dispositif mobile
JP2001186122A (ja) 認証システム及び認証方法
Oppliger Microsoft. net passport and identity management
US20070118886A1 (en) Updating security data
CN117354032A (zh) 一种基于代码服务器的多重认证方法
KR100366403B1 (ko) 인터넷 환경에서의 사용자 인증방법 및 이를 위한 시스템
CN121690868A (zh) 基于RADIUS认证的Websocket通信管理方法、平台及系统
AU2004229654A1 (en) Apparatus, system and method for facilitating authenticated communication between authentication realms

Legal Events

Date Code Title Description
EEER Examination request
MKLA Lapsed