Patents by Inventor Ivan Milman
Ivan Milman has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 8613043Abstract: A method for identity mediation in an enterprise service bus is provided in the illustrative embodiments. A security information is received at the enterprise service bus from a first application executing in a first data processing system. The security information is a part of a request for service from a second application executing in a second data processing system. A part of the security information is identified to be transformed such that the part upon transformation is usable for handling the request by the second application. A security policy applicable to the identified part is selected and the identified part is transformed according to the security policy. The transforming results in a transformed security information. The transformed security information is sent to the second application.Type: GrantFiled: March 6, 2012Date of Patent: December 17, 2013Assignee: International Business Machines CorporationInventors: Dmitriy Fot, Ivan Milman, Martin Oberhofer
-
Patent number: 8321909Abstract: A system, and computer usable program product for identity mediation in an enterprise service bus are provided in the illustrative embodiments. A security information is received at the enterprise service bus from a first application executing in a first data processing system. The security information is a part of a request for service from a second application executing in a second data processing system. A part of the security information is identified to be transformed such that the part upon transformation is usable for handling the request by the second application. A security policy applicable to the identified part is selected and the identified part is transformed according to the security policy. The transforming results in a transformed security information. The transformed security information is sent to the second application.Type: GrantFiled: December 22, 2009Date of Patent: November 27, 2012Assignee: International Business Machines CorporationInventors: Dmitriy Fot, Ivan Milman, Martin Oberhofer
-
Publication number: 20120227082Abstract: A method for identity mediation in an enterprise service bus is provided in the illustrative embodiments. A security information is received at the enterprise service bus from a first application executing in a first data processing system. The security information is a part of a request for service from a second application executing in a second data processing system. A part of the security information is identified to be transformed such that the part upon transformation is usable for handling the request by the second application. A security policy applicable to the identified part is selected and the identified part is transformed according to the security policy. The transforming results in a transformed security information. The transformed security information is sent to the second application.Type: ApplicationFiled: March 6, 2012Publication date: September 6, 2012Applicant: International Business Machines CorporationInventors: Dmitriy Fot, Ivan Milman, Martin Oberhofer
-
Publication number: 20110154435Abstract: A method, system, and computer usable program product for identity mediation in an enterprise service bus are provided in the illustrative embodiments. A security information is received at the enterprise service bus from a first application executing in a first data processing system. The security information is a part of a request for service from a second application executing in a second data processing system. A part of the security information is identified to be transformed such that the part upon transformation is usable for handling the request by the second application. A security policy applicable to the identified part is selected and the identified part is transformed according to the security policy. The transforming results in a transformed security information. The transformed security information is sent to the second application.Type: ApplicationFiled: December 22, 2009Publication date: June 23, 2011Applicant: International Business Machines CorporationInventors: Dimitriy Fot, Ivan Milman, Martin Oberhofer
-
Publication number: 20060236382Abstract: A method, system, apparatus, and computer program product are presented to support computing systems of different enterprises that interact within a federated computing environment. Federated single-sign-on operations can be initiated at the computing systems of federation partners on behalf of a user even though the user has not established a user account at a federation partner prior to the initiation of the single-sign-on operation. For example, an identity provider can initiate a single-sign-on operation at a service provider while attempting to obtain access to a controlled resource on behalf of a user. When the service provider recognizes that it does not have a linked user account for the user that allows for a single-sign-on operation with the identity provider, the service provider creates a local user account. The service provider can also pull user attributes from the identity provider as necessary to perform the user account creation operation.Type: ApplicationFiled: April 1, 2005Publication date: October 19, 2006Inventors: Heather Hinton, Ivan Milman, Venkat Raghavan, Shane Weeden
-
Publication number: 20060136990Abstract: The invention provides federated functionality within a data processing system by means of a set of specialized runtimes. Each of the plurality of specialized runtimes provides requested federation services for selected ones of the requestors according to configuration data of respective federation relationships of the requestors with the identity provider. The configuration data is dynamically retrieved during initialization of the runtimes which allows the respective runtime to be specialized for a given federation relationship. Requests are routed to the appropriate specialized runtime using the first requestor identity and the given federation relationship. The data which describes each federation relationship between the identity provider and each of the plurality of requesters is configured prior to initialization of the runtimes.Type: ApplicationFiled: December 16, 2004Publication date: June 22, 2006Inventors: Heather Hinton, Anthony Moran, Dolapo Falola, Ivan Milman, Patrick Wardrop
-
Publication number: 20050154264Abstract: A mechanism to monitor an individual's level of stress in his or her home or workplace is provided. Unobtrusive physiologic stress senses are used in combination with a wireless link and a personal computer or other intelligent device to monitor the user's stress level. Based on a user profile and the user's baseline stress indicators, one or more stress-reducing activities are presented to the user. Additionally, if a user is in a stress-sensitive population, for example, persons with a pre-existing hypertension, the user may selectively enable additional alerts.Type: ApplicationFiled: January 8, 2004Publication date: July 14, 2005Applicant: International Business Machines CorporationInventors: Kellie Lecompte, Ivan Milman, Rahul Mishra, Karthikeyan Ramamoorthy
-
Patent number: 6854056Abstract: A method or system is presented for coupling identities through the use of digital certificates, thereby allowing a client to be authenticated for a variety of services without those services having to modify their existing methods of authentication. The client generates a request for a digital certificate containing its host identity for a targeted host and secret data associated with its host identity. The secret data has been encrypted using the public key of the certifying authority that receives the request for the digital certificate. The certifying authority decrypts the secret data using its private key and encrypts the secret data using the public key of the targeted host. The digital certificate is then generated and returned to the client. At some point in time, a host receives the certificate from the client and obtains the client's host identity from the certificate, i.e. the host identity uniquely identifies the client or the user of the client to the host.Type: GrantFiled: September 21, 2000Date of Patent: February 8, 2005Assignee: International Business Machines CorporationInventors: Messaoud Benantar, Thomas L. Gindin, Ivan Milman