发明名称 Mixed-mode authentication
摘要 Techniques for mixed-mode authentication are described. In one or more embodiments, an authentication service may be implemented to selectively configure and issue authentication tokens based upon an optional secure mode that enables enhanced security. Clients may be provided with an option to choose between an insecure mode and a secure mode for authentications. Based on this choice, tokens may be configured to include an indication of whether the secure mode is disabled or enabled. When secure mode is disabled, an insecure token valid for both secure sites and other sites is issued to a client when the client is authenticated. When the optional secure mode is enabled, both secure and insecure tokens are provided to the client. The authentication services and/or other services may be configured to reject an insecure token when secure mode is enabled to prevent unauthorized use of a stolen token to access secure resources.
申请公布号 US8566915(B2) 申请公布日期 2013.10.22
申请号 US20100910411 申请日期 2010.10.22
申请人 HSUEH WALTER C.;ROUSKOV YORDAN I.;LOW SPENCER WONG;CREVIER DANIEL W.;MICROSOFT CORPORATION 发明人 HSUEH WALTER C.;ROUSKOV YORDAN I.;LOW SPENCER WONG;CREVIER DANIEL W.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址