EP1429228A2

Access information synchronization between information domains employing dissimilar protective transformation

Abstract

Mechanisms are provided for synchronizing information amongst directory spaces or repositories that employ dissimilar protective transformations. In some embodiments, directory spaces are embodied as directory servers, services or similar components of computer operating systems. In some embodiments, dissimilar protective transformations include differing hashes (or encryption) techniques or facilities employed by products available from Sun Microsystems, Inc., on the one hand, and Microsoft Corporation on another. The mechanism is responsive to a change in the second store, invalidating a corresponding entry in the first store. Upon receipt, by the first store, of an authentication request that includes a credential and which corresponds to the invalidated entry, the method chains the authentication request to the second store. If the authentication at the second store is successful, the method updates the previously invalidated entry of the first store with the credential.

EP1429228A2, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 11 December 2023, 2.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

29 claims: 24 independent, 5 dependent

  1. 1
    A method of synchronizing credentials between first and second stores that employ dissimilar protective transforms, the method comprising:responsive to a change in the second store, invalidating a corresponding entry in the first store;and upon receipt, by the first store, of an authentication request that includes a credential and which corresponds to the invalidated entry, chaining the authentication request to the second store and, if successful, updating the previously invalidated entry of the first store with the credential.
  2. 5
    The method of claim of any preceding claim, wherein the updating includes encoding the credential using a first of the dissimilar protective transforms;and wherein the updating is performed without reversing a second of the dissimilar protective transforms.
  3. 6
    The method of any preceding claim, wherein at least one of the dissimilar protective transforms is generally irreversible.
  4. 7
    The method of preceding claim, wherein the change in the second store includes a change of the credential.
  5. 8
    The method of any preceding claim, wherein the change in the second store includes a change of an entry that encodes the credential.
  6. 9
    The method of any preceding claim, further comprising:accessing a change log of the second store to detect the change.
  7. 10
    The method of any of claims 1 - 8, further comprising:accessing a change notification service of the second store to detect the change.
  8. 11
    The method of any preceding claim, further comprising:calling an interface of the second store to detect the change.
  9. 12
    The method of any preceding claim, further comprising:intercepting the change and signaling same.
  10. 13
    The method of any preceding claim, wherein the updating includes revising the previously invalidated entry.
  11. 14
    The method of any of claims 1 - 12, wherein the updating includes replacing the previously invalidated entry with a valid instance thereof including the credential.
  12. 15
    The method of any preceding claim, wherein the invalidated entry is marked as such using an invalid, non-authoritative or expiry indicator.
  13. 16
    The method of any preceding claim, wherein the invalidated entry encodes the credential.
  14. 17
    The method of any of claims 1 - 15, wherein the invalidated entry includes at least a portion of a user or entity record corresponding to the credential.
  15. 18
    The method of any preceding claim, further comprising:causing the change in the second store.
  16. 19
    The method of any preceding claim, further comprising:upon receipt, by the first store, of a second authentication request including a second credential and not corresponding to an invalidated entry, authenticating against the first store and, if unsuccessful, chaining the authentication request to the second store.
  17. 20
    The method of any preceding claim, wherein at least one of the first and second stores is embodied, at least in part, as part of an operating system.
  18. 21
    The method of any preceding claim, wherein the first and second stores reside on a same computer.
  19. 22
    The method of any preceding claim, embodied, at least in part, as a polling agent that detects the change and triggers the invalidating.
  20. 23
    A computer program for implementing the method of any preceding claim.
  21. 24
    A computer program product executable to synchronize a credential encoded by a first service with that encoded by a second service, wherein the first and second service encodings employ dissimilar protective transforms and wherein, for a first service credential encoding mapped to a corresponding second service encoding, the synchronization is performed in response to an invalidity indication for the first service credential encoding.
  22. 27
    The computer program product of any of claims 24 to 26, wherein the invalidity indication is encoded by first service.
  23. 28
    A password synchronization facility comprising:an authentication service that chains to a second service authentication requests corresponding to invalidated entries of the authentication service and, on successful authentication against the second service, updates a corresponding credential encoding of the authentication service;and a polling agent that detects changes to entries of the second service and triggers invalidation of the corresponding credential encoding of the authentication service.
  24. 29
    A password synchronization facility comprising:a polling agent that detects changes to entries of a credential store and triggers invalidation of corresponding credential encodings of an authentication service, thereby causing the authentication service to chain to a second service authentication requests corresponding to invalidated entries and, on successful authentication against the second service, updates a corresponding credential encoding of the authentication service.
Independent claims24