Claims
- 1. A method for providing secure access to resources controlled by a server entity, said method comprising the steps within said server entity of:
- receiving a first authorization token from an authorizer entity, said first authorization token being generated by said authorizer entity based on previous communication with a client entity, said server entity, said client entity and said authorizer entity being mutually interconnected; and
- validating a second authorization token to ensure that said client entity is permitted to access said resources by comparing said second authorization token with said first authorization token, said second authorization token being received as part of a request to said server entity from said client entity.
- 2. The method of claim 1 wherein said receiving step comprises receiving a generic authorization token.
- 3. The method of claim 1 wherein said receiving step comprises the step of receiving a reusable authorization token.
- 4. The method of claim 1 wherein said receiving step comprises the step of receiving a single-use authorization token.
- 5. A server entity that provides secure access to resources controlled by said server entity, said server entity comprising:
- a token receiving mechanism that receives a first authorization token from an authorizer entity and a second authorization token from a client entity, said first authorization token being generated by said authorizer entity based on previous communication with said client entity, said server entity, said client entity and said authorizer entity being mutually interconnected; and
- a token validating mechanism, said token validating mechanism ensuring that said client entity is permitted to access said resources by validating said second authorization token through comparison of said second authorization token with said first authorization token.
- 6. The server entity of claim 5 wherein said token receiving mechanism further comprises the capability of receiving a generic authorization token.
- 7. The server entity of claim 5 wherein said token receiving mechanism further comprises the capability of receiving a reusable authorization token.
- 8. The server entity of claim 5 wherein said token receiving mechanism further comprises the capability of receiving a single-use authorization token.
Parent Case Info
This is a divisional of application Ser. No. 08/324,289 filed on Oct. 17, 1994, which is a continuation of Ser. No. 07/943,654 filed on Sep. 11, 1992, abandoned.
US Referenced Citations (9)
Non-Patent Literature Citations (3)
Entry |
Kerberos Version 5 RFC, Draft #4. |
"TeleTrusT-OSIS and Communication Security", Karl Rihaczek. |
"The Three-Headed Dog", Westlake Notes, May 31, 1990. |
Divisions (1)
|
Number |
Date |
Country |
Parent |
324289 |
Oct 1994 |
|
Continuations (1)
|
Number |
Date |
Country |
Parent |
943654 |
Sep 1992 |
|