IP Library Granted Patent US 8,027,921
Granted Patent B1
US 8,027,921 · App. 10/075,336 · Granted Sep 27, 2011

Method and software for migrating protected authentication data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,027,921
App. No.
10/075,336
Granted
Sep 27, 2011
Kind
B1
Abstract

The present disclosure attempts to migrate from a first authenticator to a second authenticator. In the most preferred embodiment, the first step is to migrate the data that is not stored encrypted by a traditional replication or transformation between the datastores of the authenticators. The new authenticator is placed in position, while the old authenticator is maintained. When a user attempts to login, servlets check to see if the user's password exists within the datastore for the new authenticator. If not, then the user is sent to the old authenticator's sign-on page. When the user enters their authentication credentials into the old authenticator, a code snippet or second servlet will capture this information and, on confirmation from the old authenticator that the user is properly authenticated, use the captured information to populate the new datastore.

Claims (32)

1. A method for populating password data to a target datastore associated with a target user authenticator that is in communication with a source user authenticator after migration from the source user authenticator, the source user authenticator having associated with a source datastore comprising unencrypted user identification data and user authentication data encrypted with a proprietary encryption algorithm, while also responding to user requests for information, the method comprising:

migrating unencrypted data from the source datastore to the target datastore;

intercepting, by a servlet interceptor, a request from a user to access information protected by the target user authenticator;

prompting, by the servlet interceptor, the user for an identification;

receiving, by the servlet interceptor, the identification from the user;

locating, by the servlet interceptor, a corresponding identification in the target datastore;

searching, by the servlet interceptor, the target datastore for a user authentication data associated with the corresponding identification;

determining, by the servlet interceptor, that the target datastore does not include a user authentication data associated with the corresponding identification;

forwarding the intercepted request to the source user authenticator responsive to the determining;

prompting, by the source user authenticator, the user for identification and user authentication data;

receiving, by the source user authenticator, identification and user authentication data from the user;

monitoring, by a password capture process, the source user authenticator for an approval response;

detecting, by the password capture process, the approval response from the source user authenticator;

capturing, by the password capture process, the user authentication data provided to the source user authenticator by the user;

populating, by the password capture process, the target datastore with the captured user authentication data associated with the corresponding identification upon detecting the approval response.

2. The method of claim 1 , wherein after populating the target datastore, further comprising prompting for and receiving from the user the user authentication data associated with the identification.

3. The method of claim 2 , wherein the action of prompting for and receiving from the user the user authentication data associated with the identification comprises prompting for and receiving from the user the identification and the user authentication data associated with the identification.

4. The method of claim 1 , wherein migrating unencrypted data from the source datastore to the target datastore comprises:

reading unencrypted data from the source datastore, wherein the unencrypted data represents data for multiple users each having an associated user identification and an associated user authentication data;

converting the unencrypted data to be compatible with the target datastore; and

populating the target datastore with the converted data.

5. The method of claim 1 further comprising:

authenticating the received identification using the target user authenticator upon determining that the target datastore includes user authentication data associated with the corresponding identification.

6. The method of claim 5 , wherein authenticating the received identification further comprises prompting for and receiving from the user the user authentication data associated with the corresponding identification.

7. The method of claim 1 , wherein the target datastore is an LDAP compliant directory service.

8. The method of claim 1 , wherein the target datastore is a relational database.

9. The method of claim 1 , wherein the source datastore is a relational database.

10. The method of claim 1 , wherein the user is a person.

11. The method of claim 1 , wherein the user is a software object.

12. The method of claim 1 , wherein the user authentication data is a password.

13. The method of claim 1 , wherein receiving user authentication form a user further comprises:

prompting for and receiving the identification and the user authentication data from the user after the initial submission of the identification from the user.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →