EP1415212A2

Modular authentication and authorization scheme for internet protocol

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 11 July 2022, 4.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

22 claims: 3 independent, 19 dependent

  1. 1
    Claims of equivalent WO 03007102 A2 WHAT IS CLAIMED IS:1. A system for authentication and authorization, comprising: (a) an authorizer configured to determine if a requestor is authorized to access a resource associated with a request;(b) a client that is an Internet Protocol version 6 (IPv6) host, wherein the client is configured to make the request;and (c) a local attendant that is accessible to the authorizer and the client and that provides a conduit through which messages between the client and the authorizer pass, wherein the authorizer, the client, and a peer on which the resource may be accessed are each in separate domains, wherein each domain is defined as a set of one or more entities such that if the set includes more than one entity, a connection between any two of the entities in the set can be secured by static credentials that are known by each ofthe two entities.
  2. 16
    A method for authentication and authorization, comprising:(a) sending an identity associated with a client to an authorizer, wherein the identity is sent using Internet Protocol version 6 (IPv6);(b) generating, by the authorizer, a challenge that is calculated using the client identity;(c) sending the challenge to the client;(d) generating, by the client, a response employing the client identity and the challenge;(e) sending the response to the authorizer;(f) comparing, by the authorizer, the challenge to the client response;(g) transferring, by the authorizer, a key to a device providing a service to the client;and (h) automatically generating a copy of the key for use by the client by employing a subscriber identity module (SIM) associated with the client.
  3. 22
    A system for authenticating and authorization, comprising:(a) means for determining if a requestor is authorized to access a resource associated with a request;(b) means for requesting access to the resource;(c) means for passing messages between the requestor and the determining means, wherein the determining means, the requesting means, and the message passing means are each in a separate domain, wherein each domain is defined as a set of one or more entities such that if the set includes more than one entity, a connection between any two ofthe entities in the set can be secured by static credentials that are known by each ofthe two entities.