US2012185920A1PendingUtilityA1

Serialized authentication and authorization services

Assignee: ZMENER SEBASTIAN MATIASPriority: Jan 13, 2011Filed: Jan 13, 2011Published: Jul 19, 2012
Est. expiryJan 13, 2031(~4.5 yrs left)· nominal 20-yr term from priority
H04L 63/0892H04L 63/08H04L 63/083H04L 63/20H04L 63/101
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Requests for User Services on networked computers running on different platforms with different Authentication, Authorization and Auditing (AAA) Security Systems are processed through an AAA Services Manager Server and Web Services Servers. The AAA Services Manager Server communicates requests for User Services to Web Services Servers using corresponding URL Web addresses. Web Services correspond to their respective Authentication Security Systems and Authorization Security Systems through which User Services may be obtained. The Web Services Servers act to access, for User validation, the respective Authentication Security Systems and Authorization Security Systems according to their individual languages and computing platform requirements.

Claims

exact text as granted — not AI-modified
1 . A method of authenticating and authorizing access to Applications in different systems on networked server computers, comprising:
 providing user credentials for User access to an Application and an Application name;   providing an authentication list of authentication Services in the order in which they are to be called for authentication;   creating an authentication Web address list of Web addresses corresponding to each authentication Service on the authentication list in the same order as the authentication list; and   sequentially sending for authentication the credentials to each of the Web addresses on said authentication Web address list in the order in which they are listed to initiate interfacing access with respective user authentication Security Systems until the User credentials are accepted by an authentication Security System, the User credentials are recognized but found ineligible for present authentication or the authentication Web access list is completed to thereby complete the authentication process.   
     
     
         2 . The method as set forth in  claim 1  including the steps of:
 providing an authorization list of the user authorization Services in the order in which they will be called for authorization; 
 creating an authorization Web address list of the Web addresses corresponding to each of the authorization Services on the authorization list in the same order as the authorization list; and 
 upon completion of the authentication process step, sequentially sending for authentication the credentials and Application name to each of the Web addresses on the authorization Web address list in the order in which they are listed to initiate interfacing access with respective authorization Security System until the User credentials and Application name are accepted for access by an authorization Security System, access is denied or invalid, or the authorization Web address list is completed. 
 
     
     
         3 . The method as set forth in  claim 2  wherein the User credentials and Application name are communicated to the Web addresses of the authentication Web address list and the Web addresses of the authorization Web address list, to initiate when called interfacing with the programming language used by the respective authentication Security System and authorization Security System. 
     
     
         4 . The method as set forth in  claim 3  wherein the authentication list and the authorization list are created by user input terminals and the authentication Web address list and authorization Web address list are created by an authentication and authorization Services Manager Server from the authentication list and authorization list as received from the input terminals. 
     
     
         5 . The method as set forth in  claim 4  wherein entries on the authentication list and authorization list may vary from 1 to N in number, where N is any number. 
     
     
         6 . A system for authenticating and authorizing access to different user Applications on networked server computers, comprising:
 client devices for initiating access to an Application on networked server computers hosting a plurality of available user Applications, accessible through validation with different user authentication Systems and different user authorization Systems, by using Application name, username and password;   Web authentication and authorization Services servers having access to different user authentication Security Systems and different authorization Security Systems and with the Web authentication and authorization Services server arranged to initiate access to the different Security Systems when called by interfacing with the different authentication Security Systems and different authorization Security Systems according to the respective programming language employed by each of the respective authentication Security Systems and authorization Security Systems in response to a request for User access; and   an authentication and authorization Services Manager server arranged to process a username, password, Application name, a predefined authentication list of authentication Services and a predefined authorization list of authorization Services for User access to the networked server computers and translate the authentication list of authentication Services and the authorization list of authorization Services into a corresponding authentication Web address list and a corresponding authorization Web address list in the same order as the authentication list and authorization list with each list providing the sequential order in which the list entries will be called to initiate access to the different Security Systems, initially from the authentication Web address list for authentication with the username and password, and in response to receipt of return message from user authentication Services, as called from the authorization list for authorization with username and Application name.   
     
     
         7 . The system as set forth in  claim 1  wherein the entries on said authentication list and authorization list may vary in number from 1 to N, where N is any number. 
     
     
         8 . The system as set forth in  claim 6  wherein said client devices provide the predefined authentication list and the predefined authorization list with each list arranged in a sequence in the order in which they are to be called by the Web authentication and authorization Services Manager server. 
     
     
         9 . The system as set forth in  claim 8  wherein the authentication and authorization Services Manager server responds to an Application name to provide the predetermined authentication list and the predetermined authorization list with each list arranged in a sequence in the order in which they are to be called. 
     
