Logo
About usInnovation CMChallengesEuropa2iEntrepreneurshipR&D&I SearchAgentsEventsReports
en
METHOD FOR MANAGING ACCESS TO PROTECTED RESOURCES AND DELEGATING AUTHORITY IN A COMPUTER NETWORKCM Patents

Índice de la ficha

Updated at
24/07/2026
Numero publicacion
EP.2540051.A1
Fecha publicacion
02/01/2013
Numero solicitud
EP20100707865

En detalle

Resumen

In method; user (100) transmits (s10) represented on commission person (410) access principal's (420) protected resource by described user (100) authorization requests to ISP (200); wherein; described user (100) is representative of consumer access services supplier's (200) software application or web website, and described ISP (200) provides the software application of the access of protected resource or web website.Described ISP (200) transmits (s20) this authorization requests to controller (300).The request token also is transmitted, and this request token is that described ISP (200) is used for the value of mandate of registration request.Described controller (300) determines whether the mandate of (s30) this request satisfies management and control to the strategy setting of the access of principal's protected resource.If meet, then described ISP (200) permits the mandate that the described request token is registered, and the 3rd message that comprises the described request token is transmitted (s50) to described user (100).

Reivindicaciones

1. Method carried out at least by a consumer (100), a service provider (200) and a controller (300), wherein a service provider (200) is at least one of a software application and a web site that is configured to provide access to protected resources; and a consumer (100) is at least one of a software application and a web site that is configured to provide a service to a user, that is configured to access a service provider (200) on behalf of the user, and that is configured to provide the service to the user by integrating the protected resources accessed from the service provider (200); the method including transmitting (s10), by the consumer (100) to the service provider (200), a first message representing a request for authorization to access by the consumer (100) on behalf of a first user, here referred to as delegatee (410), the protected resources of a second user, here referred to as delegator (420), from the service provider (200); transmitting (s20), by the service provider (200) to the controller (300), a second message representing the request for authorization to access by the consumer (100) on behalf of the delegatee (410) the protected resources of the delegator (420) from the service provider (200), the second message including a request token, wherein a request token is a value used by a service provider (200) to register a requested authorization to access protected resources; determining (s30), by the controller (300), whether the requested authorization represented by the second message meets policy settings governing the access to protected resources of the delegator (420); if it is determined that the requested authorization meets the policy settings, granting (s40), by the service provider (200), the authorization registered by the request token, and transmitting (s50), by at least one of the controller (300) and the service provider (200), to the consumer (100), a third message including the request token; accessing, by the consumer (100), on behalf of the delegatee (410), the protected resources of the delegator (420) from the service provider (200), the consumer (100) using the request token to do so; and providing, by the consumer (100), a service to the delegatee (410) by integrating the protected resources accessed from the service provider (200). 2. Method of claim 1, further including, before the step of transmitting (s10), by the consumer (100) to the service provider (200), the first message, transmitting (s5), by at least one of a software application and a physical device controlled by the delegatee (410), to the consumer (200), a request for a service involving access by the consumer (100) on behalf of the delegatee (410) to the protected resources of the delegator (420) from the service provider (200). 3. Method of claim 1 or 2, wherein the step of transmitting (s10), by the consumer (100) to the service provider (200), the first message includes transmitting (s10) the first message by the consumer (100) to the service provider (200) through at least one of a software application and a physical device controlled by the delegatee (410). 4. Method according to any one of the preceding claims, further including, between the steps of determining (s30), by the controller (300), whether the requested authorization represented by the second message meets policy settings governing the access to protected resources of the delegator (420), and granting (s40), by the service provider (200), the authorization registered by the request token, and, if it is determined that the requested authorization meets the policy settings, transmitting (s32), from the controller (300) to the service provider (300), a message indicating that the requested authorization represented by the second message can be accepted. 5. Method according to any one of the preceding claims, further including, between the steps of granting (s40), by the service provider (200), the authorization registered by the request token, and transmitting (s50), by at least one of the controller (300) and the service provider (200), to the consumer (100), the third message including the request token; transmitting (s45), from the service provider (200) to the controller (300), a message including the request token for which the authorization has been granted. 