Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

9 results about "Kerberos" patented technology

Kerberos (/ˈkɜːrbərɒs/) is a computer-network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner. The protocol was named after the character Kerberos (or Cerberus) from Greek mythology, the ferocious three-headed guard dog of Hades. Its designers aimed it primarily at a client–server model and it provides mutual authentication—both the user and the server verify each other's identity. Kerberos protocol messages are protected against eavesdropping and replay attacks.

Systems, methods, and devices for preventing credential passing attacks

PendingUS20260205484A1TicketData pack
A system and method for the detection and mitigation of Kerberos golden ticket, silver ticket, and related identity-based cyberattacks by passively monitoring and analyzing Kerberos and authentication operations within the network. The system and method provide real-time detections of identity attacks using time-series data and data pipelines, and by transforming the stateless Kerberos protocol into stateful protocol. A packet capturing agent is deployed on the network where captured time-series Kerberos and related event and log information is processed in distributed computational graph (DCG) stages where declarative rules determine if an attack is being carried out and what type of attack it is.
Owner:SENTINELONE INC

Terminal domain adding method and system based on non-Kerberos protocol

The invention provides a terminal domain adding method and system based on a non-Kerberos protocol, relates to the technical field of data communication, is applied to a domain management platform, the platform comprises a client and a server, the client is deployed on a target terminal, and the method comprises the following steps: sending a domain adding request to the server through the client, responding to the domain adding request through the server, and sending the domain adding request to the target terminal through the server. The method comprises the steps of obtaining administrator login information in a domain adding request, generating a domain adding certificate based on the administrator login information through a server, sending the domain adding certificate to a client, receiving the domain adding certificate through the client, encrypting the domain adding certificate to obtain an encrypted domain adding certificate, and sending the encrypted domain adding certificate to the server when the client receives the login request of a target user. According to the technical scheme, the client performs certificate verification with the server based on the encrypted domain adding certificate to obtain the target verification result, and the target user is authorized to log in the target terminal based on the target verification result, so that the technical problem of insufficient identity authentication security caused by the adoption of a Kerberos protocol in the prior art is solved, and the effect of improving the identity authentication security is achieved.
Owner:SHANGHAI NINGTON INFORMATION TECH CO LTD

Kerberos identity authentication system and method based on SM9 and biological characteristic fuzzy extraction

The invention belongs to the technical field of network security, and relates to a Kerberos identity authentication system and method based on SM9 and biological characteristic fuzzy extraction. The system comprises a biological characteristic key generation module used for extracting a stable cryptographic key from biological characteristics of a user; the SM9 digital identity management module is used for performing identity management based on a cryptographic key; the Kerberos protocol enhancement module is used for enhancing the security of the Kerberos protocol; and the safety fusing and managing module is used for monitoring an authentication process and executing a fusing mechanism. According to the invention, the SM9 digital signature of the timestamp is embedded in the Kerberos authentication request, and the signature verification is used as the precondition of bill signing and issuing, so that an attacker is difficult to forge an effective authentication certificate.
Owner:XIAN UNIV OF POSTS & TELECOMM

Data platform scheduling method and device

The invention relates to the technical field of big data application, in particular to a data platform scheduling method and device.The method comprises the steps that roles of a multi-data platform adopting multiple clusters are divided into master services and slave services, the slave services store docking operation between different clusters, and the master services store public operation between different clusters; in response to an access request of at least one target data platform in the multiple data platforms, obtaining main service information of a main service corresponding to the at least one target data platform based on an authentication platform in the multiple data platforms; and calling a corresponding slave service node based on the master service information, and completing scheduling of the at least one target data platform by the slave service node. Therefore, the problems that in the related technology, effective support for multiple sets of Kerberos security authentication clusters cannot be achieved, the optimization target of integrating multiple tenants into the same set of big data component cannot be achieved, and the integration and resource utilization efficiency of the whole system are limited are solved.
Owner:CHERY AUTOMOBILE CO LTD

Authentication management method of a server's BMC and related device

The application relates to the field of communication technology, in particular to a BMC authentication management method of a server and related devices. The method comprises the following steps: in response to a login request of a target user to the BMC, calling a Kerberos module through a PAM framework, storing connection parameters of a KDC and a key of the BMC by the BMC; performing service identity authentication based on the key of the BMC, the connection parameters and the KDC; if the service identity authentication is successful, performing user identity authentication based on identity credentials and the KDC; if the user identity authentication is successful, obtaining and using a TGT to request an ST for accessing a directory service from the KDC; querying the directory service by using the ST to obtain group membership information of the target user; and determining access rights of the target user to the BMC according to the group membership information and a predefined mapping rule. The application integrates Kerberos based on the PAM framework, provides a two-way authentication function, and effectively improves security.
Owner:SHENZHEN GOOXI INFORMATION SECURITY CO LTD

Identity security protection methods, systems, and storage media based on Azure AD control capabilities

The application belongs to the technical field of computer network security, and particularly relates to a Kerberos protocol weak encryption and cloud dynamic strategy combined privilege escalation method. The method comprises the following steps: using SYSTEM level permission to access a target user object in AD, modifying a preset condition conforming to a cloud privilege dynamic group membership rule to obtain a tampered target user attribute; using an Azure AD Connect synchronization service to mark the tampered target user attribute as an attribute update event, and determining that abnormal data flow conforms to normal business synchronization characteristics; constructing a ticket by using a Kerberos client library according to an NTLM hash of a target user account to obtain a fake ticket; the target user account is dynamically added to an associated global administrator role group to obtain a target user account with a global administrator session token; and the target user account is logged in to a PTA service channel by using the fake ticket to obtain Azure AD control capability.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Authentication management method of BMC of server and related device

The invention relates to the technical field of communication, in particular to an authentication management method of a BMC (Baseboard Management Controller) of a server and a related device. The method comprises the steps that a login request of a target user to a BMC is responded, a Kerberos module is called through a PAM framework, and the BMC stores connection parameters of a KDC and a secret key of the BMC; service identity authentication is carried out based on the key of the BMC, the connection parameters and the KDC; if the service identity authentication is successful, performing user identity authentication based on the identity credential and the KDC; if the user identity authentication succeeds, acquiring and using the TGT to request an ST used for accessing the directory service to the KDC; querying directory service by utilizing ST to obtain group member identity information of the target user; and determining the access authority of the target user to the BMC according to the group member identity information and a predefined mapping rule. According to the embodiment of the invention, Kerberos is integrated based on the PAM framework, a bidirectional authentication function is provided, and the security is effectively improved.
Owner:SHENZHEN GOOXI INFORMATION SECURITY CO LTD

Method, device and storage medium for kerberos permission management

The application discloses a permission management method and device for Kerberos and a storage medium, and relates to the field of user permission allocation.The method comprises the following steps: storing permission management information of a user in a Ranger permission service of the user; when it is monitored that the user accesses a hive database, it is judged whether the accessed hive database accords with the permission of the current user; if yes, the current user is allowed to use a Kerberos account; otherwise, the current user is prohibited from using the Kerberos account.The application stores the permission management information of the user in the Ranger permission service of the user, and then performs authentication through the Ranger permission service, so that the purpose of allowing the user who accords with the permission to use the Kerberos account and prohibiting the user who does not accord with the permission from using the Kerberos account is achieved.The application can perform permission management on the Kerberos account without increasing virtual machines, and thus resources can be greatly saved.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD