IP Library Granted Patent US 9,130,921
Granted Patent B2
US 9,130,921 · App. 13/855,595 · Granted Sep 8, 2015

System and method for bridging identities in a service oriented architectureprofiling

Inventors: Toufic Boubez (Vancouver, CA); Dimitri Sirota (Vancouver, CA); Scott Morrison (New Westminster, CA)
Assignee: CA, INC.
H04L63/08H04L63/10H04L67/02H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,130,921
App. No.
13/855,595
Granted
Sep 8, 2015
Kind
B2
Abstract

A system for bridging user identities between at least a first and a second security domain, including a bridge associated with the first security domain for intercepting messages for service in the second domain from users in the first domain. The bridge authenticates the user identities against a local authentication source by using an established key relationship and binds a security token with the message. A gateway is associated with the second domain for gating inbound access and outbound communication with a service in the second domain and for receiving the authenticated message and verifying the authenticity of the security token by using a certificate of the trusted authentication source and authorizing access to the service upon confirmation of the authorization, such that the authorization is independent of the identity of the user.

Claims (18)

1. A system for securing web services on one or more server computers delivered to one or more client computers, comprising:

a. one or more policies stored on said one or more server computers that define rules that must be satisfied for a web service provided by said one or more server computers to be accessed by said one or more client computers;

b. an agent process residing on said one or more client computers;

c. a local authorization source residing on said one or more client computers; and

d. a gateway process residing on said one or more server computers, said agent process detects a refusal for said web service, said agent process requests and receives said one or more policies from said one or more server computers in response to detecting said refusal for said web service, said agent process caches said received one or more policies as a dynamically updateable policy on said one or more client computers, said agent process directly applies any policy changes received from said gateway process to said dynamically updateable policy, said agent process intercepts a service request message for said web service from said one or more client computers and determines an identity associated with said service request message, said agent process authenticates said identity using said local authorization source and acquires a security token from said local authorization source, said agent process decorates said service request message using said security token based on said dynamically updateable policy, said agent process transmits said decorated service request message to said one or more server computers, said gateway process receives said decorated service request message and verifies an authenticity of said security token, said gateway process authorizes access to said web service in response to said authenticity of said security token being verified, said gateway process authorizes access to said web service independent of said identity associated with said service request message.

2. A system as defined in claim 1 , wherein said identity associated with said service request message corresponds with a user identity of a user requesting access to said web service.

3. A system as defined in claim 1 , wherein said policies include a rule set.

4. A system as defined in claim 1 , wherein said policies include an assertion.

5. A system as defined in claim 1 , wherein said policies include message-rerouting information.

6. A system for bridging user identities between a first security domain and a second security domain, comprising:

a bridge residing within said first security domain, said bridge configured to intercept a service request message from a user in said first security domain for access to a web service in said second security domain, said user is associated with an identity, said bridge configured to authenticate said identity of said user and to bind a security token with said service request message;

a gateway network appliance residing within said second security domain, said gateway network appliance configured to receive said service request message and to verify an authenticity of said security token, said gateway network appliance configured to authorize access to said web service in response to said authenticity of said security token being verified, said gateway network appliance configured to authorize access to said web service independent of said identity of said user; and

an agent residing within said first security domain, said agent detects a refusal for said web service, said agent process requests and receives one or more logical expressions from said gateway network appliance in response to detecting said refusal for said web service, said agent configured to modify said service request message by applying said one or more logical expressions requested and received from said gateway network appliance according to a dynamically updateable policy received from said second security domain and stored at said agent, said agent configured to receive and apply directly from the gateway network appliance any policy changes.

7. The system of claim 6 , wherein said one or more logical expressions include a rule set, said rule set demands that said service request message be encrypted using AES encryption.

8. The system of claim 6 , wherein said one or more logical expressions include an assertion.

9. The system of claim 6 , wherein said one or more logical expressions include message-rerouting information.

10. The system of claim 6 , wherein said bridge authenticates said identity of said user using a local authorization source and acquires said security token from said local authorization source.

11. The system of claim 6 , wherein said gateway network appliance comprises a gateway server.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2013
From: BOUBEZ, TOUFIC; SIROTA, DIMITRI; MORRISON, SCOTT
To: LAYER 7 TECHNOLOGIES, INC.
Reel/Frame 031104/0442 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2013
From: LAYER 7 TECHNOLOGIES INC.
To: 0965021 B.C. LTD.
Reel/Frame 031104/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2013
From: 0965021 B.C. LTD.
To: CA, INC.
Reel/Frame 031104/0680 →
Continuity (5)
Continuation 11236567 · Sep 28, 2005
Continuation In Part 10952787 · Sep 30, 2014
Provisional Application 60613618 · Sep 28, 2004
Provisional Application 60506759 · Sep 30, 2003
Related Publication 20140298419A1 · Oct 2, 2014