The Commission's Assessment of Microsoft's
Total Page:16
File Type:pdf, Size:1020Kb
The Commission's assessment of Microsoft's innovation claims In the column "Prior Art", the symbol [PA] indicates that the reference is cited as prior art, the symbol [R] means that it is cited as a reference. The following applies in the column "References": [July-T, x] = 8 July Trustee report, page x [March-T, x] = 3 March Trustee report (as amending the 22 February Trustee report), page x [Ecis, x] = Ecis's comments to Microsoft's Response to the 1 March SO, page x Date of Reference in Microsoft's Protocol Technology Description of the technology Claimed benefit Assessment Prior Art References claim filing Active ADFS Combination of The combination of all the mentioned April 2004 The use of the five Microsoft's innovation report The claimed innovation is the [July-T, 4] Directory ADFS ADFS technologies. individual ADFS on "Microsoft Web Browse combination of different features Federation Technologies innovations in Federated Sign-on Protocol & belonging to the same protocol. Services combination is Microsoft Web Browser Combining these individual undisclosed and not Federated Sign-On Protocol features is an obvious step for a obvious. Extensions" person skilled in the art. NON-INNOVATIVE Active ADFS Defining ADFS defines communications between April 2004 The protocol Microsoft's innovation report The claim concerns resolving [PA] Anderson, Steve et al: Web Services [July-T, 4] Directory Authentication a resource identity provider and a web delivers on "Microsoft Web Browse problems which are specific to Trust Language (WS-Trust) (1 May 2004; [March-T, 110] Federation Communications service resource. maintainability by Federated Sign-on Protocol & Microsoft's implementation. The http://www.ibm.com/developerworks/libra Services defining Microsoft Web Browser claim describes something which ry/specification/ws-trust/; Microsoft has authentication. Federated Sign-On Protocol was obvious to somebody skilled participated in the development of WS- Extensions", pages 20 to 21. in the art. NON-INNOVATIVE Trust.) [PA] Bajaj, Siddharth et al: Web Services Federation Language (WS-Federation), Version 1.0 (8 July 2003; http://www.msdn.microsoft.com/ws/2003/ 07/ws-federation) Active ADFS SAML ADFS uses SAML to encapsulate April 2004 The protocol Microsoft's innovation report The claim describes something [PA] OASIS, Security Services Technical [July-T, 4] Directory Encapsulation of security IDs in tokens used to delivers security on "Microsoft Web Browse which was obvious to somebody Committee: SAML v1.0 Specification Set [March-T, 110] Federation Security IDs in authenticate access to Windows and efficiency by Federated Sign-on Protocol & skilled in the art. NON- (5 November 2002 (adoption as an OASIS Services Tokens applications. This ensures that only implementing Microsoft Web Browser INNOVATIVE standard); http://www.oasis- authorized users have access to Windows SAML Federated Sign-On Protocol open.org/committees/tc_home.php?wg_ab applications. Encapsulation of Extensions", pages 13 to 18. brev=security) Security IDs in Tokens. Page 1 of 69 Date of Reference in Microsoft's Protocol Technology Description of the technology Claimed benefit Assessment Prior Art References claim filing Active ADFS Single Sign-on ADFS implements single-sign on April 2004 The protocol Microsoft's innovation report NON-INNOVATIVE [PA] U.S. Patent 5,684,950: Method and [July-T, 3] Directory Capabilities for capabilities for web access by delivers usability on "Microsoft Web Browse system for authenticating users to multiple [March-T, 109] Federation Web Access authenticating a user to a web resource via a third-party Federated Sign-on Protocol & computer servers via a single sign-on Services through a third party authentication authentication Microsoft Web Browser (Lockheed Martin Corporation; 4 broker service. service. Federated Sign-On Protocol November 1997 (Filed 23 September 1996 Extensions", pages 8 to 13. as 08/717,961)) [PA] SecureComputing: SafeWord PremierAccess Authentication Broker (http://www.securecomputing.com/index.c fm?skey=854) [PA] Paschoud, John/McLeish, Simon: Managing Access to Decomate Resources (Logged into Economics: An assessment of the European Digital Library DECOMATE II, Barcelona, Spain; June 2000; http://hdl.handle.net/1988/2806) [PA] Rivest, Ronald A./Lampson, Butler: SDSI - A Simple Distributed Security Infrastructure (15 September 1996; http://people.csail.mit.edu/rivest/sdsi10.ht ml) [PA] Lampson, Butler et al: Authentication in distributed systems: Theory and practice (ACM Transactions on Computer Systems 10(4); 265-310; November 1992; http://portal.acm.org/citation.cfm?id=1388 74) [R] Leach, Paul J. et al: A Conceptual Authorization Model for Web Services (K. Sparck-Jones