Invention Grant
- Patent Title: Synchronizing credential hashes between directory services
- Patent Title (中): 在目录服务之间同步凭据散列
-
Application No.: US13873882Application Date: 2013-04-30
-
Publication No.: US09282093B2Publication Date: 2016-03-08
- Inventor: Jonathan M. Luk , Ariel N. Gordon , Raman N. Chikkamagalur , Ziad Elmalki , Sergii Gubenko , Girish Chander , Anandhi Somasekaran , Murli D. Satagopan
- Applicant: Microsoft Corporation
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agent Aneesh Mehta; Kate Drakos; Micky Minhas
- Main IPC: G06F7/04
- IPC: G06F7/04 ; H04L29/06 ; G06F21/31 ; H04L9/32 ; H04L9/08

Abstract:
The subject disclosure is directed towards securely synchronizing passwords that are changed at a source location (e.g., an on-premises directory service) to a target location (e.g., a cloud directory service), so that the same credentials may be used to log into the source or target location, yet without necessarily having each domain controller handle the synchronization. The plaintext password is not revealed, instead using hash values computed therefrom to represent the password-related data. The target may receive a secondary hash of a primary hash, and thereby only receive and store a password blob. Authentication is accomplished by using the same hashing algorithms at the target service to compute a blob and compare against the synchronized blob. Also described are crypto agility and/or changing hashing algorithms without requiring a user password change.
Public/Granted literature
- US20140325622A1 SYNCHRONIZING CREDENTIAL HASHES BETWEEN DIRECTORY SERVICES Public/Granted day:2014-10-30
Information query