EP1162780A2

System and method for cross directory authentication in a public key infrastructure

Abstract

System and method for cross directory authentication in a Public Key Infrastructure. A first directory is configured to query a second directory when receiving queries regarding signature certificates from a second enterprise PKI. The first directory is part of a first enterprise PKI, and the second directory is part of the second enterprise PKI. Access to a first enterprise PKI server is attempted by a user. The user presents a signature certificate from the second enterprise PKI to the server for authentication. A query is sent to the first directory from the server to determine if the user is allowed access to the server. A query is sent to the second directory from the first directory to determine if the user is a member of the second enterprise PKI. The server approves access to the server if the user is a member of the second enterprise PKI.

EP1162780A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 31 May 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 3 independent, 7 dependent

  1. 1
    A method for cross directory authentication in a Public Key Infrastructure (PKI) comprising:configuring a first directory to query a second directory when receiving queries regarding signature certificates from a second enterprise PKI, the first directory being part of a first enterprise PKI, the second directory being part of the second enterprise PKI;attempting access to a server by a user, the server being part of the first enterprise PKI, the user presenting a signature certificate from the second enterprise PKI to the server for authentication;sending a query to the first directory from the server to determine if the user is allowed access to the server;sending a query to the second directory from the first directory to determine if the user is a member of the second enterprise PKI;and signaling the server by the first directory that the user is allowed access to the server if the user is a member of the second enterprise PKI.
  2. 6
    A system for cross directory authentication in a Public Key Infrastructure (PKI) comprising:at least one server, the at least one server being part of a first enterprise PKI;at least one client platform, the at least one client platform usable by at least one user to request access to the at least one server;a second directory, the second directory containing information on at least one user with a signature certificate for a second enterprise PKI, the second directory being part of the second enterprise PKI;and a first directory, the first directory sending a query to the second directory when receiving a query from at least one server regarding a signature certificate for the second enterprise PKI received at the at least one server from at least one user for authentication, the query from the at least one server sent to the first directory to determine if the at least one user is allowed access to the at least one server, the first directory being part of the first enterprise PKI, the query sent to the second directory from the first directory being sent to determine if the at least one user is a member of the second enterprise PKI, the first directory signaling the at least one server that the at least one user is allowed access to the at least one server if the user is a member of the second enterprise PKI.
  3. 10
    An article comprising a storage medium having instructions stored therein, the instructions when executed causing a processing device to perform:receiving configuration information that causes the processing device to send a query to a directory when receiving queries regarding signature certificates for a second enterprise PKI, the processing device being part of a first enterprise PKI, the directory being part of the second enterprise PKI;receiving a query from a server requesting if a user is allowed access to the server, the server being part of the first enterprise PKI;sending a query to the directory to determine if the user is a member of the second enterprise PKI;and signaling the server that the user is allowed access to the server if the user is a member of the second enterprise PKI.