IP Library › Granted Patent US 7,313,816
Granted Patent B2
US 7,313,816 · App. 10/022,578 · Granted Dec 25, 2007

Method and system for authenticating a user in a web-based environment

Assignee: One Touch Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,313,816
App. No.
10/022,578
Granted
Dec 25, 2007
Kind
B2
Abstract

A system and method for authenticating a client having a privilege server, a head end server, and a web adapter performs the steps of negotiating an authentication scheme between the server proxy and the privilege server. User information is presented to the web adapter. The user information is provided to the head end server and in turn presents the information to the web adapter. The user is validated in accordance with the authentication scheme. When the user is validated a ticket is generated for the user. The ticket is presented to the client privilege server proxy that decrypts the ticket. A token is formed from the ticket and the client user identification. The token from the client is provided to the privilege server. A packet is formed having a sequence number and session key encrypted with the ticket. The packet is provided to the head end server which in turn authenticates the user. The packet is provided to the client privilege proxy which decrypts the packet and sends the ticket and the sequence number encrypted with the session key to the data server through the web adapter. User is validated at the data server and privileges are granted thereto.

Claims (47)

1. A method of authenticating a user having a user privilege server proxy for a network system having a privilege server, a head end server and a web adapter comprising:

presenting user information to the web adapter from the user privilege server proxy;

presenting the user information to the head end server;

presenting the user information to the privilege server from the head end server;

validating the user in response to the user information;

when a user is validated, generating a ticket for the user at the privilege server;

providing the ticket to the user privilege server proxy through the head end server;

forming a service access request token from the ticket and the user information;

sending the token from the user to the privilege server;

validating the user in response to the token;

forming a packet having a sequence number, session key and the ticket at the privilege sewer;

providing the packet to the head-end server;

in response to receiving the packet, authenticating the user at the head end server;

providing the packet to the user privilege server proxy;

sending the ticket and sequence number encrypted with the session key to a service server through the web adapter;

validating the user at the service server; and

granting the user role based privileges at the service server.

2. A method as recited in claim 1 further comprising the step of negotiating an authentication scheme between the server proxy and privilege server.

3. A method as recited in claim 2 wherein negotiating the authentication scheme between the user privilege sewer proxy and privilege server comprises presenting at least one security mechanism from the user privilege server proxy to the privilege server; accepting or rejecting the at least one security mechanism at the privilege server.

4. A method as recited in claim 2 wherein the step of validating the user in response to the user information comprises validating the user in response to the user information in accordance with the authentication scheme.

5. A method as recited in claim 1 further comprising the step of encrypting the ticket with a user password to form an encrypted ticket.

6. A method as recited in claim 5 further comprising the step of decrypting the encrypted ticket at the user privilege server proxy.

7. A method as recited in claim 1 further comprising the steps of forming a packet having a sequence number and session key encrypted with the ticket at the privilege server and decrypting the packet at the user privilege server proxy.

8. A method as in claim 1 wherein generating a ticket comprises generating a ticket with at least one of a session name and the user information.

9. A method of authenticating a user having a user privilege server proxy for a network system having a privilege server, a head end server and a web adapter comprising:

negotiating an authentication scheme between the user privilege server proxy and the privilege server;

presenting user information to the web adapter;

presenting the user information to the head end server;

presenting the user information to the privilege server from the head end server;

validating the user at the privilege server in response to the user information in accordance with the authentication scheme;

when a user is validated, generating a ticket for the user at the privilege server;

encrypting the ticket with a user password to form an encrypted ticket;

providing the encrypted ticket to the user privilege server proxy through the head end server;

decrypting the encrypted ticket to form a decrypted ticket;

forming a service access request token from the decrypted ticket and the user information at the user privilege server proxy;

sending the token from the user privilege server proxy to the privilege server;

validating the user in response to the token;

forming a packet having a sequence number and session key encrypted with the ticket at the privilege server;

providing the packet to the head-end server;

in response to the packet, authenticating the user at the head end server;

providing the packet to the user privilege server proxy;

decrypting the packet;

sending the ticket and sequence number encrypted with the session key to a service server through the web adapter;

validating the user at the service server; and

granting the user role based privileges at the service server.

10. A method as recited in claim 9 wherein negotiating an authentication scheme between the server proxy and privilege server comprises presenting at least one security mechanism from the user privilege server proxy to the privilege server and accepting or rejecting the at least one security mechanism at the privilege server.

11. A method as recited in claim 9 comprising authenticating the user by a policy engine within the privilege server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2001
From: SINHA, BHASKAR; VENNELAKANTI, RAVIGOPAL; REBALA, GOPINATH
To: ONE TOUCH SYSTEMS, INC.
Reel/Frame 012400/0235 →
Continuity (1)
Related Publication 20030115341A1 · Jun 19, 2003