Invention Grant
US09197670B2 Method and apparatus for creating conditional windows process tokens
有权
用于创建条件窗口进程令牌的方法和装置
- Patent Title: Method and apparatus for creating conditional windows process tokens
- Patent Title (中): 用于创建条件窗口进程令牌的方法和装置
-
Application No.: US14049171Application Date: 2013-10-08
-
Publication No.: US09197670B2Publication Date: 2015-11-24
- Inventor: Hon Wai Kwok
- Applicant: Centrify Corporation
- Applicant Address: US CA Sunnyvale
- Assignee: CENTRIFY CORPORATION
- Current Assignee: CENTRIFY CORPORATION
- Current Assignee Address: US CA Sunnyvale
- Agency: Blakely Sokoloff Taylor & Zafman LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A system and method for taking control of process token creation in the Windows operating system to create conditional process tokens that define access to system resources for process running on a Windows computer. The system includes an LSA shim layer that intercepts standard Windows requests for authentication and authorization and an authentication agent that determines context for each request. A custom authentication and authorization (A&A) store determines authentication success and the amount of authorization based on context and supplied credentials. Once the custom A&A store determines a successful log-on and defines authorization for the user, it passes the elements of authorization through the authentication agent to the LSA shim layer, which passes them on to the LSA module, which in turn uses them to request a Windows process token from the Windows kernel. The Windows kernel assigns the token to a user's session on the computer, defining the level of resource access available to processes the user launches.
Public/Granted literature
- US20150101020A1 METHOD AND APPARATUS FOR CREATING CONDITIONAL WINDOWS PROCESS TOKENS Public/Granted day:2015-04-09
Information query