Emulation Of Federative Authentication
Abstract
A method for emulating authentication federation between a source domain and a target domain. A user in the source domain wishes to gain access to a target application in the target domain. The target application needs to receive authorized user credentials. The target domain includes an Authentication Federation Emulator having a relationship between a Request Acceptance Token and user credentials associated with a specific user. After having obtained the Request Acceptance Token from a federation site of the target domain, the user accesses the Authentication Federation Emulator for obtaining the corresponding user credentials and sends them to the target application.
Claims
exact text as granted — not AI-modified1 . Method of emulating authentication federation between a source domain and a target domain capable of communicating electronic messages to each other;
wherein the target domain comprises a target application and a target federation site; wherein the target application is associated with a credentials memory containing authorized user credentials; wherein the user needs to provide his specific user credentials to the target application in order to obtain access; wherein the source domain comprises a source federation site and a user's workstation wishing to gain access to the target application; wherein the source federation site comprises a user memory containing per user a relationship between authorized user source credentials and an Authentication Confirmation Token for use in target domain; wherein the target federation site comprises a federation memory containing per user a relationship between Authentication Confirmation Token for use by source domain and a Request Acceptance Token; wherein the method comprises the steps of:
providing an Authentication Federation Emulator that comprises an emulator memory containing per user a relationship between the Request Acceptance Token of federation memory and the user credentials of credentials memory.
2 . Method according to claim 1 , wherein the Authentication Federation Emulator is programmed to:
receive from the user a Credential Request Message containing the Request Acceptance Token; and in response to receiving the Credential Request Message and based on the information in its emulation memory, to send to the user a Credentials Conveyance Message which includes the user credentials associated with the user's Request Acceptance Token.
3 . Method according to claim 1 , wherein the Authentication Federation Emulator is programmed to:
receive from the user a Request Access via Federative Authentication message; and in response to receiving the Request Access via Federative Authentication message, to send to the user a first response message containing address information of the target federation site.
4 . Method for granting a user's workstation in a source domain access to a target application in a target domain;
wherein the target application is associated with a credentials memory containing authorized user credentials; wherein the user needs to provide his specific user credentials to the target application in order to obtain access; wherein the method comprises the method of emulating authentication federation according to claim 1 ; wherein the method further comprises successively:
a first access request stage in which:
the user's workstation sends to the target application a Request Access via Federative Authentication message containing information signaling to the target application that the access request includes a request to use authentication via federation;
the target application sends to the user a reply message containing address information of the Authentication Federation Emulator;
a federation stage in which the user's workstation is provided with the user's specific user credentials on the basis of his authorized user source credentials;
a second access request stage in which:
the user's workstation sends to the target application an Access Request Message (ARM) containing the specific user credentials;
wherein the federation stage comprises the steps of:
using the information received with the reply message from the target application, the user's workstation resends the Request Access via Federative Authentication message to the Authentication Federation Emulator;
the Authentication Federation Emulator replies to the user's workstation a first response message containing address information of the target federation site;
using the information received with the first response message from the Authentication Federation Emulator, the user's workstation resends the Request Access via Federative Authentication message to the target federation site;
the target domain's federation site replies to the user's workstation a second response message containing address information of the source federation site;
the user's workstation sends to the source federation site an Authentication Confirmation Request Message containing an indication of the specific target domain for which the authentication is intended and possibly containing the authorized user source credentials;
in response to the Authentication Confirmation Request Message, based on the information in its source memory, the source federation site sends to the user's workstation an Authentication Confirmation Message containing the Authentication Confirmation Token associated with the user's authorized user source credentials;
using the information received with the Authentication Confirmation Message from the source federation site, the user's workstation sends to the target federation site a Source Domain Token Message containing the Authentication Confirmation Token;
in response to the Source Domain Token Message, based on the information in its federation memory, the target federation site sends to the user's workstation a Request Acceptance Message which includes the Request Acceptance Token associated with the user's Authentication Confirmation Token;
using the information received with the Request Acceptance Message from the target federation site, the user's workstation sends to the Authentication Federation Emulator a Credential Request Message containing the Request Acceptance Token; and
in response to the Credential Request Message and based on the information in its emulation memory, the Authentication Federation Emulator sends to the user's workstation a Credentials Conveyance Message which includes the user credentials associated with the user's Request Acceptance Token.
5 . Authentication Federation Emulator for use in a method according to claim 1 , the Authentication Federation Emulator comprising an emulator memory containing per user a relationship between the Request Acceptance Token of the federation memory of the target domain and the user credentials of credentials memory of the target domain.
6 . Method according to claim 2 , wherein the Authentication Federation Emulator is programmed to:
receive from the user a Request Access via Federative Authentication message; and in response to receiving the Request Access via Federative Authentication message, to send to the user a first response message containing address information of the target federation site.Join the waitlist — get patent alerts
Track US2017078271A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.