IP Library › Granted Patent US 8,839,393
Granted Patent B2
US 8,839,393 · App. 13/943,138 · Granted Sep 16, 2014

Authentication policy usage for authenticating a user

Inventor: Masahiro Takehi (Tokyo, JP)
Assignee: International Business Machines Corporation
H04L63/20H04L63/0815G06F21/31H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,839,393
App. No.
13/943,138
Granted
Sep 16, 2014
Kind
B2
Abstract

A method and system for authenticating a user. A first server of multiple servers generates an authentication policy table by inserting into the authentication policy table an authentication policy of each server and setting a relative priority of each server in the authentication policy table of the first server in order of decreasing number of users registered in an authentication system of each server. The authentication policy of each server is at least one rule of each server for authenticating users of a federated computing environment that includes the multiple servers. The first server receives an access request from the user to access the federated computing environment, receives input authentication information from the user, and determines from use of both the input authentication information and the at least one rule in the authentication policy table of the first server that the user is authorized to access the federated computing environment.

Claims (45)

1. A method for authenticating a user, comprising:

a first server of a plurality of servers generating, by a computer processor, an authentication policy table, said generating the authentication policy table comprising (i) inserting into the authentication policy table an authentication policy of each server and (ii) setting a relative priority of each server in the authentication policy table of the first server in order of decreasing number of users registered in an authentication system of each server, wherein the authentication policy of each server is at least one rule of each server for authenticating users of a federated computing environment that comprises the plurality of servers;

said first server storing, by the processor, the generated authentication policy table within the first server;

after said generating and storing the authentication policy table, said first server receiving, by the processor, an access request from the user to access the federated computing environment;

after said receiving the access request, said first server receiving, by the processor, input authentication information from the user; and

said first server ascertaining, by the processor, that the user is authorized to access the federated computing environment, wherein said ascertaining comprises determining that the received input authentication information conforms to the at least one rule of the authentication policy of a second server having a highest relative priority among servers of the plurality of servers whose authentication policy's at least one rule, in the authentication policy table of the first server, is conformed to by the received input authentication information.

2. The method of claim 1 , wherein said determining that the received input authentication information conforms to the at least one rule of the authentication policy of the second server comprises determining that the received input authentication information conforms to a format specified in the at least one rule of the authentication policy of the second server.

3. The method of claim 2 , wherein the format specified in the at least one rule of the authentication policy of the second server is a specification of an alphanumeric format of each character contained in a user identification (ID) of the user and of each character contained in a password of the user, and wherein the alphanumeric format of each character is selected from the group consisting of an alphabetic character and a numeric character.

4. The method of claim 2 , wherein the format specified in the at least one rule of the authentication policy of the second server is a specified total number of bytes of binary data representing a fingerprint of the user or a voice print of the user.

5. The method of claim 1 , wherein said generating the authentication policy table further comprises inserting a server address of each server into the authentication policy table, and wherein said determining that the user is authorized to access the federated computing environment comprises:

said first server obtaining from the authentication policy table of the first server the server address of the second server;

said first server transmitting the input authentication information to the second server via the obtained server address of the second server; and

after said transmitting the input authentication information to the second server, said first server receiving from the second server a notification that the second server has successfully authorized the user.

6. The method of claim 1 , said method further comprising:

after said determining that the user is authorized to access the federated computing environment, said first server permitting, by the processor, the user to access the federated computing environment.

7. A computer system comprising a processor, a storage device coupled to the processor, and a computer readable memory unit coupled to the processor, said storage device containing program code configured to be executed by the processor via the memory unit to implement a method for authenticating a user, said method comprising:

a first server of a plurality of servers generating, by the processor, an authentication policy table, said generating the authentication policy table comprising (i) inserting into the authentication policy table an authentication policy of each server and (ii) setting a relative priority of each server in the authentication policy table of the first server in order of decreasing number of users registered in an authentication system of each server, wherein the authentication policy of each server is at least one rule of each server for authenticating users of a federated that comprises the plurality of servers;

said first server storing, by the processor, the generated authentication policy table within the first server;

after said generating and storing the authentication policy table, said first server receiving, by the processor, an access request from the user to access the federated computing environment;

after said receiving the access request, said first server receiving, by the processor, input authentication information from the user; and

said first server ascertaining, by the processor, that the user is authorized to access the federated computing environment, wherein said ascertaining comprises determining that the received input authentication information conforms to the at least one rule of the authentication policy of a second server having a highest relative priority among servers of the plurality of servers whose authentication policy's at least one rule, in the authentication policy table of the first server, is conformed to by the received input authentication information.

