EP1531377A2

Secure authentication of an executable by an authentication entity

Abstract

A resource is obtained from a resource provider (RP) for a resource requester (RR) operating on a computing device. The RR has an identity descriptor (id) associated therewith, where the id including security-related information specifying an environment in which the RR operates. A code identity (code-ID) is calculated corresponding to and based on the loaded RR and loaded id. The RP verifies that the calculated code-ID in a request for the resource matches one of one or more valid code-IDs for the identified RR to conclude that the RR and id can be trusted, and the RP responds to the forwarded request by providing the requested resource to the RR.

EP1531377A2, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 2 September 2024, 2.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

36 claims: 4 independent, 32 dependent

  1. 1
    A method of obtaining a resource from a resource provider for a resource requester operating on a computing device, the resource requester having an identity descriptor associated therewith, the identity descriptor including security-related information specifying an environment in which the resource requester operates, the method comprising:loading the resource requester onto the computing device;loading the identity descriptor corresponding to the resource requester onto the computing device;providing the resource requester with a reference to the loaded identity descriptor;calculating a code identity corresponding to and based on the loaded resource requester and loaded identity descriptor;receiving a request from the resource requester for the resource;ascertaining that the requesting resource requester has rights to the resource and is to be trusted with the resource;forwarding the request for the resource from the resource requester to the resource provider, the forwarded request including the calculated code identity for the requesting resource requester, the identity descriptor for the requesting resource requester, and a definition of the resource requested by the resource requester, the resource provider verifying that the calculated code identity in the forwarded request matches one of one or more valid code identities for the identified resource requester, concluding based thereon that the resource requester can be trusted as being a known resource requester that can be presumed to be trustworthy, and also that the security-related information upon which the resource requester operates is known security-related information that can be presumed to be trustworthy, and responding to the forwarded request by providing the requested resource;receiving, by the resource requester, the requested resource as provided by the resource provider, and employing same in a manner consistent with the trust imparted to the resource requester by the resource provider, and in accordance with the security-related information set forth in the identity descriptor corresponding to the resource requester.
  2. 9
    A method of providing a resource by a resource provider to a resource requester operating on a computing device, the resource requester having an identity descriptor associated therewith, the identity descriptor including security-related information specifying an environment in which the resource requester operates, the method comprising:receiving a forwarded request from the resource requester for the resource, the forwarded request including a code identity calculated for the requesting resource requester, the calculated code identity corresponding to and based on the resource requester and the identity descriptor as loaded on the computing device, the forwarded request also including the identity descriptor for the requesting resource requester and a definition of the resource requested by the resource requester;verifying the received request;obtaining the code identity, the identity descriptor, and the definition of the resource requested from the received request;determining from the received request an identity of the requesting resource requester;obtaining each of one or more valid code identities for the identified resource requester;verifying that the calculated code identity in the received request matches one of one or more valid code identities for the identified resource requester and concluding based thereon that the resource requester can be trusted as being a known resource requester that can be presumed to be trustworthy, and also that the security-related information upon which the resource requester operates is known security-related information that can be presumed to be trustworthy;responding to the forwarded request by providing the requested resource to the resource requester, the resource requester receiving the requested resource as provided by the resource provider and employing same in a manner consistent with the trust imparted to the resource requester by the resource provider, and in accordance with the security-related information set forth in the identity descriptor corresponding to the resource requester.
  3. 19
    A computer-readable medium having stored thereon computer-executable instructions for performing a method of obtaining a resource from a resource provider for a resource requester operating on a computing device, the resource requester having an identity descriptor associated therewith, the identity descriptor including security-related information specifying an environment in which the resource requester operates, the method comprising:loading the resource requester onto the computing device;loading the identity descriptor corresponding to the resource requester onto the computing device;providing the resource requester with a reference to the loaded identity descriptor;calculating a code identity corresponding to and based on the loaded resource requester and loaded identity descriptor;receiving a request from the resource requester for the resource;ascertaining that the requesting resource requester has rights to the resource and is to be trusted with the resource;forwarding the request for the resource from the resource requester to the resource provider, the forwarded request including the calculated code identity for the requesting resource requester, the identity descriptor for the requesting resource requester, and a definition of the resource requested by the resource requester, the resource provider verifying that the calculated code identity in the forwarded request matches one of one or more valid code identities for the identified resource requester, concluding based thereon that the resource requester can be trusted as being a known resource requester that can be presumed to be trustworthy, and also that the security-related information upon which the resource requester operates is known security-related information that can be presumed to be trustworthy, and responding to the forwarded request by providing the requested resource;receiving, by the resource requester, the requested resource as provided by the resource provider, and employing same in a manner consistent with the trust imparted to the resource requester by the resource provider, and in accordance with the security-related information set forth in the identity descriptor corresponding to the resource requester.
  4. 27
    A computer-readable medium having stored thereon computer-executable instructions for performing a method of providing a resource by a resource provider to a resource requester operating on a computing device, the resource requester having an identity descriptor associated therewith, the identity descriptor including security-related information specifying an environment in which the resource requester operates, the method comprising:receiving a forwarded request from the resource requester for the resource, the forwarded request including a code identity calculated for the requesting resource requester, the calculated code identity corresponding to and based on the resource requester and the identity descriptor as loaded on the computing device, the forwarded request also including the identity descriptor for the requesting resource requester and a definition of the resource requested by the resource requester;verifying the received request;obtaining the code identity, the identity descriptor, and the definition of the resource requested from the received request;determining from the received request an identity of the requesting resource requester;obtaining each of one or more valid code identities for the identified resource requester;verifying that the calculated code identity in the received request matches one of one or more valid code identities for the identified resource requester and concluding based thereon that the resource requester can be trusted as being a known resource requester that can be presumed to be trustworthy, and also that the security-related information upon which the resource requester operates is known security-related information that can be presumed to be trustworthy;responding to the forwarded request by providing the requested resource to the resource requester, the resource requester receiving the requested resource as provided by the resource provider and employing same in a manner consistent with the trust imparted to the resource requester by the resource provider, and in accordance with the security-related information set forth in the identity descriptor corresponding to the resource requester.