Invention Grant
- Patent Title: Usable security of online password management with sensor-based authentication
-
Application No.: US14832954Application Date: 2015-08-21
-
Publication No.: US09858402B2Publication Date: 2018-01-02
- Inventor: Guobin Shen , Fan Yang , Lidong Zhou
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Rainier Patents, P.S.
- Main IPC: G06F21/32
- IPC: G06F21/32 ; H04L9/32 ; H04L29/06 ; H04L9/08

Abstract:
A multi-party security protocol that incorporates biometric-based authentication and withstands attacks against any single party (e.g., mobile phone, cloud, or the user). The protocol involves the function split between mobile and cloud and the mechanisms to chain-hold the secrets. A key generation mechanisms binds secrets to a specific device or URL (uniform resource locator) by adding salt to a master credential. An inline CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) handling mechanism uses the same sensor modality as the authentication process, which not only improves the usability, but also facilitates the authentication process. This architecture further enhances existing overall system security (e.g., handling untrusted or compromised cloud service, phone being lost, impersonation, etc.) and also improves the usability by automatically handling the CAPTCHA.
Public/Granted literature
- US20160055328A1 USABLE SECURITY OF ONLINE PASSWORD MANAGMENT WITH SENSOR-BASED AUTHENTICATION Public/Granted day:2016-02-25
Information query