IP Library Granted Patent US 7,526,798
Granted Patent B2
US 7,526,798 · App. 10/286,609 · Granted Apr 28, 2009

System and method for credential delegation using identity assertion

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,526,798
App. No.
10/286,609
Granted
Apr 28, 2009
Kind
B2
Abstract

Run-as credentials delegation using identity assertion is presented. A server receives a request from a client that includes the client's user identifier and password. The server authenticates the client and stores the client's user identifier without the corresponding password in a client credential storage area. The server determines if a run-as command is specified to communicate with a downstream server. If a run-as command is specified, the server retrieves a corresponding run-as identity which identifies whether a client credential type, a server credential type, or a specific identifier credential type should be used in the run-as command. The server retrieves an identified credential corresponding to the identified credential type, and sends the identified credential in an identity assertion token to a downstream server.

Claims (13)

1. A method for handling network security, said method comprising:

receiving, at a first server, a client request from a client, wherein the client request includes a user identifier and a password;

authenticating the client request using a security service, wherein the security service is different than the first server;

in response to authenticating the client request, sending an authentication token from the security service to the first server;

in response to receiving the authentication token at the first server, storing the user identifier without the password in a client credential at the first server, wherein the client credential corresponds to a client credential type;

after receiving the authentication token from the security service, determining that a run-as command is specified that allows the first server to send an identity assertion token to a downstream server using a different identity, wherein the different identity is based upon a credential type that is selected from the group consisting of the client credential type, a server credential type, and a specific identifier credential type;

in response to determining that the run-as command is specified, selecting, at the first server, one of the credential types;

determining whether an enterprise Java bean has been invoked;

in response to determining that the enterprise Java bean has been invoked, generating the identity assertion token using an identified credential which corresponds to the selected credential type; and

sending the identity assertion token from the first server directly to the downstream server.

2. The method as described in claim 1 further comprising:

selecting the client credential as the identified credential.

3. The method as described in claim 1 wherein the identity assertion token includes the identified credential and a server credential.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2002
From: CHAO, CHING-YUN; CHUNG, HYEN V.; REEDY, AJAY; VENKATARAMAPPA, VISHWANATH
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 013477/0408 →
Continuity (1)
Related Publication 20040088578A1 · May 6, 2004