Invention Grant
- Patent Title: Securing passwords against dictionary attacks
-
Application No.: US14666277Application Date: 2015-03-23
-
Publication No.: US10027631B2Publication Date: 2018-07-17
- Inventor: Mira Belenkiy , Tolga Acar , Henry Nelson Jerez , Alptekin Kupcu
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Agency: Medley, Behrens & Lewis, LLC
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F7/04 ; H04L29/06 ; H04L9/08 ; H04L9/32

Abstract:
Described herein are various technologies pertaining to constructions of a password-based authentication protocol that are configured to allow a user to register with and authenticate to an online service without the online service receiving a password or a deterministic function of the password of the user. When registering with an online service, a client computing device establishes a cryptographically strong random secret and stores an encryption of such secret with a data storage device. The storage device also never receives the password or a deterministic function of the password. When the user wishes to authenticate to the online service, the user employs her password to retrieve the encrypted secret from the storage device, decrypts such secret, and utilizes the decrypted secret to answer a cryptographically strong challenge provided to the user by the online service upon the online service receiving a username pertaining to such user.
Public/Granted literature
- US20150195257A1 SECURING PASSWORDS AGAINST DICTIONARY ATTACKS Public/Granted day:2015-07-09
Information query