Invention Grant
- Patent Title: Securing passwords against dictionary attacks
- Patent Title (中): 保护密码免受字典攻击
-
Application No.: US12755426Application Date: 2010-04-07
-
Publication No.: US09015489B2Publication Date: 2015-04-21
- Inventor: Mira Belenkiy , Tolga Acar , Henry Nelson Jerez Morales , Alptekin Kupcu
- Applicant: Mira Belenkiy , Tolga Acar , Henry Nelson Jerez Morales , Alptekin Kupcu
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agent Julie Kane Akhter; Danielle Johnston-Holmes; Micky Minhas
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F7/04 ; H04L29/06 ; H04L9/08 ; H04L9/32

Abstract:
Described herein are various technologies pertaining to constructions of a password-based authentication protocol that are configured to allow a user to register with and authenticate to an online service without the online service receiving a password or a deterministic function of the password of the user. When registering with an online service, a client computing device establishes a cryptographically strong random secret and stores an encryption of such secret with a data storage device. The storage device also never receives the password or a deterministic function of the password. When the user wishes to authenticate to the online service, the user employs her password to retrieve the encrypted secret from the storage device, decrypts such secret, and utilizes the decrypted secret to answer a cryptographically strong challenge provided to the user by the online service upon the online service receiving a username pertaining to such user.
Public/Granted literature
- US20110252229A1 SECURING PASSWORDS AGAINST DICTIONARY ATTACKS Public/Granted day:2011-10-13
Information query