6. Method according to any one of the preceding claims, wherein the step of transmitting (s50), to the consumer (100), the third message including the request token is performed from the controller (300). 7. Method according to any one of the preceding claims, wherein the controller (300) includes a delegation assistant (310) being executed on behalf of the delegatee (410), and a delegation assistant (320) being executed on behalf of the delegator (420), wherein a delegation assistant (310, 320) is at least one of a software application and a physical device. 8. Method according to any one of the preceding claims, wherein determining (s30), by the controller (300), whether the requested authorization represented by the second message meets policy settings governing the access to protected resources of the delegator (420) includes extracting (s301) from the second message at least one of information about the consumer (100) from which the requested authorization originates; information about the delegatee (410) on behalf of which the consumer (100) requests authorization to access the protected resources of the delegator (420); information about the protected resources on which one or more operations are requested to be authorized by means of the request token; and information about the one or more operations which are requested to be authorized by means of the request token; and determining (s302) whether the extracted information meets the policy settings. 9. Delegation assistant (320) including a receiver (25) configured for receiving, from another delegation assistant (310), a message, here referred to as request message, representing a request for authorization to access by a consumer (100) on behalf of a first user, here referred to as delegatee (410), the protected resources of a second user, here referred to as delegator (420), from the service provider (200), the request message including a request token, wherein a service provider (200) is at least one of a software application and a web site that is configured to provide access to protected resources; a consumer (100) is at least one of a software application and a web site that is configured to provide a service to a user, that is configured to access a service provider (200) on behalf of the user, and that is configured to provide the service to the user by integrating the protected resources accessed from the service provider (200); and a request token is a value used by a service provider (200) to register a requested authorization to access protected resources; a determiner (30) configured for determining whether the requested authorization represented by the request message meets policy settings governing the access to protected resources of the delegator (420); and, a transmitter (32) configured for, if it is determined that the requested authorization meets the policy settings, transmitting, to the service provider (200), a response message indicating that the requested authorization represented by the request message can be granted. 10. Delegation assistant (320) of claim 9, wherein the determiner (30) includes an extracter (301) configured for extracting from the request message at least one of information about the consumer (100) from which the requested authorization originates; information about the delegatee (410) on behalf of which the consumer (100) requests authorization to access the protected resources of the delegator (420); information about the protected resources on which one or more operations are requested to be authorized by means of the request token; and information about the one or more operations which are requested to be authorized by means of the request token; and a sub-determiner (302) configured for determining whether the extracted information meets the policy settings. 11. Delegation assistant (320) of claim 9 or 10, configured to be executed in parallel to a browser. 12. Delegation assistant (320) of claim 11, configured to be executed in parallel to a browser as an add-on to the browser. 13. Delegation assistant (320) of claim 9 or 10, configured to be executed on a server. 14. Delegation assistant (310, 320) according to any one of claims 9 to 13, wherein the transmitter (32) is further configured for transmitting, to the other delegation assistant (310, 320) or to yet another delegation assistant (320), a message, here referred to as second request message, representing a request for authorization to access by the consumer (100) or another consumer (100) on behalf of the second user the protected resources of the first user or of a third user, here referred to as second delegator, from the service provider (200) or from another servicer provider, wherein the request message includes another request token. 15. Computer program including instructions configured, when executed on a server or on a computer, to cause the server or the computer respectively to operate as a delegation assistant as defined in any one of claims 9 to 14.

Etiquetas

Inventores
Monjas Llorente Miguel AngelDel Alamo Ramiro Jose MariaYelmo Garcia Juan CarlosDel Alamo Ramir Jose MariaDel Álamo Ramiro José María
Solicitantes
Ericsson Telefon Ab L MUniversidad Politécnica de MadridTelefonaktiebolaget Lm Ericsson (PublTelefonaktiebolaget L M Ericsson (PublMonjas Llorente Miguel AngelDel Alamo Ramir Jose MariaYelmo Garcia Juan CarlosDel Álamo Ramiro José María
Clasificacion ipc
H04L 29/ 06 A IG06F 21/ 00 A I
Clasificacion cpc
726/4
Logo

Innovation CM
Challenges
Europa2i
Entrepreneurship
R&D&I Search
Agents
Events
Reports
About us
Contact
Give us your opinion
Cookies
Legal notice
Privacy

© Copyright Espacio Madrileño de Investigación e Innovación 2026