Remotable information cards
Abstract
An accessor function interfaces among a client, a relying party, and an identity provider. The identity provider can “manage” personal (i.e., self-asserted) information cards on behalf of a user, making the personal information cards available on clients on which the personal information cards are not installed. The client can be an untrusted client, vulnerable to attacks such as key logging, screen capture, and memory interrogation. The accessor function can also asked as a proxy for the relying party in terms of invoking and using the information cards system, for use with legacy relying parties.
Claims
exact text as granted — not AI-modified1 . A method, comprising:
identifying a request of a resource of a legacy relying party received from a client, the legacy relying party not designed to use a security token; requesting the security token from the client; and using the security token on behalf of the user to access the resource.
2 . A method according to claim 1 , wherein using the security token on behalf of the user includes filling out a form on a website of the legacy relying party.
3 . A method according to claim 1 , wherein using the security token on behalf of the user includes authenticating the user to the legacy relying party.
4 . A method according to claim 1 , wherein using the security token on behalf of the user includes populating an LDAP store used by the legacy relying party.
5 . A method according to claim 1 , wherein:
identifying a request of a resource of a legacy relying party received from a client includes identifying a request of a resource of a legacy relying party received from an untrusted client; and requesting the security token from the untrusted client.Join the waitlist — get patent alerts
Track US2013014245A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.