Password-based generation and management of secret cryptographic keys

    公开(公告)号:GB2543726A

    公开(公告)日:2017-04-26

    申请号:GB201703301

    申请日:2015-08-25

    Applicant: IBM

    Abstract: Methods and apparatus are provided for generating a secret cryptographic key of a user computer (3) which is connectable to a server (2) via a network (4). A secret user value is provided at the user computer (3). A secret server value is provided at the server (2) with a check value which encodes the secret user value and a user password. In response to input of an input password at the user computer (3), the user computer encodes the secret user value and the input password to produce a first value corresponding to said check va1ue, and communicates the first value to the server (2) via the network (4). In response, the server (2) compares the first value and the check value to check whether the input password equals the user password. If so, the server (2) encodes the first value and said secret server value to produce a second value and communicates the second value to the user computer (3) via the network (4). In response, the user computer generates the secret cryptographic key by encoding the second value, the input password and the secret user value.

Patent Agency Ranking