US2008178274A1PendingUtilityA1

System for using an authorization token to separate authentication and authorization services

Assignee: FUTUREWEI TECHNOLOGIES INCPriority: Nov 27, 2006Filed: Nov 9, 2007Published: Jul 24, 2008
Est. expiryNov 27, 2026(~0.3 yrs left)· nominal 20-yr term from priority
H04L 9/321H04L 63/0807H04L 63/0892H04L 63/06H04L 9/3242
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A novel system for utilizing an authorization token to separate authentication and authorization services. The system authenticates a client to an authenticating server; generates an authorization token with the authenticating server and the client; and authorizes services for the client using the generated authorization token. The authorization token may be transferred via a third party, or may be utilized to extend an initial session without re-authentication.

Claims

exact text as granted — not AI-modified
1 . A method of separating authentication and authorization services in a communications system, comprising the steps of:
 authenticating a client node to an authenticating server utilizing extensible authentication protocol;   generating an authorization token; and   authorizing services rendered to the client node via an authorizing server, based upon information in the authorization token.   
     
     
         2 . The method of  claim 1 , further comprising distributing the authorization token by which a client is capable of signing its service requests to an authorization server. 
     
     
         3 . The method of  claim 2 , wherein the client, following a successful authentication, signs service authorization requests towards the authorizing server. 
     
     
         4 . The method of  claim 2 , wherein the authorizing server authorizes the client service request, based upon the existence of the client signature, free from the authorizing server authenticating client identity. 
     
     
         5 . The method of  claim 4 , wherein the authorizing server authorizes a client service request for fulfillment by a continued service server. 
     
     
         6 . The method of  claim 4 , wherein the authorizing server authorizes a client service request for fulfillment by a third party server. 
     
     
         7 . A method by which a Handover Keying authorization request for a client, and authentication of the client, comprising the steps of:
 authenticating a client node to an authenticating server utilizing extensible authentication protocol;   generating an authorization token; and   authorizing services rendered to the client node via an authorizing server, based upon information in the authorization token.   
     
     
         8 . The method of  claim 7 , wherein the authorizing server is different from the authenticating AAA server, in at least one logical or physical aspect. 
     
     
         9 . The method of  claim 7 , further comprising distributing the authorization token by which a client is capable of signing its service requests to an authorizing server. 
     
     
         10 . The method of  claim 7 , wherein the client, following a successful authentication, signs service authorization requests towards the authorizing server. 
     
     
         11 . The method of  claim 7 , wherein the authorizing server authorizes the client service request, based upon the existence of the client signature, free from the authorizing server authenticating client identity. 
     
     
         12 . The method of  claim 11 , wherein the authorizing server authorizes a client service request for fulfillment by a continued service server. 
     
     
         13 . The method of  claim 11 , wherein the authorizing server authorizes a client service request for fulfillment by a third party server. 
     
     
         14 . The method of  claim 7 , wherein the authorization token is derived from an extensible authentication protocol master session key. 
     
     
         15 . The method of  claim 7 , wherein the authorization token comprises a shared secret authentication key between the authorizing server and the client node. 
     
     
         16 . The method of  claim 14 , wherein the extensible authentication protocol master session key is generated after successful extensible authentication protocol authentication. 
     
     
         17 . The method of  claim 14 , wherein the authorization token is delivered from the authentication server to the authorization server. 
     
     
         18 . The method of  claim 14 , wherein the authorization token is encrypted for delivery to the authorization server. 
     
     
         19 . A communications system comprising:
 an authenticating network component;   an authorizing network component; and   a client network component, adapted to:
 exchange authentication messages with the authenticating network component utilizing extensible authentication protocol; 
 generate an authorization token; and 
 transfer the authorization token to the authorizing server to request a service. 
   
     
     
         20 . The system of  claim 19 , wherein the service is Handover Keying service. 
     
     
         21 . A client network device for use in a communications system, comprising:
 a first component adapted to exchange authentication messages with an authenticating network component, utilizing extensible authentication protocol;   a second component adapted to generate an authorization token; and   a third component adapted to transfer the authorization token to the authorizing server to request a service.   
     
     
         22 . The device of  claim 21 , wherein the service is Handover Keying service. 
     
     
         23 . An authenticating network device for use in a communications system, comprising:
 a first component adapted to receive authentication messages from a client network device, utilizing extensible authentication protocol;   a second component adapted to generate an authorization token;   a third component adapted to receive a service authentication message from a network service device; and   a fourth component adapted to authenticate the service authentication message utilizing the authorization token.   
     
     
         24 . The device of  claim 23 , wherein the service authentication message is for Handover Keying service.

Join the waitlist — get patent alerts

Track US2008178274A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.