发明名称 Disconnected credential validation using pre-fetched service tickets
摘要 One or more user service tickets are obtained (i.e. pre-fetched) from an authentication server and stored in a ticket cache. The user service tickets facilitate a login device communicating with one or more users or group members associated with the login device. Login credentials for the users or group members may be subsequently authenticated against the user service tickets within the ticket cache thereby eliminating the need for immediate access to the authentication server or a previous login session by the users or group members. The user service tickets within the ticket cache may be refreshed as needed. In one embodiment, the user service tickets are refreshed daily and also in response to login attempts if the authentication service is readily accessible.
申请公布号 US9288201(B2) 申请公布日期 2016.03.15
申请号 US201314076913 申请日期 2013.11.11
申请人 Dell Software Inc. 发明人 Peterson Matthew T.;Webb Jeff Marsden
分类号 H04L29/06;H04L9/32 主分类号 H04L29/06
代理机构 Knobbe Martens Olson & Bear, LLP 代理人 Knobbe Martens Olson & Bear, LLP
主权项 1. A computerized method that processes login credentials, the method comprising: pre-caching a Kerberos user service ticket in a ticket cache associated with a login device, the Kerberos user service ticket comprising an encrypted portion with identification information about a user that is used to subsequently authenticate the user, wherein the Kerberos user service ticket identifies the login device as a principal and a user as a service provider; receiving an authentication request at the login device from the user subsequent to pre-caching the Kerberos user service ticket, the authentication request comprising one or more login credentials of the user; in response to receiving the authentication request from the user, determining whether a Kerberos server is unavailable; and in response to determining that the Kerberos server is unavailable, authenticating the user based on the Kerberos user service ticket stored in the ticket cache, said authenticating comprising decrypting the Kerberos user service ticket and comparing the identification information about the user stored in the Kerberos user service ticket with the one or more login credentials of the user.
地址 Aliso Viejo CA US