IP Library Granted Patent US 7,487,361
Granted Patent B2
US 7,487,361 · App. 10/881,962 · Granted Feb 3, 2009

Dynamic cache lookup based on dynamic data

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,487,361
App. No.
10/881,962
Granted
Feb 3, 2009
Kind
B2
Abstract

A system and method for tracking user security credentials in a distributed computing environment. The security credentials of an authenticated user includes not just his unique user identifier, but also a set of security attributes such as the time of authentication, the location where the user is authenticated (i.e., intranet user v. internet user), the authentication strength, and so on. The security attributes are used in access control decisions. The same user can be given different authorization if he has a different security attribute value. Security credentials may be generated either by WebSphere security code or by third party security provider code. This invention stores the user credentials in a distributed cache and provides a system and method to compute the unique key based on the dynamic security credentials for cache lookup

Claims (10)

1. A method of caching authentication data on a computer network, comprising the steps of:

receiving, at a server in a computer network, an access request by a login user;

the server authenticating the login user based on security credentials forwarded by the login user and sending a token back to the login user, wherein the token comprises a single-sign on token and contains the security credentials forwarded by the login user;

the server receiving a later access request by the login user, the later access request including the token;

the server generating a unique lookup key using the token, the unique lookup key comprising a one-way hash of unique security attributes, wherein the unique security attributes comprises static security attributes including an access ID, and dynamic security attributes including a login time and a login location, and wherein the dynamic security attributes are selected based on a login module;

the server using the generated unique lookup key to find security credentials of the login user in a distributed cache; and

the server granting the later access request by granting access rights to the login user according to the security credentials in the distributed cache, wherein the security credentials in the distributed cache vary according to both the static security attributes and the dynamic security attributes, such that the login user having the same static security attributes is granted different access rights according to differences in the dynamic security attributes.

2. The method of claim 1 , further comprising:

providing the login module with the dynamic security attributes.

3. The method of claim 1 , wherein the access ID is simultaneously logged into the network as two different login users based on the dynamic security attributes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2004
From: BIRK, PETER DANIEL; CHAO, CHING-YUN; CHUNG, HYEN VUI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014866/0907 →
Continuity (1)
Related Publication 20060020813A1 · Jan 26, 2006