EP0503765A2

Access control in a distributed computer system.

Abstract

A mechanism is described for controlling access to a target application (TA) in a distributed computer system. A user sponsor (US) acting on behalf of an end user is issued with a privilege attribute certificate (PAC) containing initiator qualifier attributes (IQA) identifying permitted users of the PAC. The US obtains a key from a key distribution server (KDS), the key having initiator qualifier attributes of the US cryptographically associated with it. The US uses this key to communicate with the TA, and presents its PAC for verification. If the IQA in the PAC do not match the IQA associated with the key, this indicates that the PAC is being presented by the wrong initiator, and so access is not permitted. If a receiving entity subsequently wishes to act as an initiator and to use the PAC by proxy, it acquires a key from the KDS, the key having the receiving entity's attributes cryptographically associated with it. This provides a way of regulating proxy use of PACs. <IMAGE>

EP0503765A2, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 10 February 2012, 14.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

5 claims: 4 independent, 1 dependent

  1. 1
    A data processing system in which a plurality of initiator entities can access a plurality of target entities (10), the system comprising:- a) means (16) for issuing privilege attribute certificates PACs) to the initiator entities,b) verification means (18) for verifying the PACs, andc) key distribution means (14) for issuing cryptographic keys to the initiator entities, characterised in that: (i) each initiator entity (10) is assigned a set of initiator qualifier attributes,(ii) each said key issued to an initiator entity by the key distribution means (14) has initiator qualifier attributes of the initiator entity cryptographically associated with it,(iii) each PAC contains initiator qualifier attributes corresponding to the initiator entity or entities entitled to use the PAC,(iv) when the verification means receives a PAC for verification, the verification means (18) checks whether the initiator qualifier attributes in the PAC match those associated with the key used to communicate with the verification means.
  2. 3
    A system according to either preceding Claim wherein said initiator entities include at least one user sponsor unit for acting on behalf of a particular end user to provide an interface between the user and the system.
  3. 4
    A system according to any preceding Claim wherein said target entities include at least one application program.
  4. 5
    A method of operating data processing system in which a plurality of initiator entities can access a plurality of target entities, the method comprising:- (a) issuing privilege attribute certificates (PACs) to the initiator entities, each PAC containing initiator qualifier attributes corresponding to the initiator entity entitled to use the PAC,(b) issuing cryptographic keys to the initiator entities, each said key having initiator qualifier attributes of the initiator entity cryptographically associated with it, and(c) checking whether the initiator qualifier attributes in a PAC match those associated with the key used to communicate the PAC.