Claims
- 1. A computer-readable medium having computer-executable instructions for performing steps by a computer in a logon process, comprising:receiving user input for logging onto the computer; sending a first network access request for the user to a network access control server requesting authentication of the user; receiving an access control document from the network access control server; retrieving account data for the user from the access control document; completing the logon process using the retrieved account data for the user.
- 2. A computer-readable medium as in claim 1, wherein the step of retrieving the account data for the user includes decrypting the access control document with a security key of the computer.
- 3. A computer-readable medium as in claim 2, wherein the access control document is a service ticket for the computer.
- 4. A computer-readable medium as in claim 3, wherein the first network access request requests for a session ticket for communicating with the network access control server, and further including computer-executable instructions for performing steps including:receiving a session ticket for communicating with the network access control server; sending a second network access request to the network access control server for the service ticket for the computer.
- 5. A computer-readable medium as in claim 4, wherein the network access control server is a Kerberos Key Distribution Center (KDC).
- 6. A computer-readable medium as in claim 1, wherein the step of sending includes identifying in the first network access request the user account data needed for the logon process.
- 7. A computer-readable medium having stored thereon a data structure transmitted to a user computer for use in completing a log-on process of a user, the data structure comprising data fields representing a network access ticket formatted according to the Kerberos protocol and issued to the user computer for the user, including an authorization data field containing data representing account data for the user required for the user to log onto the user computer.
- 8. A computer-readable medium as in claim 7, wherein the authorization data field in the network access ticket includes a buffer field containing the account data for the user and a buffer information field including data identifying the buffer field as containing the account data and data representing a pointer to the buffer field containing the account data.
RELATED APPLICATIONS
This application is a continuation of copending U.S. patent application Ser. No. 09/525,419, filed Mar. 15, 2000, which claims the benefit of U.S. Provisional Application No. 60/160,477, filed Oct. 19, 1999.
US Referenced Citations (5)
Foreign Referenced Citations (1)
Number |
Date |
Country |
WO 9953391 |
Oct 1999 |
WO |
Non-Patent Literature Citations (5)
Entry |
Neuman, Clifford et al. The Kerberos Network Authentication Service (V5)—draft. [web page] Jun. 25, 1999; http://search.ietf.org/internet-drafts/draft-ietf-cat-kerberos-revisions-04.txt. [Accessed Nov. 8, 1999]. |
Computerworld, Users Ask for Single Log-Ons. p. 37, Jul. 26, 1993. |
R. Moskowitz. The Battle of the Logan Titans. Network Computing, n. 903, p. 37, 1998. |
D. Backman. KerbNet Takes a Bite Out of Hackers. Network Computing, n. 807, p. 42, 1997. |
D. Backman, Kerberos: A Piece of the Net Security Puzzle. Network Computing, n. 719, p. 156, 1996. |
Provisional Applications (1)
|
Number |
Date |
Country |
|
60/160477 |
Oct 1999 |
US |
Continuations (1)
|
Number |
Date |
Country |
Parent |
09/525419 |
Mar 2000 |
US |
Child |
09/549794 |
|
US |