Federated identity management for data repositories
US-2024348610-A1 · Oct 17, 2024 · US
US9049025B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-9049025-B1 |
| Application number | US-201113164138-A |
| Country | US |
| Kind code | B1 |
| Filing date | Jun 20, 2011 |
| Priority date | Jun 20, 2011 |
| Publication date | Jun 2, 2015 |
| Grant date | Jun 2, 2015 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A server receives encrypted information for an intended recipient. The server determines, based on recipient information, whether the recipient's device is able to decrypt the encrypted information. If so, the encrypted information is provided to the device. Upon determining that the device is unable to decrypt the encrypted information, the server sends a notification message to the device. The notification message indicates that the encrypted message has been received. In response to the notification message, the server receives a response from the device. If the device is successfully authenticated, based on the response, the server decrypts the encrypted information and provides the decrypted information to the device for presentation to the recipient.
Opening claim text (preview).
We claim: 1. A method comprising: receiving, by a server, registration information of a plurality of devices, including information indicating whether each device is a secure device having encryption and decryption capabilities or a non-secure device not having encryption and decryption capabilities; distributing, by a key management server, to the server and to the secure devices, respective encryption and decryption keys; receiving, in the server, information encrypted by and sent from one of the secure devices to an intended recipient device through a communication network, the encrypted information being accompanied with information identifying the intended recipient and the encrypted information being encrypted using the respective secure device encryption key that is different from the encryption keys used by other secure devices; determining in the server, based on the recipient information and the registration information, whether a device of the intended recipient is a secure or a non-secure device; and upon determining that the intended recipient device is a non-secure device: storing the encrypted information with a reference identifier identifying the encrypted information; sending a notification message to the intended recipient device, the notification message including: (a) a flag indicating that the server received the encrypted information addressed to the intended recipient device and, (b) the reference identifier; receiving a response to the notification message from the intended recipient device, the response including the reference identifier and a token acquired by the intended recipient device from an authentication and authorization system connected to the communication network via direct communication between the intended recipient device and the authentication and authorization systems, wherein the authentication and authorization system is different from the server; after receiving the response, authenticating the intended recipient device by the server, based on the token received in the response to the notification message by communicating with the authentication and authorization system through the communication network; decrypting the encrypted information identified by the reference identifier included in the response using the decryption key of the secure device wherein the decryption key of the secure device is different from the token; establishing, by the server, a secured network connection between the server and the intended recipient device; and sending the decrypted information, to the intended recipient device, via the established secured network connection; wherein at least one of the decrypting and sending steps is responsive to the server determining, based on the communication with the authentication and authorization system, that the token is valid. 2. The method of claim 1 , wherein the intended recipient device is a mobile phone. 3. The method of claim 2 , wherein the recipient information includes a mobile directory number of the mobile phone. 4. The method of claim 1 , wherein: the notification message includes: a network address which is sent to the intended recipient device for responding to the notification message and from which the intended recipient device receives the decrypted information. 5. The method of claim 4 , wherein to the sending of the network address to the intended recipient device is via the established secured network connection. 6. The method of claim 4 , wherein the server finds the encrypted information based on the reference identifier included in the response, and decrypts the found encrypted information. 7. The method of claim 4 , wherein the notification message is sent as a short messaging service (SMS) message. 8. The method of claim 1 , further comprising the server: in response to sending the notification message, receiving an acknowledgment from the intended recipient device; and in response to receiving the acknowledgment, sending a delivery acknowledgment to the respective secure device subscriber. 9. The method of claim 1 , further comprising, the server: receiving non-encrypted information from the intended recipient device; encrypting the non-encrypted information; and sending the encrypted information to a designated receiver device. 10. The method of claim 1 , wherein the token is valid for a limited period of time after the token is acquired by the intended recipient device from the authentication and authorization system via the direct communication and for a single authentication. 11. The method of claim 1 , wherein the token: is valid for a limited period of time after the token is acquired by the intended recipient device from the authentication and authorization system via the direct communication, and includes: a first token that is valid for a first limited period of time and is valid for multiple authentications, and a second token that is valid for a second limited period of time shorter than the first limited period of time and is valid only for a single authentication. 12. A system comprising: an authentication and authorization system; a key management server; a server, configured to be in communication with the authentication and authorization system and the key management server; wherein: the key management server is configured to distribute, to the server and to respective subscribers of the secure devices, respective encryption and decryption keys; and the server is configured to: receive registration information for a plurality of subscriber devices, including information indicating whether each device is a secure device having encryption and decryption capabilities or a non-secure device not having encryption and decryption capabilities; receive information encrypted by and sent from one of the secure devices to an intended recipient through a communication network, the encrypted information being accompanied with information identifying the intended recipient and the encrypted information being encrypted using the respective secure device encryption key that is different from the encryption keys used by other secure devices; determine, based on the recipient information and the registration information, whether a device of the intended recipient of the encrypted information is a secure or a non-secure device; and upon determining that the intended recipient device is a non-secure device: store the encrypted information with a reference identifier identifying the encrypted information; send a notification message to the intended recipient device that includes: (a) a flag which indicates that the server received the encrypted message addressed to the intended recipient device and the reference identifier; receive a response to the notification message from the intended recipient device, the response including the reference identifier and a token acquired by the intended recipient device from the authentication and authorization system connected to the communication network via direct communication between the intended recipient device and the authentication and authorization system, wherein the authentication and authorization system is different from the server; after reception of the response, the server is configured to: authenticate the intended recipient device based on the token received in the response to the notification message by communicating with the authentication and authorization system through the communication network; decrypt the encrypted information identified by the reference identifier included in the response using the decryption key of the secure device and wherein the decryption key of the secur
Electricity · mapped topic
including means for verifying the identity or authority of a user of the system {or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials} · CPC title
Format adaptation, e.g. format conversion or compression · CPC title
of the user plane, e.g. user's traffic · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.