EP1473618A2

Uniform modular framework for a host computer system

Abstract

A security framework for a host computer system (105) which allows a host to control access to a compliant security token (75) by ensuring enforcement of established security policies administered by a middleware application. Processing between the host computer system (105) and the security token (75) is performed using one or more modular security application agents. The modular security application agents are counterpart applications to security applications installed in the security token (75) and may be retrieved and installed upon to ensure compatibility between counterpart token and host security applications. The security policies (152C) are a composite of host security policies (152) and token security policies (184) which are logically combined by the middleware application at the beginning of a session.

EP1473618A2, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Projected expiry passed 27 April 2024, 2.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

44 claims: 9 independent, 35 dependent

  1. 1
    A system which provides a modular uniform security applications framework for a host computer system (105) and a compliant security token (75) in processing communications with the host computer system (105) comprising:said compliant security token (75) including a set of retrievable token security policies (184) and one or more token security applications (186, 188, 192, 194, 198);said host computer system (105) including a retrievable set of host security policies (152) and a token access control application (142), wherein said token access control application (142) includes means for;retrieving at least a portion of said host security policies (152) from said host computer system (105),       retrieving at least a portion of said token security policies (184) from said compliant security token (75),       generating a composite set of security policies from said host security policies (152) and said token security policies (184), and       ensuring enforcement of said composite set of security policies on a request to perform a security function using said compliant security token (75).
  2. 9
    A system which provides a modular uniform security applications framework for a host computer system (105) and a compliant security token (75) in processing communications with the host computer system (105) comprising:said compliant security token (75) including a set of retrievable token security policies (184) and one or more token security applications (186, 188, 192, 194, 198);said host computer system (105) including a token access control application (142), a retrievable set of host security policies (152) and at least one security application agent functionally associated with said token access control application (142);said token access control application (142) including means for;retrieving at least a portion of said host security policies (152) from said host computer system (105),       retrieving at least a portion of said token security policies (184) from said compliant security token (75),       generating a composite set of security policies from said host security policies (152) and said token security policies (184), and       transferring at least a portion of said composite set of security policies to said at least one of security application agent.
  3. 13
    A system which provides a modular uniform security applications framework for a host computer system (105) and a compliant security token (75) in processing communications with the host computer system (105) comprising:said compliant security token (75) including a set of retrievable token security policies (184) and one or more token security applications (186, 188, 192, 194, 198);said host computer system (105) including a requesting application, a token access control application (142), a retrievable set of host security policies (152) and at least one security application agent functionally associated with said token access control application (142);said token access control application (142) including means for;retrieving at least a portion of said host security policies (152) from said host computer system (105),       retrieving at least a portion of said token security policies (184) from said compliant security token (75),       generating a composite set of security policies from said host security policies (152) and said token security policies (184), and       returning at least a portion of said composite set of security policies to said requesting application;said requesting application including means for;generating a request to perform a security function using said compliant security token (75),    ensuring enforcement of said at least a portion of said composite set of security policies, and    causing said at least one security application agent to execute in response to said request;and said at least one security application agent including means for performing a security function with said one or more token security applications (186, 188, 192, 194, 198) in accordance with said at least a portion of said composite set of security requirements.
  4. 17
    A system which provides a modular uniform security applications framework for a host computer system (105) and a compliant security token (75) in processing communications with the host computer system (105) comprising:said compliant security token (75) including a set of retrievable token security policies (184) and one or more token security applications (186, 188, 192, 194, 198);said host computer system (105) including a token access control application (142), a retrievable set of host security policies (152) and at least one security application agent functionally associated with said token access control application (142);said token access control application (142) including means for;retrieving at least a portion of said host security policies (152) from said host computer system (105),       retrieving at least a portion of said token security policies (184) from said compliant security token (75),       generating a composite set of security policies from said host security policies (152) and said token security policies (184),       ensuring enforcement of said composite set of security policies on a request to perform a security function using said compliant security token (75);and    said at least one security application agent, including means for performing said security function with said one or more token security applications (186, 188, 192, 194, 198) in accordance with said composite set of security policies.
  5. 27
    A method for using a modular uniform security applications framework for a host computer system (105) and a compliant security token (75) comprising the steps of:a. receiving (405) a token security function request from a requesting application, b. retrieving (415) a set of token security policies (184), c. retrieving (420) a set of host security policies (152), d. combining (425) said token security policies (184) and said host security policies (152) into a composite security policy, e. ensuring enforcement (430) of said composite security policy on said security function request, f. receiving (450) a credential if required by said composite security policy, g. sending (460) said credential to an appropriate security application agent if required by said composite security policy, h. sending (465) said credential to an appropriate token security application if required by said composite security policy, and i. performing (475) a security function in accordance with said composite security policy.
  6. 28
    A method for using a modular uniform security applications framework for a host computer system (105) and a compliant security token (75) comprising the steps of:a. receiving (412) a token security function request from a requesting application, b. retrieving (418) a set of token security policies (184), c. retrieving (424) a set of host security policies (152), d. combining (432) said token security policies (184) and said host security policies (152) into a composite security policy, e. sending (468) at least a portion of said composite security policy to a appropriate security application agent, f. ensuring (474) enforcement of at least a portion of said composite security policy on said security function request, g. receiving (480) a credential if required by said composite security policy, h. sending (484) said credential to an appropriate token security application if required by said composite security policy, and i. performing (492) a security function in accordance with said composite security policy.
  7. 29
    A method for providing a modular uniform security applications framework for a host computer system (105) and a compliant security token (75) comprising the steps of:a. receiving (407) a token security function request from a requesting application, b. retrieving (411) a set of token security policies (184), c. retrieving (413) a set of host security policies (152), d. combining (419) said token security policies (184) and said host security policies (152) into a composite security policy, e. sending (447) at least a portion of said composite security policy to said requesting application, f. ensuring (449) enforcement of at least a portion of said composite security policy by said requesting application, g. receiving (451) a credential if required by said composite security policy, h. sending said credential to an appropriate security application agent if required by said composite security policy, i. sending (453) said credential to an appropriate token security application if required by said composite security policy, and j. performing (459) a security function in accordance with said composite security policy.
  8. 32
    A system which provides for retrieval of compatibility information associated with one or more counterpart security application agents from a functionally connected security token (75) by at least one security application installed on a host computer system (105) comprising:said functionally connected security token (75) including said retrievable compatibility information and one or more token security applications (186, 188, 192, 194, 198) installed in said functionally connected security token (75), wherein said retrievable capability information relates to compatibility between said one or more counterpart security application agents and said one or more token security applications (186, 188, 192, 194, 198);said host computer system (105) including said one or more counterpart security application agents and said at least one security application, wherein said at least one security application includes means for;retrieving said compatibility information related to said one or more counterpart security application agents;verifying that at least one compatible counterpart security application agent is operatively installed and if not, retrieving and operatively installing at least one compatible counterpart security application agent.
  9. 40
    A method which provides for retrieval of compatibility information related to one or more counterpart security application agents from a functionally connected security token (75) by at least one security application installed on a host computer system (105) comprising the steps of:a. retrieving (473) said compatibility information related to said one or more counterpart security application agents from said functionally connected security token (75), b. verifying (475) that at least one compatible counterpart security application agent is operatively installed on a host computer system (105), and if not, c. retrieving (479) said at least one compatible counterpart security application agent and d. operatively installing (489) said at least one compatible counterpart security application agent on said host computer system (105).