US2014365762A1PendingUtilityA1

Method and Apparatus for Securely Synchronizing Password Systems

Assignee: ROCKSTAR CONSORTIUM US LPPriority: Mar 31, 2003Filed: Aug 27, 2014Published: Dec 11, 2014
Est. expiryMar 31, 2023(expired)· nominal 20-yr term from priority
H04L 63/0846G06F 21/45H04L 63/083G06F 2221/2113G06Q 20/4012H04L 63/105H04L 63/0815G06F 21/41
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A centralized password repository (CPR) provides network users with a password portal through which the user can manage password access to domains and applications on the network. A subset of the domains and applications on the network may be required, by design, to maintain a separate password infrastructure. For these systems, the CPR establishes a secure and authenticated communication channel and software on the system interfaces with the password infrastructure to synchronize the password in the system password infrastructure with the password in the CPR. For other systems not required to maintain a separate password infrastructure, the CPR performs password services by responding to requests from those systems seeking to validate user IDs and passwords. The CPR enables an administrator to modify network privileges and enables a user to alter passwords on the network through a single interface.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 - 17 . (canceled) 
     
     
         18 . A communication network comprising:
 a plurality of password domains, each password domain configured to maintain a respective association between respective users and respective passwords used to authenticate the respective users for access to the respective password domains, and each password domain requiring a respective authentication level for password changes;   a password portal configured to maintain an association between respective users, respective password domains and respective passwords used to authenticate the respective users for changing the respective passwords associated with the respective users at the password portal and at respective password domains; and   communication facilities connected between the password portal and the plurality of password domains;   the password portal being configured:   to receive a password change request from a particular user authenticated at a particular authentication level at the password portal;   to implement the password change request at the password portal;   to establish respective encrypted and authenticated communication channels over the communication facilities only to respective password domains which are associated with the particular user at the password portal and which require respective authentication levels for password changes which is not higher than the particular authentication level; and   to communicate the password change request over each respective encrypted and authenticated communication channel to a respective password domain; and   each password domain receiving the password change request over a respective encrypted and authenticated communication channel being configured to implement the password change request at the password domain.   
     
     
         19 . The communication network of  claim 18 , wherein the password portal is configured, on determining that the particular user is associated with a password domain requiring an authentication level for password changes which is higher than the particular authentication at which the particular user is authenticated at the password portal, to initiate re-authentication at the at least one password portal of the particular user at an authentication level at least as high as the authentication level required by the password domain which is associated with the particular user at password portal. 
     
     
         20 . The communication network of  claim 19 , wherein the password portal is configured:
 to establish an encrypted and authenticated communication channel over the communication facilities to the password domain which is associated with the particular user at the password portal and which requires a respective authentication level which is higher than the particular authentication level after re-authenticating the particular user at the authentication level at least as high as the authentication level required by the password domain which is associated with the particular user at the password portal; and   to communicate the password change request over the encrypted and authenticated communication channel to the password domain which requires a respective authentication level which is higher than the particular authentication level.   
     
     
         21 . The communication network of  claim 18 , comprising plural password portals connected by the communication facilities, wherein each password portal is configured to synchronize passwords at the plural password portals. 
     
     
         22 . The communication network of  claim 21 , wherein each password portal is configured to synchronize passwords at the plural password portals by sending received password change requests to the other password portals. 
     
     
         23 . The communication network of  claim 21 , wherein each password portal is configured synchronize passwords at the plural password portals by sending periodic synchronization messages to the other password portals. 
     
     
         24 . The communication network of  claim 21 , wherein each password portal is configured to synchronize a password for a particular user only at password portals that maintain passwords for the particular user. 
     
     
         25 . The communication network of  claim 24 , wherein each password portal is configured to determine, for the particular user, which other password portals maintain a password for the particular user. 
     
     
         26 . The communication network of  claim 25 , wherein each password portal is configured to determine, for the particular user, which other password portals maintain a password for the particular user by querying the other password portals. 
     
     
         27 . The communication network of  claim 26 , wherein each password portal maintains a list of domain specific user identifiers for the particular user for use in querying the other password portals. 
     
     
         28 . The communication network of  claim 24 , wherein each password portal maintains a list of password portals that maintain passwords for the particular user. 
     
     
         29 . The communication network of  claim 21 , wherein each password portal is configured:
 to receive a password change request initiated by a particular user authenticated at a particular authentication level at the password portal; and   to implement the password change request at the password portal;   to establish respective encrypted and authenticated communication channels over the communication facilities only to respective password domains which are associated with the particular user at the password portal and which require respective authentication levels for password changes which is not higher than the particular authentication level; and   to communicate the password change request over each respective encrypted and authenticated communication channel to a respective password domain.   
     
     
         30 . The communication network of  claim 18 , wherein the password change request indicates a user identifier and a new password and each password domain is configured to implement the password change request by associating the new password with the user identifier. 
     
     
         31 . The communication network of  claim 18 , wherein each password domain is configured to implement the password change using a reset function. 
     
     
         32 . The communication network of  claim 31 , wherein the reset function can be invoked without using a previous password. 
     
     
         33 . The communication network of  claim 18 , wherein each password domain is configured to communicate to the password portal success or failure of the password change request at the password domain. 
     
     
         34 . The communication network of  claim 18 , wherein each password domain maintains a respective database to maintain the respective association between respective users and respective passwords which is used to authenticate the respective users for access to the respective password domains. 
     
     
         35 . The communication network of  claim 18 , comprising at least one password domain which does not maintain a respective database to maintain an association between respective users and respective passwords, wherein the password portal is configured to perform password services for the at least one password domain which does not maintain a respective database to maintain an association between respective users and respective passwords. 
     
     
         36 . The communication network of  claim 18 , wherein the password portal is configured to present web interfaces to users. 
     
     
         37 . The communication network of  claim 36 , wherein the web interfaces are configured to receive password change requests from users and to communicate success or failure of password change requests to users. 
     
     
         38 . The communication network of  claim 18 , wherein the password portal comprises:
 at least one network port;   at least one controller coupled to the at least one network port; and   a password database coupled to the at least one controller and configured to maintain the association between the respective users, the respective password domains and the respective passwords.   
     
     
         39 . The communication network of  claim 38 , further comprising an authentication server. 
     
     
         40 . The communication network of  claim 39 , wherein the authentication server is a Radius server. 
     
     
         41 . The communication network of  claim 18 , wherein each password domain comprises a password database. 
     
     
         42 . The communication network of  claim 41 , wherein each password domain comprises a database management system (DBMS) configured to manage the password database. 
     
     
         43 . The communication network of  claim 18 , wherein each password domain comprises:
 at least one network port;   at least one controller coupled to the at least one network port; and   a password database coupled to the at least one controller and configured to maintain the respective association between respective users and the respective passwords.   
     
     
         44 . The communication network of  claim 18 , configured to authenticate users using at least one other element authentication information in addition to a password. 
     
     
         45 . The communication network of  claim 44 , wherein the at least one other element of authentication information comprises biometric information. 
     
     
         46 . The communication network of  claim 44 , wherein the at least one other element of authentication information comprises an electronic certificate.

Join the waitlist — get patent alerts

Track US2014365762A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.