IP Library Granted Patent US 7,117,366
Granted Patent B2
US 7,117,366 · App. 10/042,639 · Granted Oct 3, 2006

Public key based authentication method for transaction delegation in service-based computing environments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,117,366
App. No.
10/042,639
Granted
Oct 3, 2006
Kind
B2
Abstract

A system and method for allowing access to data or processing on a remote computer. An authorizing computer provides client computers with a data specification and remote computer address along with an authorization code that is digitally signed or encrypted and that may only be used for a limited number of times. A client computer then accesses the remote computer by providing the digitally signed authorization code. The remote computer responds with the data or processing if the digital signature is successfully verified and the authorization code has been used fewer than the limited number of times.

Claims (53)

1. A method on a central computer of providing data to a client computer, comprising:

accepting a request for data from a client computer; and

transmitting, from a central computer, a partial response to the client computer, wherein the partial response comprises at least a nonce value and a representation of information to be displayed on the client computer, and wherein the nonce value is digitally signed by the central computer and is used to authorize a limited number of direct accesses to data on a remote computer, without using the central computer.

2. The method according to claim 1 , further comprising the step of charging an entity upon use of the nonce value for at least one of the direct accesses.

3. The method according to claim 1 , wherein the nonce value comprises an expiration time.

4. A method of controlling access to data on a remote computer, the method comprising:

accepting a request for a data item from a client computer, wherein the request contains a nonce value which has been digitally signed with a digital signature by a central computer;

verifying the nonce value, wherein the step of verifying the nonce value comprises the step of verifying the digital signature; and

responding to the request by returning the data item directly to the client computer without using an intermediary central computer if the nonce value is valid and has been previously used fewer than a limited number of times.

5. The method according to claim 4 , further comprising the step of charging an entity upon performance of the step of responding in conjunction with the use of the nonce value.

6. The method according to claim 4 , wherein the nonce value comprises an expiration time.

7. The method according to claim 4 , wherein step of verifying comprises comparing the nonce value to a list of stored and valid nonce values.

8. The method according to claim 7 , wherein the list of stored and valid nonce values is shared with an entity that originated the data request.

9. A method on a client computer of obtaining service from a secure data server, the method comprising:

accepting a partial response from a first computer, wherein the partial response comprises at least a nonce value, a specification of a remote computer, and a representation of information to be displayed on a client computer accepting the partial response, and wherein the nonce value is signed with a digital signature from the first computer;

transmitting a service request to the remote computer, wherein the service request comprises the nonce value; and

receiving a service response from directly the remote computer without the use of an intermediary central computer if the nonce value was valid.

10. The method according to claim 9 , wherein the service request comprises one of a request for a data item and a request for a computing service.

11. A central computer system for providing data to a client computer, the system comprising:

a request message receiver for accepting a request for data from a client computer; and

a partial response transmitter for transmitting a partial response by a central computer to the client computer, wherein the partial response comprises at least a nonce value and a representation of information to be displayed on the client computer, and wherein the nonce value is digitally signed by the central computer and is used to authorize a limited number of direct accesses to data on a remote computer, without using the central computer.

12. The system according to claim 11 , further comprising a billing module for charging an entity upon use of the nonce value for at least one of the direct accesses.

13. The system according to claim 11 , wherein the nonce value comprises an expiration time.

14. A system for controlling access to data on a computer, the system comprising:

a request receiver for accepting a request for a data item from a client computer, wherein the request contains a nonce value, wherein the nonce value is digitally signed with a digital signature by a central computer;

a nonce verifier for verifying the nonce value, wherein the nonce verifier performs at least a verification of the digital signature; and

a response generator for responding to the request by returning the data item directly to the client computer without using an intermediary central computer if the nonce value is valid and has been previously used fewer than a limited number of times.

15. The system according to claim 14 , further comprising a billing module for charging an entity upon use of the nonce value for the onetime access.

16. The system according to claim 14 , wherein the nonce value comprises an expiration time.

17. A system for obtaining service from a secure data server, the system comprising:

a partial response receiver for accepting a partial response from a first computer, wherein the partial response comprises at least a nonce value, a specification of a remote computer, and a representation of information to be displayed on a client computer accepting the partial response, and wherein the nonce value is digitally signed with a digital signature by the first computer;

a request transmitter for transmitting a service request to the remote computer, wherein the service request comprises the nonce value; and

a service response receiver for receiving a service response directly from the remote computer without the use of an intermediary central computer if the nonce value was valid.

18. The system according to claim 17 , wherein the service request comprises a request for a data item.

19. A computer program product for controlling communications access to remote processors, the computer program product comprising:

a storage medium readable by a processing circuit and storing computer instructions for execution by the processing circuit for performing a method comprising:

accepting a request for data from a client computer; and

transmitting a partial response, from a central computer, to the client computer, wherein the partial response comprises at least a nonce value and a representation of information to be displayed on the client computer, wherein the nonce value is digitally signed with a digital signature by the central computer and the nonce value is used to authorize a limited number of direct accesses to data on a remote computer, without using the central computer.

20. The computer program product of claim 19 , further comprising instructions for charging an entity for at least one of the direct accesses.

21. The computer program product of claim 19 , wherein the nonce value comprises an expiration time.

22. A computer program product for controlling communications access to computer, the computer program product comprising:

a storage medium readable by a processing circuit and storing computer instructions for execution by the processing circuit for performing a method comprising:

accepting a request for a data item from a client computer, wherein the request contains a nonce value, wherein the nonce value is digitally signed with a digital signature by a central computer;

verifying the nonce value, wherein the instructions for verifying comprise instructions for verifying the digital signature; and

responding to the request by returning the data item directly to the client computer without using an intermediary central computer if the nonce value was verified by the instructions for verifying and the nonce value is valid and has been previously used fewer than a limited number of times.

23. The computer program product according to claim 22 , further comprising instructions for charging an entity upon use of the nonce value for the onetime access.

24. The computer program product according to claim 22 , wherein the nonce value comprises an expiration time.

25. A computer program product for obtaining service from a secure data server, the computer program product comprising:

a storage medium readable by a processing circuit and storing computer instructions for execution by the processing circuit for performing a method comprising:

accepting a partial response from a first computer, wherein the partial response comprises at least a nonce value, a specification of a remote computer, and a representation of information to be displayed on a client computer accepting the partial response, wherein the nonce value is digitally signed with a digital signature by the first computer;

transmitting a service request to the remote computer, wherein the service request comprises the nonce value; and

receiving a service response from the remote computer without the use of an intermediary central computer if the nonce value was valid.

26. The computer program product according to claim 25 , wherein the service request comprises a request for a data item.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: WRP IP MANAGEMENT, LLC
Reel/Frame 049033/0410 →