Invention Grant
- Patent Title: Protecting passwords and biometrics against back-end security breaches
-
Application No.: US15136834Application Date: 2016-04-22
-
Publication No.: US09887989B2Publication Date: 2018-02-06
- Inventor: Francisco Corella , Karen Pomian Lewison
- Applicant: Francisco Corella , Karen Pomian Lewison
- Applicant Address: US CA Carmichael
- Assignee: Pomian & Corella, LLC
- Current Assignee: Pomian & Corella, LLC
- Current Assignee Address: US CA Carmichael
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/32 ; G06F21/41 ; H04L9/32 ; H04L9/08

Abstract:
A method and system are provided for authenticating a user to an application back-end using a key pair and one or more bearer tokens such as a password, a biometric code, or a biometric key, while protecting the bearer tokens against back-end security breaches. In one embodiment, an application front-end authenticates the user by sending the bearer tokens and a public key to the application back-end, and demonstrating knowledge of a private key. The application back-end compares an authentication-phase tag derived from a joint hash of the public key and the bearer tokens against a registration-phase tag stored in a device record within a back-end database. The public key is not stored in the database, thereby depriving an adversary who breaches back-end security of information needed to test guesses of the bearer tokens.
Public/Granted literature
- US20160269393A1 PROTECTING PASSWORDS AND BIOMETRICS AGAINST BACK-END SECURITY BREACHES Public/Granted day:2016-09-15
Information query