首页> 外国专利> Scheme for sub-realms within an authentication protocol

Scheme for sub-realms within an authentication protocol

机译:认证协议中子领域的方案

摘要

Branch domain controllers (DCs) contain read only replicas of the data in a normal domain DC. This includes information about the groups a user belongs to so it can be used to determine authorization information. Password information, however, is desirably replicated to the branch DCs only for users and services (including machines) designated for that particular branch. Moreover, all write operations are desirably handled by hub DCs, the primary domain controller (PDC), or other DCs trusted by the corporate office. Rapid authentication and authorization in branch offices is supported using Kerberos sub-realms in which each branch office operates as a virtual realm. The Kerberos protocol employs different key version numbers to distinguish between the virtual realms of the head and branch key distribution centers (KDCs). Accounts may be named krbtgt_ID where ID is carried in the kvno field of the ticket granting ticket (TGT) to indicate to the hub KDC which krbtgt′ key was used to encrypt the TGT.
机译:分支域控制器(DC)包含普通域DC中数据的只读副本。这包括有关用户所属组的信息,因此可用于确定授权信息。但是,希望仅针对为该特定分支指定的用户和服务(包括计算机)将密码信息复制到分支DC。而且,所有写操作都希望由集线器DC,主域控制器(PDC)或公司办公室信任的其他DC处理。使用Kerberos子域支持分支机构中的快速身份验证和授权,在该子域中,每个分支机构都作为虚拟域运行。 Kerberos协议使用不同的密钥版本号来区分头部和分支密钥分发中心(KDC)的虚拟域。可以将帐户命名为krbtgt_ ,其中在票证授予票证(TGT)的kvno字段中携带,以向集线器KDC指示哪个krbtgt'密钥用于加密TGT。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号