首页> 外国专利> Sign-On system with distributed access

Sign-On system with distributed access

机译:具有分布式访问权限的登录系统

摘要

A security system is provided for storing sensitive data and providing access to this data to at least one user (10) having an electronic communication device and using a single-sign-on procedure. A request (101) is directed to a first service provider (20). Based on the request (101) a challenge request (102) comprising the user identification code is sent to the second service provider (30); wherein the second service provider sends an authentication message (103) comprising the user identification code and an user Sign-On key to the first computer system, wherein the user Sign-On key is asymmetrically encrypted with a first service provider's (20) public key. Upon reception of the authentication message (103), the application of the first computer system creates an access ticket (104) comprising the digitally signed Sign-On key of the user, asymmetrically encrypted with a second service provider's (30) public key, wherein the content of said access ticket (104) is transmitted (105) to the user address from which the initial request (101) was initiated for a redirect (106) to the second computer system. The second service provider (30) starts a communication session with said user for accessing data in the data storage facility (31) after having checked the authentication of the user based on the basis of the user Sign-On key and a further part of the Sign-On key.
机译:提供一种安全系统,用于存储敏感数据并向具有电子通信设备并使用单点登录过程的至少一个用户(10)提供对该数据的访问。请求(101)被定向到第一服务提供商(20)。基于请求(101),将包括用户识别码的挑战请求(102)发送到第二服务提供商(30);其中第二服务提供商向第一计算机系统发送包括用户标识代码和用户登录密钥的认证消息(103),其中用户登录密钥被第一服务提供商的公共密钥(20)非对称加密。在接收到认证消息(103)之后,第一计算机系统的应用程序创建访问票据(104),该访问票据包括用户的数字签名的登录密钥,并用第二服务提供商的(30)公共密钥进行非对称加密,其中所述访问权证(104)的内容被发送(105)到用户地址,从该用户地址发起初始请求(101),以进行到第二计算机系统的重定向(106)。第二服务提供者(30)在基于用户登录密钥和用户的另一部分的基础检查了用户的身份验证之后,开始与所述用户的通信会话,以访问数据存储设备(31)中的数据。登录密钥。

著录项

  • 公开/公告号EP2530618B1

    专利类型

  • 公开/公告日2016-06-08

    原文格式PDF

  • 申请/专利权人 DSWISS AG;

    申请/专利号EP20120170543

  • 申请日2012-06-01

  • 分类号G06F21/41;G06F21/33;H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-21 14:52:34

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号