8. The computer system of claim 7 , wherein said determining that the received input authentication information conforms to the at least one rule of the authentication policy of the second server comprises determining that the received input authentication information conforms to a format specified in the at least one rule of the authentication policy of the second server.

9. The computer system of claim 8 , wherein the format specified in the at least one rule of the authentication policy of the second server is a specification of an alphanumeric format of each character contained in a user identification (ID) of the user and of each character contained in a password of the user, and wherein the alphanumeric format of each character is selected from the group consisting of an alphabetic character and a numeric character.

10. The computer system of claim 8 , wherein the format specified in the at least one rule of the authentication policy of the second server is a specified total number of bytes of binary data representing a fingerprint of the user or a voice print of the user.

11. The computer system of claim 7 , wherein said generating the authentication policy table further comprises inserting a server address of each server into the authentication policy table, and wherein said determining that the user is authorized to access the federated computing environment comprises:

said first server obtaining from the authentication policy table of the first server the server address of the second server;

said first server transmitting the input authentication information to the second server via the obtained server address of the second server; and

after said transmitting the input authentication information to the second server, said first server receiving from the second server a notification that the second server has successfully authorized the user.

12. The computer system of claim 7 , said method further comprising:

after said determining that the user is authorized to access the federated computing environment, said first server permitting, by the processor, the user to access the federated computing environment.

13. A computer program product, comprising a computer readable storage device having program code stored therein, said program code configured to be executed by a computer processor to perform a method for authenticating a user, said method comprising:

a first server of a plurality of servers generating, by the processor, an authentication policy table, said generating the authentication policy table comprising (i) inserting into the authentication policy table an authentication policy of each server and (ii) setting a relative priority of each server in the authentication policy table of the first server in order of decreasing number of users registered in an authentication system of each server, wherein the authentication policy of each server is at least one rule of each server for authenticating users of a federated that comprises the plurality of servers;

said first server storing, by the processor, the generated authentication policy table within the first server;

after said generating and storing the authentication policy table, said first server receiving, by the processor, an access request from the user to access the federated computing environment;

after said receiving the access request, said first server receiving, by the processor, input authentication information from the user; and

said first server ascertaining, by the processor, that the user is authorized to access the federated computing environment, wherein said ascertaining comprises determining that the received input authentication information conforms to the at least one rule of the authentication policy of a second server having a highest relative priority among servers of the plurality of servers whose authentication policy's at least one rule, in the authentication policy table of the first server, is conformed to by the received input authentication information.

14. The computer program product of claim 13 , wherein said determining that the received input authentication information conforms to the at least one rule of the authentication policy of the second server comprises determining that the received input authentication information conforms to a format specified in the at least one rule of the authentication policy of the second server.

15. The computer program product of claim 14 , wherein the format specified in the at least one rule of the authentication policy of the second server is a specification of an alphanumeric format of each character contained in a user identification (ID) of the user and of each character contained in a password of the user, and wherein the alphanumeric format of each character is selected from the group consisting of an alphabetic character and a numeric character.

16. The computer program product of claim 14 , wherein the format specified in the at least one rule of the authentication policy of the second server is a specified total number of bytes of binary data representing a fingerprint of the user or a voice print of the user.

17. The computer program product of claim 13 , wherein said generating the authentication policy table further comprises inserting a server address of each server into the authentication policy table, and wherein said determining that the user is authorized to access the federated computing environment comprises:

said first server obtaining from the authentication policy table of the first server the server address of the second server;

said first server transmitting the input authentication information to the second server via the obtained server address of the second server; and

after said transmitting the input authentication information to the second server, said first server receiving from the second server a notification that the second server has successfully authorized the user.

18. The computer program product of claim 13 , said method further comprising:

after said determining that the user is authorized to access the federated computing environment, said first server permitting, by the processor, the user to access the federated computing environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: AIRBNB, INC.
Reel/Frame 056427/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2013
From: TAKEHI, MASAHIRO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 030806/0389 →
Continuity (3)
Continuation 12767832 · Apr 27, 2010
Division 10598875 · Sep 14, 2006
Related Publication 20130305313A1 · Nov 14, 2013