Patent · US Expired

Providing identity-related information and preventing man-in-the-middle attacks

US7240362B2 · kind B2 · utility

8Cited by
3References
16Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 8, 2003
Grant dateJul 3, 2007
Priority date
Expiry dateAug 31, 2025

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1483
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

This invention provides identity-related information about a client application to an honest requesting entity, ensuring identity of client applications and preventing man-in-the-middle attacks. An example method comprises transferring identity-related information hosted on an identity provider about a client application to an honest requesting entity by: the client application receiving from a particular entity a request to forward an inner request comprising an identifier of the honest requesting entity to an identity provider selected by the client application; the client application forwards the inner request to the identity provider holding the identity-related information; the client application receives from the identity provider a response envelope instructing the client application to forward an inner response comprising the identity-related information requested in the inner request and the identifier; the client application derives an address of the honest requesting entity having the identifier; and the client application forwards the inner response to the derived address.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.