Electrical computers and digital processing systems: support – Multiple computer communication using cryptography – Central trusted authority provides computer authentication
Reexamination Certificate
2005-04-01
2009-08-04
Barron, Jr., Gilberto (Department: 2432)
Electrical computers and digital processing systems: support
Multiple computer communication using cryptography
Central trusted authority provides computer authentication
C709S229000, C380S277000, C713S171000
Reexamination Certificate
active
07571311
ABSTRACT:
Branch domain controllers (DCs) contain read only replicas of the data in a normal domain DC. This includes information about the groups a user belongs to so it can be used to determine authorization information. Password information, however, is desirably replicated to the branch DCs only for users and services (including machines) designated for that particular branch. Moreover, all write operations are desirably handled by hub DCs, the primary domain controller (PDC), or other DCs trusted by the corporate office. Rapid authentication and authorization in branch offices is supported using Kerberos sub-realms in which each branch office operates as a virtual realm. The Kerberos protocol employs different key version numbers to distinguish between the virtual realms of the head and branch key distribution centers (KDCs). Accounts may be named krbtgt_<ID> where <ID> is carried in the kvno field of the ticket granting ticket (TGT) to indicate to the hub KDC which krbtgt′ key was used to encrypt the TGT.
REFERENCES:
patent: 5757920 (1998-05-01), Misra et al.
patent: 6128391 (2000-10-01), Denno et al.
patent: 6279111 (2001-08-01), Jensenworth et al.
patent: 6427209 (2002-07-01), Brezak, Jr. et al.
patent: 2003/0120948 (2003-06-01), Schmidt et al.
Ilac Cristian Marius
Jaganathan Karthik
Mahmoud Kamel Tarek Bahna El-Din
Satagopan Murli D.
Stecher Todd F.
Barron Jr. Gilberto
Microsoft Corporation
Woodcock & Washburn LLP
Yousefi Shahrouz
LandOfFree
Scheme for sub-realms within an authentication protocol does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Scheme for sub-realms within an authentication protocol, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Scheme for sub-realms within an authentication protocol will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-4100778