IL144902A

Trust negotiation in a client/server data processing network using automatic incremental credential disclosure

Abstract

In client/server computing, especially in the field of e-commerce, digitally signed credentials are passed between client and server to develop trust between the parties. However, this requires that one party disclose its credentials (which could be considered sensitive) to the other party before the disclosing party knows anything about the receiving party (someone has to go first). To solve this problem, the invention implements a negotiation of credential disclosure called automatic incremental credential disclosure. Each credential held at a local site is associated with an access policy which is based on opposing site credentials. Incoming requests for credentials are logically combined with the access policies to derive further negotiation responses.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

16 claims: 2 independent, 14 dependent

  1. 1
    20 CLAIMS We claim:1. A data processing system for use in a client/server network where a client data 5 processing apparatus sends a data processing request to a server data processing apparatus and the server data processing apparatus performs data processing based on the request and returns a reply to the client data processing apparatus, the data processing system comprising: storage means for storing a plurality of local site credentials;10 means for receiving a first credentials request from an opposing site data processing apparatus, the credentials requested by the first credentials request being local site credentials stored in the storage means that satisfy a first logical expression provided with the first credentials request;and means for sending to the opposing site data processing apparatus a second 15 credentials request which is dependent upon the contents of the first credentials request, the credentials requested by the second credentials request being opposing site credentials that satisfy a second logical expression provided with the second credentials request.
  2. 9
    A method of operating a data processing apparatus for use in a client/server network where a client data processing apparatus sends a data processing request to a server data processing apparatus and the server data processing apparatus performs data processing based on the request and returns a reply to the client data processing apparatus, the data processing apparatus comprising a storage means for storing a plurality of local site credentials, the method comprising steps of:receiving a first credentials request from an opposing site data processing apparatus, the credentials requested by the first credentials request being local site credentials stored in the storage means that satisfy a first logical expression provided with the first credentials request;and sending to the opposing site data processing apparatus a second credentials request which is dependent upon the contents of the first credentials request, the credentials requested by the second credentials request being opposing site credentials that satisfy a second logical expression provided with the second credentials request.