-
公开(公告)号:GB2530726B
公开(公告)日:2016-11-02
申请号:GB201416888
申请日:2014-09-25
Applicant: IBM
Inventor: JAN LEONHARD CAMENISCH , YOSSI GILAD , ANJA LEHMANN , ZOLTAN ARNOLD NAGY , GREGORY NEVEN
Abstract: Respective cryptographic shares of password data, dependent on a user password, are provided at n authentication servers. A number t1≤n of the password data shares determine if the user password matches a password attempt. Respective cryptographic shares of secret data, enabling determination of a username for each verifier server, are provided at n authentication servers. A number t2≤t1 of the shares reconstruct the secret data. For a password attempt, the user computer communicates with at least t1 authentication servers to determine if the user password matches the password attempt and, if so, the user computer receives at least t2 secret data shares from respective authentication servers. The user computer uses the secret data to generate, with T≤t1 of said t1 servers, a cryptographic token for authenticating the user computer to a selected verifier server, secret from said at least T servers, under said username.