     
         10 . The system as set forth in  claim 6  wherein the Web authentication and authorization Services receive results from the authentication Security Systems and authorization Security Systems as they are called from the authentication Web address list and authorization Web address list and creates standard coded responses to send to the authentication and authorization Services Manager server indicative of the type of response received. 
     
     
         11 . The system as set forth in  claim 10  wherein when a standard coded response sent to the authentication and authorization Services Manager server from the Web authentication and authorization Services indicates a negative response so that the User can not have access, the authentication and authorization Services Manager server acts to call the next Web address on the Web address list. 
     
     
         12 . The system as set forth in  claim 11  wherein when the standard coded response sent to the authentication and authorization Services Manager server from the Web authentication and authorization Services indicates a positive response so that the User may have access but cannot access now, a response is sent by the authentication and authorization Services Manager server and the process ends. 
     
     
         13 . The system as set forth in  claim 12  wherein when the standard coded response sent to the authentication and authorization Services Manager server from the Web authentication and authorization Services include a standard neutral response that indicates success, the authentication and authorization Services Manager server begins calling the authorization Web address list when in authentication phase, or returns the success code and message to the Application when in authorization phase. 
     
     
         14 . A method for authenticating and authorizing access to Applications in different user systems on networked server computers, comprising:
 receiving a username, password and an Application name;   providing a predefined authentication list of authentication Services in the order in which they are to be called for authentication;   providing a predefined authorization list of the user authorization Services in the order in which they will be called for authorization;   creating an authentication Web address list of the Web addresses corresponding to each authentication Service on the authentication list in the same order as the authentication list;   creating an authorization Web address list of the Web addresses corresponding to each of the authorization Services on the authorization list;   sequentially sending the username and password to each of the Web addresses on said authentication Web address list in the order in which they are listed to initiate interfacing each access until a username is accepted by an authentication System, the authentication list is completed or the User password is recognized but found invalid, expired, locked or otherwise ineligible for present authentication; and   when a password is accepted by an authentication System, sequentially sending the username and Application name to each of the Web addresses on the authorization Web address list in the order in which they are listed to initiate interfacing each access until the username and Application are accepted for access by an authorization System, the username and Application are found in an entry but the access is denied, expired, pending approval or other status that differs from granting access, or the authorization list is completed.   
     
     
         15 . The method as set forth in  claim 14  wherein the responses from the authentication Systems and authorization Systems are translated into a standard code response. 
     
     
         16 . A computer program product for authenticating and authorizing access to Applications in different user systems on networked server computers, comprising:
 a computer usable medium having computer usable program code embodied therewith, the computer usable program code comprising:   computer usable program code configured to process username, password, an Application name, an authentication list with the names of authentication Services and an authorization list with names of authorization Services;   computer readable program code configured to create an authentication Web address list of the Web addresses corresponding to each user authentication Service on the authentication list in the same order as the authentication list;   computer readable program code configured to create an authorization Web address list of the Web addresses corresponding to each of the user authorization Services on the authorization list;   computer readable program code configured to sequentially send the username and password to each of the Web addresses on the authentication Web address list in the order in which they are listed to initiate interfacing User access until a username and password are accepted by an authentication Security System, the authentication list is completed or the User password is recognized but found invalid, expired, locked or otherwise ineligible for present authentication; and   computer readable program code configured so that when a password is accepted by an authentication Security System, the program code acts to sequentially send the username and Application name to each of the Web addresses on the authorization Web address list in the order in which they are listed to initiate interfacing User access until the username and Application name are accepted for access by an authorization Security System, the authorization list is completed or the username and Application name are matched but access is denied, invalid or has a status that otherwise will not grant access at the time of the access attempt.   
     
     
         17 . The method as set forth in  claim 16  including computer usable program code configured to translate the responses from the authentication Security Systems and authorization Security Systems into a standard code response. 
     
     
         18 . The method as set forth in  claim 17  including computer readable program code configured to communicate the username, password and Application name to the Web addresses corresponding to the user authentication Services and the Web addresses corresponding to the authorization Services to initiate interfacing with the programming language used by their respective Security Systems. 
     
     
         19 . The method as set forth in  claim 18  including computer readable program code configured to receive the authentication list and the authorization list as created by user input terminals and create the authentication Web address list and authorization Web address list from the received authentication list and authorization list. 
     
     
         20 . The method as set forth in  claim 19  wherein computer readable program code is configured to create the authentication list and authorization list at a server.

Join the waitlist — get patent alerts

Track US2012185920A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.