Invention Grant
- Patent Title: Controlling exposure of sensitive data and operation using process bound security tokens in cloud computing environment
-
Application No.: US15620660Application Date: 2017-06-12
-
Publication No.: US10341109B2Publication Date: 2019-07-02
- Inventor: John Y-C. Chang , Ching-Yun Chao , Bertrand Be-Chung Chiu , Ki H. Park
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Robert H. Frantz; Scott S. Dobson
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L29/06

Abstract:
Exposure of sensitive information to users is controlled using a first security token containing user identity and user credentials to represent the user who requests services, and a second security token containing two other identities, one identifying the token issuer and the other identifying the owning process. When requesting services, the token-owning process sends a security token to indicate who is making the request, and uses its key to digitally sign the request. The token-owning process signs the request to indicate that it endorses the request. A receiving server accepts a request if (1) the token-owning process endorses the request by signing the request; (2) the token is valid (token is signed by its issuer and the digital signature is verified and unexpired); (3) user entity, which can be a real user or a deployment or a server process, that is represented by the token has the authorization to access the specified resources; and (4) the token-owning process is authorized to endorse the user entity represented by the token to access the specified resources.
Public/Granted literature
Information query