Patent · US Active

System and method for managing security meta-data in a reverse proxy

US7600230B2 · kind B2 · utility

18Cited by
4References
23Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 6, 2004
Grant dateOct 6, 2009
Priority date
Expiry dateJan 23, 2027

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/101
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system and method for managing security meta-data in a reverse proxy server. The reverse proxy caches data served by an origin server, and also stores security meta-data for authenticating a user and/or authorizing access to cached data. The security meta-data may include an ACL (Access Control List), access control token or descriptor, other access control information, user credentials, user privileges or roles, group membership, user aliases, etc. The reverse proxy may automatically receive access control information from the origin server when a request for data is forwarded to the origin server, or may explicitly request the information from the origin server or a security server. The reverse proxy receives and applies invalidation messages to invalidate stored security meta-data. Also, the reverse proxy acts in a stateful manner, with knowledge of the correlation between a given user and that user's session with the origin server.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.