US2013283354A1PendingUtilityA1

Selective cross-realm authentication

Assignee: MICROSOFT CORPPriority: Oct 31, 2002Filed: Jun 18, 2013Published: Oct 24, 2013
Est. expiryOct 31, 2022(expired)· nominal 20-yr term from priority
H04L 63/0815H04L 63/0807H04L 63/101H04L 63/08H04L 63/10
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A selective cross-realm authenticator associates an identifier with a request from an entity authenticated in one realm to access a resource associated with a second realm. The identifier indicates that the entity was authenticated in a realm other than the realm associated with the requested resource. A domain controller associated with the resource performs an access check to verify that the authenticated user is authorized to authenticate to the requested resource. Permissions associated with the resource can be used to specify levels of access to be granted to entities authenticated by a domain controller associated with another realm.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, from an entity authenticated in a first realm, a request to access a resource associated with a second realm;   determining whether entities authenticated by other than the second realm are allowed access to the resource according to a selective trust relationship between the second realm and other realms that include the first realm;   in an event that entities authenticated by other than the second realm are allowed access to the resource:
 determining other realm access permissions to be assigned to entities authenticated by other than the second realm, based on the selective trust relationship, wherein the other realm access permissions are different from second realm access permissions that are to be assigned to entities authenticated by the second realm; and 
 granting the entity access to the resource according to the other realm access permissions; and 
   in an event that entities authenticated by other than the second realm are not allowed to access the resource, refusing to grant the entity access to the resource.   
     
     
         2 . The method as recited in  claim 1  wherein determining whether entities authenticated by other than the second realm are allowed to access the resource comprises comparing a security identifier associated with the entity with an access control list associated with the resource, wherein the security identifier indicates that the entity was authenticated by other than the second realm. 
     
     
         3 . The method as recited in  claim 1  wherein determining whether entities authenticated by other than the second realm are allowed to access the resource comprises comparing data associated with a security token to an access control list, wherein the data associated with the security token indicates that the entity was authenticated outside of the second realm. 
     
     
         4 . The method as recited in  claim 3  wherein the security token comprises at least one of an SAML token and an XrML token. 
     
     
         5 . The method as recited in  claim 1  wherein granting the entity access to the resource comprises completing an authentication request. 
     
     
         6 . The method as recited in  claim 1  wherein granting the entity access to the resource comprises completing an NTLM authentication request. 
     
     
         7 . The method as recited in  claim 1  wherein granting the entity access to the resource comprises serving a service ticket associated with the resource to the entity. 
     
     
         8 . A domain controller configured to perform the method as recited in  claim 1 . 
     
     
         9 . One or more computer-readable media comprising computer executable instructions that, when executed, direct a computing system to perform the method as recited in  claim 1 . 
     
     
         10 . A method comprising:
 receiving, from a user authenticated in a first realm, a request to access a resource associated with a second realm; and   associating with the user, an identifier that indicates the user was authenticated in a realm other than the second realm,   wherein the second realm has a selective trust relationship with other realms, including the first realm, such that user access permissions to the resource associated with the second realm differ based on whether the user was authenticated in the second realm or whether the user was authenticated in one of the other realms.   
     
     
         11 . The method as recited in  claim 10  wherein the user comprises an application. 
     
     
         12 . The method as recited in  claim 10  wherein the user comprises a computer system. 
     
     
         13 . The method as recited in  claim 10  wherein the identifier further indicates a type of authentication associated with the user. 
     
     
         14 . The method as recited in  claim 10  wherein the associating comprises adding a security identifier to a privilege access certificate associated with the user. 
     
     
         15 . The method as recited in  claim 10  wherein the associating comprises adding a security identifier to a privilege access certificate associated with the request. 
     
     
         16 . The method as recited in  claim 10  wherein the associating comprises setting a flag associated with the user. 
     
     
         17 . The method as recited in  claim 10  wherein the associating comprises setting a flag associated with the request. 
     
     
         18 . One or more computer-readable media comprising computer executable instructions that, when executed, direct a computing system to perform the method as recited in  claim 10 . 
     
     
         19 . A system comprising:
 a first domain controller implemented to maintain first user accounts and to authenticate users based on the first user accounts;   a second domain controller implemented to maintain second user accounts and to authenticate users based on the second user accounts; and   a cross-realm authenticator configured to associate, with a request from an entity authenticated by the first domain controller to access a resource associated with the second domain controller, an identifier that indicates that the request is from an entity authenticated by a domain controller other than the second domain controller.   
     
     
         20 . The system as recited in  claim 19  wherein the second domain controller is further configured to verify that an entity authenticated by a domain controller other than the second domain controller is allowed to access the resource.

Join the waitlist — get patent alerts

Track US2013283354A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.