AUTHENTICATION SERVER AUDITING OF CLIENTS USING CACHE PROVISIONING
Sharing resources on a network include, for example, a domain controller hierarchy scheme, which is used in some implementations to organize and share both secure and non-secure resources in an efficient manner. Using authentication information can be used to architect a trustworthy system to divulging sensitive client data (such as user/computer passwords) to a host system. The sensitive client data can be released to the host system when a client establishes a relationship having a degree of trust with the host.
1 .- 20 . (canceled)
21 . A computer implemented method, the method comprising:
receiving an availability request from a client;
sending an encrypted secret to the client, wherein the encrypted secret includes a secret that is decryptable using a key;
receiving a resource request from the client, wherein the resource request includes the secret;
after receiving the resource request that includes the secret, caching information about the client.
22 . The method of claim 1 further comprising:
after receiving the availability request from the client, determining that information about the client is not cached;
sending the availability request to a hub domain controller;
in response to sending the availability request to the hub domain controller, receiving the encrypted secret from the domain hub controller;
after receiving the resource request from the client, verifying that the resource request cannot be decrypted;
sending the resource request to the hub domain controller;
in response to sending the resource request to the hub controller, receiving information regarding the resource;
sending the information regarding the resource to the client;
prior to caching the information about the client, sending a caching request to the central hub controller to cache information about the client;
in response to sending the caching request, receiving permission to cache the information about the client.
23 . The method of claim 21 , wherein the encrypted secret includes a ticket granting ticket and a session key.
24 . The method of claim 21 wherein the key is a client password.
25 . The method of claim 22 further comprising:
in response to sending the caching request, receiving a second secret and the key from the hub domain controller.
26 . The method of claim 25 , further comprising:
receiving a second resource request from the client;
determining information about the client is in the cache;
encrypting the second secret with the key;
after encrypting the second secret with the key, sending the second secret to the client.
27 . The method of claim 21 , wherein the resource request comprises a request to access another client computer.
28 . A system, the system comprising at least one processor operatively connected to a computer storage device, the computer storage device having instructions that, when executed by the at least one processor, cause the at least one processor to perform a method, the method comprising:
receiving an availability request from a client;
sending an encrypted secret to the client, wherein the encrypted secret includes a secret that is decryptable using a key;
receiving a resource request from the client, wherein the resource request includes the secret;
after receiving the resource request that includes the secret, caching information about the client.
29 . The system of claim 28 , the method further comprising:
after receiving the availability request from the client, determining that information about the client is not cached;
sending the availability request to a hub domain controller;
in response to sending the availability request to the hub domain controller, receiving the encrypted secret from the domain hub controller;
after receiving the resource request from the client, verifying that the resource request cannot be decrypted;
sending the resource request to the hub domain controller;
in response to sending the resource request to the hub controller, receiving information regarding the resource;
sending the information regarding the resource to the client;
prior to caching the information about the client, sending a caching request to the central hub controller to cache information about the client;
in response to sending the caching request, receiving permission to cache the information about the client.
30 . The system of claim 28 , wherein the encrypted secret includes a ticket granting ticket and a session key.
31 . The system of claim 28 , wherein the key is a client password.
32 . The system of claim 29 , the method further comprising:
in response to sending the caching request, receiving a second secret and the key from the hub domain controller.
33 . The system of claim 32 , the method further comprising:
receiving a second resource request from the client;
determining the information about the client is in the cache;
encrypting the second secret with the key;
after encrypting the second secret with the key, sending the second secret to the client.
34 . The system of claim 32 , wherein the resource request comprises a request to access another client computer.
35 . A computer storage device having instructions that when executed are capable of performing the method of:
receiving an availability request from a client;
sending an encrypted secret to the client, wherein the encrypted secret includes a secret that is decryptable using a key;
receiving a resource request from the client, wherein the resource request includes the secret;
after receiving the resource request that includes the secret, caching information about the client.
36 . The computer storage device of claim 35 further comprising:
after receiving the availability request from the client, determining that information about the client is not cached;
sending the availability request to a hub domain controller;
in response to sending the availability request to the hub domain controller, receiving the encrypted secret from the domain hub controller;
after receiving the resource request from the client, verifying that the resource request cannot be decrypted;
sending the resource request to the hub domain controller;
in response to sending the resource request to the hub controller, receiving information regarding the resource;
sending the information regarding the resource to the client;
prior to caching the information about the client, sending a caching request to the central hub controller to cache information about to the client;
in response to sending the caching request, receiving permission to cache the information about the client;
prior to caching information about the client, determining that the client is not on a deny list.
37 . The computer storage device of claim 35 , wherein the encrypted secret includes a ticket granting ticket and a session key.
38 . The computer storage device of claim 35 , wherein the key is a client password.
39 . The computer storage device of claim 38 , further comprising:
in response to sending the caching request, receiving a second secret and the key from the hub domain controller.
40 . The computer storage device of claim 39 , further comprising:
receiving a second resource request from the client;
determining the information about the client is in the cache;
encrypting the second secret with the key;
after encrypting the second secret with the key, sending the second secret to the client.