Secure configuration catalog of trusted identity providers
US9690920B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Aug 30, 2012 |
| Grant date | Jun 27, 2017 |
| Priority date | — |
| Expiry date | May 26, 2033 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/0884
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A secure database includes a catalog of information about one or more identity providers (IdPs) that are trusted by a service provider (SP) to authenticate users on the SP's behalf. The catalog securely stores one or more IdP configurations. An entry in the database stores information associated with the trusted IdP including artifacts to identify the IdP, artifacts used by the IdP for cryptographic operations, and a specification of one or more website(s) serviced by the trusted identity provider. Upon receipt by the SP of identity information representing a user that has authenticated to an IdP, information in the catalog of information is used to determine whether the IdP is trusted to authenticate the user on the service provider's behalf. The determination verifies that the SP uses the IdP and that a binding between an IdP identifier and at least one IdP cryptographic artifact is valid.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.