IP Library Granted Patent US 7,380,129
Granted Patent B2
US 7,380,129 · App. 10/829,856 · Granted May 27, 2008

Method and apparatus for detecting grid intrusions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,380,129
App. No.
10/829,856
Granted
May 27, 2008
Kind
B2
Abstract

A method, apparatus, and computer instructions for authorizing a user to access grid resources. A request is received from the user to access a resource on the data processing system. This request includes a certificate. An authentication process is performed using the certificate when the request is received. In response to successfully authenticating the user in the authentication process, a first host name for the certificate is requested from a trusted source. A reply containing the first host name is received. Access to the resource is provided if the first host name returned by the trusted source matches a second host name for the user from which the request originated.

Claims (15)

1. A method in a data processing system for authorizing a user to access grid resources, the method comprising:

receiving a request from the user to access a resource on the data processing system, wherein the request includes a certificate;

responsive to receiving the request, performing an authentication process using the certificate;

responsive to successfully authenticating the user in the authentication process, requesting a first host name for the certificate from a trusted source; and

responsive to receiving the first host name, providing access to the resource if the first host name returned by the trusted source matches a second host name for the user from which the request originated.

2. The method of claim 1 , wherein the trusted source is a certificate authority.

3. The method of claim 1 further comprising:

responsive to successfully authenticating the user in the authentication process, requesting a revocation list from the trusted source;

determining whether the certificate has been revoked using the revocation list; and

preventing access to the resource if the certificate has been revoked.

4. The method of claim 1 , wherein the certificate is a proxy certificate, wherein the proxy certificate is valid only for a selected period of time.

5. The method of claim 1 , wherein the first host name is for a client data processing system for the user and is registered with the trusted source when the certificate is issued.

6. The method of claim 1 , wherein the certificate is an X.509 certificate.

7. The method of claim 1 , wherein the access to the resource is to run a task on the data processing system.

8. The method of claim 1 , wherein the data processing system is part of a grid.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2010
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: TREND MICRO INCORPORATED
Reel/Frame 024286/0924 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNOR NAME. PREVIOUSLY RECORDED ON REEL 014633 FRAME 0491. Recorded Oct 12, 2004
From: KEOHANE, SUSANN MARTE; MCBREARTY, GERALD FRANCIS; MULLEN, SHAWN PATRICK; MURILLO, JESSICA KELLEY; SHIEH, JOHNNY MENG-HAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 015236/0805 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2004
From: KEOHANE, SUSANN MARIE; MCBREARTY, GERALD FRANCIS; MULLEN, SHAWN PATRICK; MURILLO, JESSICA KELLEY; SHIEH, JONNY MENG-HAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014633/0491 →