IP Library Granted Patent US 8,296,853
Granted Patent B2
US 8,296,853 · App. 11/765,750 · Granted Oct 23, 2012

Method and system for authenticating a user

Assignee: Software AG
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,296,853
App. No.
11/765,750
Granted
Oct 23, 2012
Kind
B2
Abstract

Method of authenticating a user in a heterogeneous computer environment. The method may include defining a set of unique prefixes, each prefix identifying a type of user repository; defining a set of abstract repository names, each abstract repository name identifying an address of a user repository; and authenticating the user in the heterogeneous computer environment by assigning a sequence comprising a unique prefix, a reference to an abstract repository name and a unique identifier for the user within the user repository indicated by the reference to the abstract repository name.

Claims (37)

1. A method for authenticating a user in a heterogeneous computer environment, the method comprising:

utilizing one or more computers to perform:

a. defining a set of unique prefixes, each prefix identifying a type of user repository;

b. defining a set of abstract repository names, each abstract repository name identifying an address of a user repository, wherein each abstract repository name is mapped to a user repository, and is used to retrieve required address information that must be used to communicate with the repository, wherein said defining comprises defining an Abstract Repository Name Catalogue, which maps references to abstract repository names and abstract repository names to physical addresses; and

c. identifying the user in the heterogeneous computer environment by assigning a sequence comprising a unique prefix, a reference to an abstract repository name and a unique identifier for the user within the user repository indicated by the reference to the abstract repository name, wherein the user repository is indicated via the mapping by the Abstract Repository Name Catalogue of the reference to the abstract repository name, and of the abstract repository name to the physical address of the user repository, wherein the unique identifier for the user uniquely identifies the user based on one or more rules of the user repository, and wherein authenticating the user comprises verifying that the identified user is authenticated for the indicated user repository based on the one or more rules;

wherein more than one physical address is provided for a single abstract repository name, if the respective repository can be accessed via more than one protocol, and wherein the Abstract Repository Name Catalogue selects the physical address to return to the requestor based on the protocol required by the requestor to access the repository.

2. The method of claim 1 , wherein the set of unique prefixes comprises prefixes for at least one user repository type of one or more of:

Lightweight Directory Access Protocol Server (LDAP);

Windows Active Directory Server (ADS); or

Security Authorization Function (SAF), comprising RACF, ACF2 or TopSecret.

3. The method of claim 1 , wherein the set of unique prefixes comprises a prefix of a user repository of a native operating system.

4. The method of claim 1 , wherein there are more than one reference for a single abstract repository name.

5. The method of claim 1 , wherein the Abstract Repository Name Catalogue is implemented as a database.

6. The method of claim 1 , further comprising accessing the Abstract Repository Name Catalogue for verifying the authentication of the user by at least one application running in the heterogeneous computer environment.

7. The method of claim 1 , wherein the abstract repository name in the sequence identifies a user repository, for authenticating the credentials of the user.

8. The method of claim 1 , wherein the sequence is a string having the format of “prefix:reference:identifier”.

9. A non-transitory memory medium comprising program instructions for authenticating a user in a heterogeneous computer environment, wherein the program instructions are executable by a processor to:

a. define a set of unique prefixes, each prefix identifying a type of user repository;

b. define a set of abstract repository names, each abstract repository name identifying an address of a user repository, wherein each abstract repository name is mapped to a user repository, and is used to retrieve required address information that must be used to communicate with the repository, wherein said defining comprises defining an Abstract Repository Name Catalogue, which maps references to abstract repository names and abstract repository names to physical addresses; and

c. identify the user in the heterogeneous computer environment by assigning a sequence comprising a unique prefix, a reference to an abstract repository name and a unique identifier for the user within the user repository indicated by the reference to the abstract repository name, wherein the user repository is indicated via the mapping by the Abstract Repository Name Catalogue of the reference to the abstract repository name, and of the abstract repository name to the physical address of the user repository, wherein the unique identifier for the user uniquely identifies the user based on one or more rules of the user repository, and wherein authenticating the user comprises verifying that the identified user is authenticated for the indicated user repository based on the one or more rules;

wherein more than one physical address is provided for a single abstract repository name, if the respective repository can be accessed via more than one protocol, and wherein the Abstract Repository Name Catalogue selects the physical address to return to the requestor based on the protocol required by the requestor to access the repository.

10. The non-transitory memory medium of claim 9 , wherein the set of unique prefixes comprises prefixes for at least one user repository type of one or more of:

Lightweight Directory Access Protocol Server (LDAP);

Windows Active Directory Server (ADS); or

Security Authorization Function (SAF), comprising RACF, ACF2 or TopSecret.

11. The non-transitory memory medium of claim 9 , wherein the set of unique prefixes comprises a prefix of a user repository of a native operating system.

12. The non-transitory memory medium of claim 9 , wherein there are more than one reference for a single abstract repository name.

13. The non-transitory memory medium of claim 9 , wherein the Abstract Repository Name Catalogue is implemented as a database.

14. The non-transitory memory medium of claim 9 , wherein the program instructions are further executable to access the Abstract Repository Name Catalogue for verifying the authentication of the user by at least one application running in the heterogeneous computer environment.

15. The non-transitory memory medium of claim 9 , wherein the abstract repository name in the sequence identifies a user repository, for authenticating the credentials of the user.

16. A computer system for authenticating a user in a heterogeneous computer environment, comprising:

a processor; and

a memory medium coupled to the processor, wherein the memory medium comprises program instructions executable by the processor to:

define a set of unique prefixes, each prefix identifying a type of user repository;

define a set of abstract repository names, each abstract repository name identifying an address of a user repository, wherein each abstract repository name is mapped to a user repository, and is used to retrieve required address information that must be used to communicate with the repository, wherein said defining comprises defining an Abstract Repository Name Catalogue, which maps references to abstract repository names and abstract repository names to physical addresses; and

identify the user in the heterogeneous computer environment by assigning a sequence comprising a unique prefix, a reference to an abstract repository name and a unique identifier for the user within the user repository indicated by the reference to the abstract repository name, wherein the user repository is indicated via the mapping by the Abstract Repository Name Catalogue of the reference to the abstract repository name, and of the abstract repository name to the physical address of the user repository, wherein the unique identifier for the user uniquely identifies the user based on one or more rules of the user repository, and wherein authenticating the user comprises verifying that the identified user is authenticated for the indicated user repository based on the one or more rules;

wherein more than one physical address is provided for a single abstract repository name, if the respective repository can be accessed via more than one protocol, and wherein the Abstract Repository Name Catalogue selects the physical address to return to the requestor based on the protocol required by the requestor to access the repository.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2024
From: SOFTWARE AG
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 069048/0240 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2007
From: VOGLER, THOMAS; KESSLER, DIETER; WEBER, HEIKO; VIEGENER, JOHANNES, DR.
To: SOFTWARE AG
Reel/Frame 019937/0975 →
Priority Claims (1)
EP 07011721 · Jun 14, 2007 · regional
Continuity (1)
Related Publication 20080320602A1 · Dec 25, 2008