EP1560394B1

Techniques for dynamically establishing and managing authentication and trust relationships

Abstract

This record has no abstract on file.

EP1560394B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 8 December 2024, 1.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

31 claims: 3 independent, 28 dependent

  1. 1
    A computer-implemented method for authenticating a principal, comprising:receiving (110) an access request from a first principal for access to a second principal;evaluating (120) a contract to acquire a credential for the first principal, wherein the contract is a data structure which identifies identifier information for the first principal and an authentication technique for the first principal to authenticate to the second principal;and transmitting (130) the credential to the first principal for use (170) in interacting with the second principal, wherein the credential includes authentication information, characterized in that the contract includes directives that permit attribute information and policies of the first principal to be assembled from a variety of data stores into aggregated attributes and aggregated policies for use by the first principal in interacting directly with the second principal.
  2. 16
    A computer-networked principal authentication system (300), comprising:a first principal service (310);a second principal service (320);and an identity service (330), wherein the identity service acquires and manages a first contract on behalf of the first principal service and a second contract on behalf of the second principal service, and wherein the identity service provides a first credential to the first principal service and a second credential to the second principal service, the credentials used by the first principal service and the second principal service to interact with one another, characterized in that the first and second contracts are data structures which identify identifier information for the first and second principals, respectively, and wherein first and second contracts further identify directives for aggregating attribute information and policies from a variety of data stores for each of the principals.
  3. 31
    A computer program product which when executing on a computer network performs the method of any one of claims 1 to 15.