Patent · US Expired

Apparatus and method for using a directory service for authentication and authorization to access resources outside of the directory service

US7146635B2 · kind B2 · utility

27Cited by
3References
3Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 27, 2000
Grant dateDec 5, 2006
Priority date
Expiry dateMay 24, 2023

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/6218
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

An apparatus and method use the built-in authentication and authorization functions of a directory service to perform authentication and authorization for resources that are external to the directory service. A Lightweight Directory Access Protocol (LDAP) service is used in the preferred embodiments. The LDAP directory includes built-in functions for authenticating a user that requests access to an entry. Each resource that needs to be protected is mapped to an entry in the LDAP directory. These entries that correspond to protected resources external to the LDAP directory are called proxy entries. Proxy entries contain the authorization information for the corresponding protected resource in the form of an access control list for each entry that specifies the authorized users of the entry. When a user needs to access a protected resource, the user or an application uses the LDAP directory to determine whether the user is authenticated and authorized to access the proxy entry in the directory that corresponds to the resource. If the user is authenticated and authorized to access the proxy entry, the user may then access the corresponding external protected resource. The present inve…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.