Nova Patents
EP0513484A2

Digital network access authorisation.

Abstract

In a distributed data system serving a large geographical area and having several network management systems, each for managing system components in a portion of the geographical area, the system including a number of workstations at which administrative commands for configuring or monitoring the network may be entered, each network management system and each workstation hosting a number of software processes, a method is provided of storing in the network management systems and not in the workstations the information required to determine that an operator at a workstation is authorized to access the network, rendering such information less susceptible of tampering. The trusted system appends to each request from a workstation the operator's user identification, account number, and corporate affiliation; process to which such requests are routed for disposition may perform checks regarding the appropriateness of fulfilling the request in light of these parameters. Workstations not originating any messages for a predetermined time are automatically logged off to reduce the possibility of unauthorized persons entering requests at a logged-on workstation whose operator has left the vicinity.

EP0513484A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 27 February 2012, 14.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

6 claims: 2 independent, 4 dependent

  1. 1
    In a distributed digital data network comprising a plurality of interconnected control nodes with one of more workstations connected to each control node, the control nodes being responsive to requests entered at the workstations by operators, each of whom has logged on to the network by identifying himself and providing a password matching a password prestored for him, the control nodes being located in controlled-access trusted facilities and the workstations being located in untrusted facilities, a method of enhancing network security comprising the steps of:entering and storing a prestored password for an operator at a trusted facility;and    forwarding from a workstation to a control node at a trusted facility a password provided by an operator attempting to log on and performing comparison with a password prestored for that operator within the control node at the trusted facility.
  2. 3
    In a distributed digital data network comprising a plurality of interconnected control nodes with one of more workstations connected to each control node, the control nodes being responsive to requests entered at the workstations by operators, each of whom has logged on to the network by identifying himself and providing a password matching a password prestored for him, the control nodes being located in controlled-access trusted facilities and the workstations being located in untrusted facilities,    each control node is controlled by software organized as a plurality of processes, and a first certain process in each control node receives requests from workstations and forwards requests to second processes for disposition,    a method of enhancing network security comprising the steps of:entering and storing a prestored password for an operator at a trusted facility;forwarding from a workstation to a control node at a trusted facility a password provided by an operator attempting to log on and performing comparison with a password prestored for that operator within the control node at the trusted facility;storing with each operators prestored password his account number, his user identification, and his corporate affiliation;retrieving each operators password, user account number, user identification, and corporate affiliation responsive to the first certain process upon its receipt of a request from an operator;forwarding to the second process the user account number, user identification, and corporate affiliation along with a request from an operator;and    verifying in the second process that the action requested is appropriate to the user account number, user identification, and corporate affiliation.