EP1517510A2

Moving principals across security boundaries without service interruptions

Abstract

An improved network architecture employs a super authority having an identity catalog to direct login authentication tasks to appropriate authorities. Authentication tasks may be performed by authorities across namespace boundaries if so directed by the super authority, such that a principal account may be moved without alteration of the account ID. In an embodiment of the invention, the identity catalog comprises a listing associating account IDs with appropriate authenticating authorities.

EP1517510A2, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 13 May 2024, 2.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

25 claims: 5 independent, 20 dependent

  1. 1
    A method of authenticating a principal in a network environment for access to secured resources comprising:receiving at an authority a login request from the principal, wherein the login request comprises an account identifier;transmitting the account identifier from the receiving authority to a super authority for identification of an authority that is authorized to authenticate the principal;andauthenticating the principal at the receiving authority if a transmission is received at the receiving authority from the super authority indicating that the receiving authority is authorized to authenticate the principal, and otherwise abstaining from authentication of the principal.
  2. 4
    A controlling authority for identifying an authenticating authority for authenticating a principal for access to network resources comprising:an identity catalog mapping at least one account ID of at least one principal to an identifier of a corresponding authenticating authority;andan authority resolution module for accessing the identity catalog to match the account ID with a corresponding authenticating authority and for causing an authentication request to be directed to the corresponding authenticating authority.
  3. 11
    A method of controlling authentication of principals for access to network resources in a network environment comprising:receiving a request for an authenticating authority resolution from one of a plurality of authenticating authorities, wherein the request comprises an account ID of a principal to be authenticated;accessing an assignment mapping of a plurality of account IDs to a corresponding plurality of authenticating authorities and locating within the mapping the account ID of the principal to be authenticated;locating within the mapping an identity of an assigned authenticating authority that is mapped to the account ID of the principal to be authenticated;andcausing an authentication request to be transmitted to the assigned authenticating authority, wherein the request asks the assigned authenticating authority to authenticate the principal to be authenticated.
  4. 17
    An apparatus for controlling authentication of principals for access to network resources in a network environment comprising:means for receiving a request for an authenticating authority resolution from one of a plurality of authenticating authorities, wherein the request comprises an account ID of a principal to be authenticated;means for accessing an assignment mapping of a plurality of account IDs to a corresponding plurality of authenticating authorities and for locating within the mapping the account ID of a principal to be authenticated;means for locating within the mapping an identity of an assigned authenticating authority that is mapped to the account ID of a principal to be authenticated;andmeans for causing an authentication request to be transmitted to the assigned authenticating authority, wherein the request invites the assigned authenticating authority to authenticate the principal to be authenticated.
  5. 21
    A computer-readable medium having thereon computer-executable instructions for performing a method of controlling authentication of principals for access to network resources in a network environment comprising the steps of:receiving a request for an authenticating authority resolution from one of a plurality of authenticating authorities, wherein the request comprises an account ID of a principal to be authenticated;accessing an assignment mapping of a plurality of account IDs to a corresponding plurality of authenticating authorities and locating within the mapping the account ID of a principal to be authenticated;locating within the mapping an identity of an assigned authenticating authority that is mapped to the account ID of a principal to be authenticated;andcausing an authentication request to be transmitted to the assigned authenticating authority, wherein the request asks the assigned authenticating authority to authenticate the principal to be authenticated.