A method and a system are disclosed, of enabling a user of an Internet
application to access protected information. An idea behind at least one
embodiment of the invention is that a user identifier token is created,
after a user has been authenticated by way of a logon mechanism of the
Internet application. The user identifier token is then associated with
the authenticated user and stored at an Internet client of the
authenticated user. When protected information is to be made available
for a requesting user, the concerned set of protected information is
associated with the authenticated user and an information identifier
token is created and associated with the protected information. The
information identifier token is delivered to the authenticated user via
e-mail. When a request is received from a requesting user, it is verified
that the request comprises a user identifier token and an information
identifier token, that there exists an association between these tokens
and the previously authenticated user and the protected information,
respectively, and that the requested protected information is associated
with the authenticated user. If so, the requesting user is allowed to
access the protected information.