Invention Grant
- Patent Title: Distributed single sign-on
-
Application No.: US16007205Application Date: 2018-06-13
-
Publication No.: US10164964B2Publication Date: 2018-12-25
- Inventor: Jan Camenisch , Yossi Gilad , Anja Lehmann , Zoltan A. Nagy , Gregory Neven
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Stosch Sabo
- Priority: GB1416888.4 20140925
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32 ; G06F21/41 ; H04L9/30 ; H04L9/08

Abstract:
Respective cryptographic shares of password data, dependent on a user password, are provided at n authentication servers. A number t1≤n of the password data shares determine if the user password matches a password attempt. Respective cryptographic shares of secret data, enabling determination of a username for each verifier server, are provided at n authentication servers. A number t2≤t1 of the shares reconstruct the secret data. For a password attempt, the user computer communicates with at least t1 authentication servers to determine if the user password matches the password attempt and, if so, the user computer receives at least t2 secret data shares from respective authentication servers. The user computer uses the secret data to generate, with T≤t1 of said t1 servers, a cryptographic token for authenticating the user computer to a selected verifier server, secret from said at least T servers, under said username.
Public/Granted literature
- US20180302396A1 DISTRIBUTED SINGLE SIGN-ON Public/Granted day:2018-10-18
Information query