Back-end matching method supporting front-end knowledge-based probabilistic authentication systems for enhanced credential security
US9215072B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Oct 23, 2012 |
| Grant date | Dec 15, 2015 |
| Priority date | — |
| Expiry date | Aug 27, 2034 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/083
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A party can authenticate itself by interacting with multiple servers without revealing the shared secret to any of the involved parties. The stored shared secret is strengthened and broken into shares and saved on the servers. The shared secret is safe against offline brute force attack unless all servers where the shares are stored are compromised. The compromise of any single server, or multiple servers—but less than the maximum number—will not allow the attacker to do a brute force analysis on the shared secret. This back end security enhancement is suitable for probabilistic front end authentication algorithms.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.