CNIPA.AI
검색으로 돌아가기
기록

NETWORK AUTHENTICATION SERVICE SECURITY

발명심사 중
3조회수
20청구항 · 3 독립항
§ Ⅰ

개요

발명자

Sinead O’DONOVAN; Avraham CARMON; Ashish JAIN; Shahzad Ahmed KHALID; Mordhai GENDELMAN; Or MORAN; Navyatha BEESETTI

IPC 분류

H4L 9/40

CPC 분류

H4L63/807

Some embodiments provide or utilize technology which increases the security of network authentication operations, such as Kerberos operations, New Technology LAN Manager operations, or other network authentication operations which utilize security tickets or security tokens or both. In some embodiments, a user machine (also known as a client machine) receives an authentication data structure (ADS) which includes one or more security tickets or security tokens or both. Embodiments constrain the ADS according to at least one security requirement, such as a volatile-memory-only constraint, a secured-memory-only constraint, or a multilayer encryption constraint. Embodiments also transmit the ADS from the machine as a part of performing the network authentication service. Some embodiments inhibit virtual memory, or memory dumping, or both. Some embodiments bind the ADS to the user machine, and some embodiments limit ADS usage counts.

원문 (중국어)

Some embodiments provide or utilize technology which increases the security of network authentication operations, such as Kerberos operations, New Technology LAN Manager operations, or other network authentication operations which utilize security tickets or security tokens or both. In some embodiments, a user machine (also known as a client machine) receives an authentication data structure (ADS) which includes one or more security tickets or security tokens or both. Embodiments constrain the ADS according to at least one security requirement, such as a volatile-memory-only constraint, a secured-memory-only constraint, or a multilayer encryption constraint. Embodiments also transmit the ADS from the machine as a part of performing the network authentication service. Some embodiments inhibit virtual memory, or memory dumping, or both. Some embodiments bind the ADS to the user machine, and some embodiments limit ADS usage counts.