IP Library Granted Patent US 8,452,881
Granted Patent B2
US 8,452,881 · App. 11/236,567 · Granted May 28, 2013

System and method for bridging identities in a service oriented architecture

Inventors: Toufic Boubez (Vancouver, CA); Dimitri Sirota (Vancouver, CA); Scott Morrison (New Westminster, CA)
H04L29/08072
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,452,881
App. No.
11/236,567
Granted
May 28, 2013
Kind
B2
Abstract

A system for bridging user identities between at least a first and a second security domain, including a bridge associated with the first security domain for intercepting messages for service in the second domain from users in the first domain. The bridge authenticates the user identities against a local authentication source by using an established key relationship and binds a security token with the message. A gateway is associated with the second domain for gating inbound access and outbound communication with a service in the second domain and for receiving the authenticated message and verifying the authenticity of the security token by using a certificate of the trusted authentication source and authorising access to the service upon confirmation of the authorisation, such that the authorisation is independent of the identity of the user.

Claims (4)

1. A system for bridging user identities between at least a first security domain and a second security domain, comprising:

a. a bridge associated with said first security domain for intercepting messages for service in said second security domain from users in said first domain and for authenticating an identity of said user against a local authentication source by using an established key relationship and for binding a security token with said message;

b. a gateway network appliance associated with said second domain for gating inbound access and outbound communication with a service in said second domain and for receiving an authenticated message and verifying an authenticity of said security token by using a certificate of a trusted authentication source and authorizing access to said service upon confirmation of an authorization, such that said authorization is independent of the identity of said user; and

c. an agent in said first domain for i) preparing and modifying said message by applying one or more logical expressions requested and received from said gateway network appliance according to a dynamically updateable policy received from said second domain and stored at said agent and ii) receiving and applying directly from the gateway network appliance any policy changes.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2013
From: 0965021 B.C. LTD.
To: CA, INC.
Reel/Frame 030944/0618 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2013
From: LAYER 7 TECHNOLOGIES INC.
To: 0965021 B.C. LTD.
Reel/Frame 030908/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2009
From: BOUBEZ, TOUFIC; SIROTA, DIMITRI; MORRISON, SCOTT
To: LAYER 7 TECHNOLOGIES INC.
Reel/Frame 022313/0444 →
Continuity (3)
Continuation In Part 10952787 · Sep 30, 2004
Provisional Application 60613618 · Sep 28, 2004
Related Publication 20060080352A1 · Apr 13, 2006