The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.
The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.
Patent No.:
Date of Patent:
Aug. 04, 2009
Filed:
Apr. 01, 2005
Cristian Marius Ilac, Sammamish, WA (US);
Karthik Jaganathan, Redmond, WA (US);
Murli D. Satagopan, Sammamish, WA (US);
Tarek Bahna El-din Mahmoud Kamel, Issaquah, WA (US);
Todd F. Stecher, Seattle, WA (US);
Cristian Marius Ilac, Sammamish, WA (US);
Karthik Jaganathan, Redmond, WA (US);
Murli D. Satagopan, Sammamish, WA (US);
Tarek Bahna El-Din Mahmoud Kamel, Issaquah, WA (US);
Todd F. Stecher, Seattle, WA (US);
Microsoft Corporation, Redmond, WA (US);
Abstract
Branch domain controllers (DCs) contain read only replicas of the data in a normal domain DC. This includes information about the groups a user belongs to so it can be used to determine authorization information. Password information, however, is desirably replicated to the branch DCs only for users and services (including machines) designated for that particular branch. Moreover, all write operations are desirably handled by hub DCs, the primary domain controller (PDC), or other DCs trusted by the corporate office. Rapid authentication and authorization in branch offices is supported using Kerberos sub-realms in which each branch office operates as a virtual realm. The Kerberos protocol employs different key version numbers to distinguish between the virtual realms of the head and branch key distribution centers (KDCs). Accounts may be named krbtgt_<ID> where <ID> is carried in the kvno field of the ticket granting ticket (TGT) to indicate to the hub KDC which krbtgt' key was used to encrypt the TGT.