Nova Patents
IL201728A

Cascading authentication system

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

19 claims: 3 independent, 16 dependent

  1. 1
    201,728/2 CLAIMS 1. A method for authenticating a user to a target server, the method comprising the steps of:receiving, by a computer system having at least one processor coupled to memory, a request from a user computer system to authenticate the user for access to a target server at level N of N levels, wherein N is a positive integer of at least 2, wherein N target servers are sequentially nested at respective levels of the N levels denoted as levels 1 through N sequenced from lowest level to highest level, and wherein authentication of the user for access to the target server at level N requires prior authentication of the user for access to the target server at level 1 if N is 2 or for access to the N-l target servers at the respective levels 1 through N-l if N is at least 3;determining, by the computer system, that an authentication plan is required to authenticate the user for access to the target server at level N, wherein the authentication plan comprises one or more defined authentication steps that must be performed before the user is allowed to authenticate for access to the target server at level N;in response to the step of determining that the authentication plan is required to authenticate the user for access to the target server at level N, accessing, by the computer system, a stored authentication plan associated with the user, the stored authentication plan having one or more authentication records each having expected information relating to authentication of the user for access to the N-l target servers at the respective levels 1 through N-l;receiving, by the computer system, a current authentication plan for the user from a storage device, the current authentication plan having one or more authentication records each having current information relating to authentication of the user for access to the N-l target servers at the respective levels 1 through N-l;comparing, by the computer system, the stored authentication plan with the current authentication plan to determine, based on analyzing authentication events, whether there is at least a partial match between the stored authentication plan and the current authentication plan;and authenticating, by the computer system, the user at level N if said comparing the stored authentication plan with the current authentication plan determines that there is at least the partial match between the stored authentication plan and the current authentication plan. 21 201,728/2
  2. 10
    A computer program product for authenticating a user to a target server, the computer program product comprising one or more computer readable storage devices; program instructions, stored on at least one of the one or more storage devices, adapted to perform, when the program is executed on a computer, the steps of:22 201,728/2 receiving a request from a user computer system to authenticate the user for access to a target server at level N of N levels, wherein N is a positive integer of at least 2, wherein N target servers are sequentially nested at respective levels of the N levels denoted as levels 1 through N sequenced from lowest level to highest level, and wherein authentication of the user for access to the target server at level N requires prior authentication of the user for access to the target server at level 1 if N is 2 or for access to the N-l target servers at the respective levels 1 through N-l if N is at least 3;determining that an authentication plan is required to authenticate the user for access to the target server at level N, wherein the authentication plan comprises one or more defined authentication steps that must be performed before the user is allowed to authenticate for access to the target server at level N;in response to determining that the authentication plan is required, to authenticate the user for access to the target server at level N, accessing a stored authentication plan associated with the user, the stored authentication plan having one or more authentication records each having expected information relating to authentication of the user for access the N-l target servers at the respective levels 1 through N-l;receiving a current authentication plan for the user from a storage device, the current authentication plan having one or more authentication records each having current information relating to authentication of the user for access to the N-l target servers at the respective levels 1 through N-l;comparing the stored authentication plan with the current authentication plan to determine based on analyzing authentication events, whether there is at least a partial match between the stored authentication plan and the current authentication plan;and authenticating the user, at level N if a comparison of the stored authentication plan with the current authentication plan determines that there is at least the partial in response to a match between the stored authentication plan and the current authentication plan.
  3. 19
    A system for authenticating a user to a target server, the system comprising:a target server at level N of N levels, wherein N is a positive integer of at least 2, wherein N target servers are sequentially nested at respective levels of the N levels denoted as levels 1 through N sequenced from lowest level to highest level, and wherein authentication of the user for access to the target server at level N requires prior authentication of the user for access to the target server at level 1 if N is 2 or for access to the N-l target servers at the respective levels 1 24 201,728/2 through N-l if N is at least 3, the target server at level N having an authentication plan manager operable to access a stored authentication plan associated with a user requesting access to the target server, the stored authentication plan comprising one or more authentication records each having expected data associated with access by the user to the N-l target servers at the respective levels 1 through N-l;an authentication store operable to store a current authentication plan associated with the user, the current authentication plan comprising one or more authentication records each having current data associated with access by the user to the N-l target servers at the respective levels 1 through N-l;an authentication store manager operable to communicate with the target server and the authentication store and operable to provide the current authentication plan associated with a particular user to the authentication plan manager of the target server;and wherein the authentication plan manager of the target server is operable to determine whether to authenticate a user based on a comparison between the stored authentication plan and the current authentication plan. 25