Electrical computers and digital processing systems: support – Multiple computer communication using cryptography – Protection at a particular protocol layer
Reexamination Certificate
1998-03-27
2001-08-14
Lee, Thomas (Department: 2182)
Electrical computers and digital processing systems: support
Multiple computer communication using cryptography
Protection at a particular protocol layer
C713S175000, C713S182000
Reexamination Certificate
active
06275941
ABSTRACT:
BACKGROUND OF THE INVENTION
The present invention relates to a security management method for a network having a client and severs, and more particularly, to a network system security management method which integrally manages a user and provides the single sign-on function of utilizing an integrated certificate for the user.
With a widespread use of the Internet, the market trend toward the security management has changed drastically. Especially when a wide area network system such as the Internet and an intra-enterprise network system (intranet) are combined together, the user authentication function and the function of controlling access to resources in the two network systems, by which the two networks can be integrated, have been sought. In other words, the integral management of a user and the centralized management of network resources which cover the two of the wide area network system and intra-enterprise network system have been desired.
As a method of integrally managing a user utilizing a wide area network system, a method as described in, for example, JP-A-6-223041 is known, according to which private information of a utilizer and utilization environment information are ciphered with a private key, a certificate issue server issues, as a certificate, the ciphered information to the utilizer and the utilizer logs in the system by utilizing this certificate. Further, as a security management method considering a distributed system, a method as described in, for example, JP-A-8-106437 is known in which when a user accesses a domain which is not a home domain of the user, a log-on certificate for certificating qualification authentication of the user is utilized. Further, JP-A-7-141296 discloses a system in which a TTP (Trusted Third Party) for managing security over a network domain is provided to perform setting and change of security policy of the overall network and access control based on the security policy is carried out.
Expectantly, the system for performing the user authentication and access control by utilizing the certificate as described above will come into wide use as one of security management systems for future wide area network systems. But when it comes to considering an actual network system, the existing enterprise network system has difficulties in shifting to a working which integrally utilizes a certificate issued by an external certificate authority and shifting to the security management based on the TTP. Namely, a method is desired which introduces a single sign-on scheme based on utilization of a certificate while preserving the existing user authentication scheme based on a user ID and a password.
SUMMARY OF THE INVENTION
An object of the present invention is to provide a security management method which facilitates shifting of the existing user authentication scheme based on a user ID and a password to the single on-sign based on utilization of an integrated certificate.
Another object of the present invention is to provide a security management method for wide area network system which can afford to perform user authentication by using a single integrated certificate in connection with different service requests made by the same user.
According to the present invention, in a security management system for a network system in which a client, an application server and an integrated authentication server can communicate with each other through a network, the client makes a service request by transmitting information of an integrated certificate to the application server. The application server transfers the information of the integrated certificate to the integrated authentication server to request the integrated authentication server to confirm the integrated certificate. The integrated authentication server confirms the integrated certificate and checks a user for the right to access the application server, and if valid, the integrated authentication server transmits a user ID and a password to the application server and the application server performs user authentication based on the user ID and the password.
In place of the confirmation of the integrated certificate by the integrated authentication server, the integrated certificate may be confirmed by the application server. In that case, when the application server has confirmed the integrated certificate, the application server transfers the information of the integrated certificate to the integrated authentication server to make a request for a user ID and a password to the integrated authentication server. The integrated authentication server checks the user for the right to access the application server and if valid, the integrated authentication server transmits the user ID and the password to the application server. After that, the application server may perform user authentication based on the user ID and the password.
In the present invention, the client may transmit a user ID and a password to the application server to initially make a service request, and the application server may transfer the user ID and the password to the integrated authentication server. In that case, the integrated authentication server may check the user for the right to access the application server and if valid, the integrated authentication server may prepare a temporal integrated certificate and transmit it to the client via the application server. A security management method may be adopted wherein when the user subsequently makes a service request, the temporal integrated certificate is transmitted to the application server.
Preferably, in the present invention, the results of security check, including a result of the confirmation of the integrated certificate which is executed by the integrated authentication server and application server while the client initially logs in the system and finally logs off the system, a result of checking the right to access the application server, a result of authentication of the user ID and password, and a result of checking the right to access data held by the application server, may be recorded as access history information in the client and the application server. For example, the integrated authentication server can record as access history information the result of the confirmation of the integrated certificate and the result of the security check including checking the right to access the application server, and access conditions of the user can be checked by collating the access history information recorded in the client with the access history information recorded in the integrated authentication server.
Further, the process of the above method to be executed on the integrated authentication server side can be carried out by executing a computer program implemented on a storage medium readable by the integrated authentication server.
When the same user possesses a plurality of certificates for user authentication in respect of a plurality of transactions, a certificate corresponding to a transaction can be down-loaded from the authentication server to the user in response to inputting of the integrated certificate by the user and authentication of a communication partner and ciphering of communication can be realized on the basis of information of the certificate.
According to the present invention, in a security management method for, for example, a network system in which a client, an application server or a communication partner and an integrated authentication server can communicate with each other through a network, the client transmits information of an integrated certificate to the integrated authentication server to request the integrated authentication server to authenticate a user of the client. In response to a request for communicating with an application of the application server or the communication partner made by the client, the integrated authentication server checks the right to access and if valid, the integrated authentication server transmits a certificate of the transaction to an entity concerned in communication and the client c
Ikeuchi Manabu
Saito Yoko
Shimizu Michihiro
Antonelli Terry Stout & Kraus LLP
Hiatchi Ltd.
Lee Thomas
Nguyen Nguyen
LandOfFree
Security management method for network system does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Security management method for network system, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Security management method for network system will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-2470349