The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 23, 2019

Filed:

Oct. 05, 2017
Applicant:

Microsoft Technology Licensing, Llc, Redmond, WA (US);

Inventors:

Sai Sudhir Anantha Padmanaban, Redmond, WA (US);

Lokesh Srinivas Koppolu, Redmond, WA (US);

Andrea D'Amato, Kirkland, WA (US);

Yi Zeng, Bothell, WA (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/41 (2013.01); H04L 29/06 (2006.01); H04L 29/12 (2006.01); H04L 9/32 (2006.01); H04L 29/08 (2006.01); H04L 29/14 (2006.01);
U.S. Cl.
CPC ...
H04L 63/083 (2013.01); H04L 61/1511 (2013.01); H04L 63/0807 (2013.01); H04L 63/0815 (2013.01); G06F 2221/2145 (2013.01); H04L 67/10 (2013.01); H04L 69/40 (2013.01);
Abstract

Services from domainless machines are made available in a security domain under a virtual name. Each machine is not joined to the domain but can reach a security domain controller. The controller controls at least one security domain using an authentication protocol, such as a modified Kerberos protocol. One obtains a set of security domain credentials, generates a cluster name secret, gives the cluster a virtual name, and authenticates the machines to the domain controller using these items. In some cases, authentication uses a ticket-based protocol which accepts the cluster name secret in place of a proof of valid security domain membership. In some, the domain controller uses a directory service which is compatible with an active directory service; the cluster virtual name is provisioned as an account in the directory service. The cluster virtual name may concurrently serve clients on different security domains of the directory service.


Find Patent Forward Citations

Loading…