US2010031321A1PendingUtilityA1

Method and system for preventing impersonation of computer system user

Assignee: PROTEGRITY CORPPriority: Jun 11, 2007Filed: Apr 2, 2008Published: Feb 4, 2010
Est. expiryJun 11, 2027(~0.9 yrs left)· nominal 20-yr term from priority
Inventors:Ulf Mattsson
G06F 21/31G06F 21/45G06F 16/217
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for preventing an administrator impersonating a user from accessing sensitive resources on a target system is provided. The method comprises receiving a first request from a user to change the user's password on a target system to be changed, sending a “change password” request for the user to the target system, storing the user's new password, receiving a second request from the target system on behalf of the user for access to a sensitive resource, wherein the second request contains information about the user's password, and denying the second request if the information about the user's password is not consistent with the user's stored new password.

Claims

exact text as granted — not AI-modified
1 . A method of changing a user password on a target system, the method comprising:
 receiving a first request from a user to change the user's password on a target system to be changed;   sending a “change password” request for the user to the target system;   storing the user's new password;   receiving a second request from the target system on behalf of the user for access to a sensitive resource, wherein the second request contains information about the user's password; and   denying the second request if the information about the user's password is not consistent with the user's stored new password.   
   
   
       2 . The method according to  claim 1 , the method further comprising:
 authenticating the first user.   
   
   
       3 . The method according to  claim 1 , wherein information about the user's password comprises the user's password in plain text. 
   
   
       4 . The method according to  claim 1 , wherein information about the user's password comprises the user's password in encrypted text. 
   
   
       5 . The method according to  claim 1 , wherein information about the user's password comprises a hash value of the user's password. 
   
   
       6 . The method according to  claim 1 , wherein the sensitive resource is encrypted data. 
   
   
       7 . The method according to  claim 1 , wherein the target system is a database. 
   
   
       8 . The method according to  claim 1 , wherein the target system is a file system. 
   
   
       9 . The method according to  claim 1 , wherein the target system is an application. 
   
   
       10 . The method according to  claim 1 , wherein the target system is a network. 
   
   
       11 . The method according to  claim 1 , wherein the target system is a data at rest system. 
   
   
       12 . A computer-readable medium whose contents cause a computer to perform a method of changing a user password on a target system by the steps of:
 receiving a first request from a user to change the user's password on a target system to be changed;   sending a “change password” request for the user to the target system;   storing the user's new password;   receiving a second request from the target system on behalf of the user for access to a sensitive resource, wherein the second request contains information about the user's password; and   denying the second request if the information about the user's password is not consistent with the user's stored new password.   
   
   
       13 . A system for preventing an administrator from impersonating a user of a target system, the system comprising:
 an access control system comprising a computer readable medium comprising instructions to execute the method of  claim 1 ; and   the target system comprising sensitive data, wherein user requests to the target system for sensitive resources are sent to the access control system for authentication.

Join the waitlist — get patent alerts

Track US2010031321A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.