and A. Herbert (eds.): Computer Systems: Theory, Technology, and Applications; 137-146; 2004; http://research.microsoft.com/Lampson/71 -ConceptualWebAuthZ/71- ConceptualWebAuthZ.pdf) Active ADFS Use of HTTP ADFS uses query strings in HTTP April 2004 The protocol Microsoft's innovation report The claim describes something [PA] RFC 2965: HTTP State Management [July-T, 3] Directory Query Strings messages as a way to transmit web delivers on "Microsoft Web Browse which was obvious to somebody Mechanism (October 2000; [March-T, 110] Federation access authentication information to a interoperability and Federated Sign-on Protocol & skilled in the art. NON- http://tools.ietf.org/html/rfc2965) Services web resource via a client. One common adaptability by the Microsoft Web Browser INNOVATIVE [PA] RFC 2616: Hypertext Transfer way of transmitting this authentication innovation of Query Federated Sign-On Protocol Protocol -- HTTP/1.1 (June 1999; information is through the use of HTTP Strings in HTTP Extensions", pages 18 to 20. http://tools.ietf.org/html/rfc2616) Post messages. However, many clients messages. do not support the use of HTTP Post. Data transfer using HTTP is a way to overcome these limitations. Page 2 of 69 Date of Reference in Microsoft's Protocol Technology Description of the technology Claimed benefit Assessment Prior Art References claim filing Active ADFS Windows ADFS uses SAML Security Tokens to April 2004 The protocol Microsoft's innovation report The claim describes something [PA] NetBSD Programmer's Manual: [March-T, 111] Directory Security transport security information including delivers efficiency on "Microsoft Web Browse which was obvious to somebody Name-Service Switch (nsswitch) (22 Federation Principal the identity of the requesting party. In a through Windows Federated Sign-on Protocol & skilled in the art. NON- January 1998; http://netbsd.gw.com/cgi- Services Mapping Windows environment, identities are Security Principal Microsoft Web Browser INNOVATIVE bin/man-cgi?nsswitch.conf++NetBSD- stored in an Active Directory server as Mapping Federated Sign-On Protocol 1.4.3) Windows Security Principals. ADFS Innovation. Extensions", pages 21 to 22. [PA] Sun Microsystems: Name-Service bridges the gap between Windows Switch (nsswitch) (SunOS Manual; Security Principals by mapping the December 2005; Subject element of a Security Token to a http://compute.cnr.berkeley.edu/cgi- Windows Security Principal and then bin/man-cgi?nsswitch.conf; This is a replacing the AuthIdentity value with recent manual reference, but nsswitch has Windows Security Principal. This allows been available since at least 1986 as part a server to quickly access security of BSD UNIX 4.3.) information in an Active Directory when starting with a Security Token. Microsoft CISP Open Connect A client has traditionally needed to create July 1996 The Open Connect Microsoft's Innovation The claim describes something [R] Koch, George: Oracle 7 [March-T, 124] Content Feature a connection with a server in order to Feature enhances Report: "Content Indexing which was obvious to somebody (Osborne/McGraw-Hill, second revised Indexing issue every query of a content indexing efficiency by Service", pages 8 and 9. skilled in the art. NON- edition; 609; March 1993) Services service. Clients often make repeated allowing multiple INNOVATIVE [PA] ISO: Information processing systems Protocol connections to a server in order to queries to be made - Database language - SQL (ISO present multiple queries. This consumes serially through a 9075:1987; more resources and is cumbersome. CISP single connection. http://archive.opengroup.org/public/tech/d eliminates this problem through its Open atam/sql.htm; The linked article provides Connect Feature. This feature creates a some background about the chronology of client-server connection that enables the the SQL standards.) client to issue multiple queries to the [PA] O'Neil, Patrick: Database: Principles, server. As a result, clients can more Programming, and Performance (Morgan efficiently query a content indexing Kaufmann Publishers, San Francisco, first server. edition; 1994) Microsoft CISP Oversized If a requested property is too large to fit July 1996 Oversized Property Microsoft's Innovation NON-INNOVATIVE [R] Microsoft: FP97: Using FrontPage [July-T, 11] Content Property Value into a response buffer, then the server Value Fetching Report: "Content Indexing Search Engine Instead of Microsoft Index [March-T, 124] Indexing Fetching flags the property as deferred rather than enhances efficiency Service", pages 9 and 10. Server (Frontpage 97 was released in Services sending it. By way of a specific message by avoiding 1997.; Protocol the client requests the deferred property property value http://support.microsoft.com/kb/181204/E in a series