IP Library › Granted Patent US 9,148,285
Granted Patent B2
US 9,148,285 · App. 13/745,942 · Granted Sep 29, 2015

Controlling exposure of sensitive data and operation using process bound security tokens in cloud computing environment

Inventors: John Y-C. Chang (Austin, TX); Ching-Yun Chao (Austin, TX); Bertrand Be-Chung Chiu (Austin, TX); Ki Hong Park (Research Triangle Park, NC)
Assignee: International Business Machines Corporation
H04L9/3247H04L9/3213H04L63/0815H04L63/0823H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,148,285
App. No.
13/745,942
Granted
Sep 29, 2015
Kind
B2
Abstract

Exposure of sensitive information to users is controlled using a first security token containing user identity and user credentials to represent the user who requests services, and a second security token containing two other identities, one identifying the token issuer and the other identifying the owning process. When requesting services, the token-owning process sends a security token to indicate who is making the request, and uses its key to digitally sign the request. The token-owning process signs the request to indicate that it endorses the request. A receiving server accepts a request if (1) the token-owning process endorses the request by signing the request; (2) the token is valid (token is signed by its issuer and the digital signature is verified and unexpired); (3) user entity, which can be a real user or a deployment or a server process, that is represented by the token has the authorization to access the specified resources; and (4) the token-owning process is authorized to endorse the user entity represented by the token to access the specified resources.

Claims (11)

1. A computer program product for controlling exposure of sensitive data and using process-bound security tokens comprising:

a tangible, computer-readable memory storage device; and

one or more program codes stored by the tangible, computer-readable memory storage device, for causing a processor to:

send in response to a user logging into an owning process to a targeted server computer a digitally signed owning process token containing an identity and a password of the user and an identity of the owning process, the owning process being executed by a first server computer which is separate from the targeted server, and the user being previously unauthenticated to the owning process;

receive a digitally signed user token from the targeted server computer subsequent to authentication of the user by the targeted server computer;

store the user token by the owning process for future use;

block forwarding of the user token to the user;

issue a single sign on token by the owning process;

send the single-sign-on token to the user from the owning process; and

protect the user token from exposure to the user by forwarding subsequent access requests by the user to the targeted server computer with the stored user token substituted in place of the single-sign-on token.

2. The computer program product as set forth in claim 1 wherein the digitally-signed user token is signed by a private key of a token service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2013
From: CHANG, JOHN Y-C.; CHAO, CHING-YUN; CHIU, BERTRAND BE-CHUNG; PARK, KI H.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 029663/0064 →
Continuity (1)
Related Publication 20140208119A1 · Jul 24, 2014