US Patent:
20030070069, Apr 10, 2003
Inventors:
Abhijit Belapurkar - Jersey City NJ, US
Gayathri Krishnamurthy - Jersey City NJ, US
Maneesh Bhandari - Edison NJ, US
International Classification:
H04L009/00
H04L009/32
G06F015/16
US Classification:
713/155000, 713/201000, 709/229000
Abstract:
A pluggable authentication module (PAM) is designed for compatibility with a receiver component. In response to a request for a protected web resource, the receiver component receives a user identification (user ID) from a secure and trusted source; the receiver component need not receive a password corresponding to the user ID. The receiver component generates and sends a login request to the PAM for authentication of the user. The login request contains a representation of the user ID, but is void of a corresponding user password. The receiver component and the PAM perform a trust establishment protocol that enables the PAM to determine whether the login request (and the received user ID) is legitimate.