USPatentGranted

System for increasing the difficulty of password guessing attacks in a distributed authentication scheme employing authentication tokens

Granted 13 Dec 1994 · no office action yet

Assignee:

Law firm: Law firm · Log in to unlock

Attorney: Attorney · Log in to unlock

Inventors: Charles W. Kaufman, Radia J. Pearlman, Morrie Gasser · Examiner: Tod R. Swann

Application
Not granted yet
filed 18 Mar 1993
Publication
Not published
not published
Patent· this page
US 5,373,559
granted 13 Dec 1994

Life of the patent

3 dated events
⤢ drag to zoom19941996199820002002200420062008201020122014ProsecutionTerm & fees
ProsecutionTerm & feeshover for detail · click to open

Abstract

An improved security system inhibits eavesdropping, dictionary attacks, and intrusion into stored password lists. In one implementation, the user provides a workstation with a \"password\", and a \"token\" obtained from a passive authentication token generator. The workstation calculates a \"transmission code\" by performing a first hashing algorithm upon the password and token. The workstation sends the transmission code to the server. Then, the server attempts to reproduce the transmission code by combining passwords from a stored list with tokens generated by a second identical passive authentication token generator just prior to receipt of the transmission code. If any password/token combination yields the transmission code, the workstation is provided with a message useful in communicating with a desired computing system; the message is encrypted with a session code calculated by applying a different hashing algorithm to the password and token. In another embodiment, the workstation transmits a user name to the authentication server. The server verifies the user name\'s validity, and uses an active authentication token generator to obtain a \"response\" to an arbitrarily selected challenge. The server generates a session code by performing a hashing algorithm upon the response and the password. The server sends the challenge and a message encrypted with the session code to the workstation. The workstation generates the session code by performing the hashing algorithm on the password and the received challenge, and uses the session code to decrypt the encrypted message. The message is useful in communicating with a desired computing system.

Claims

37 · 6 independent · depth 3
12345678910111213141516171819202122232425262728293031323334353637
37 granted claims

Classifications

2 codes
USPC · US Patent Classification
380/30380/25

Claim changes

Soon
Coming soonHow the claims changed between publication and grant

See which claims were amended, added or cancelled during examination, with every added and removed word marked.

AmendedAddedCancelledUnchanged

The published claims of this patent are not paired with the granted ones in what we hold.

File wrapper

Pendency
1.7 y
635 days filing → grant
Office actions
0
on the grant's record
Examiner
Tod R. Swann
art unit —
Citations: 6 back · 11 forward

Term & fees

See the term timeline — pendency span, in-force span, the maintenance fees paid and both computed expiry dates.

Log in to unlock

Validity challenges

See the validity challenges on record — reexaminations, IPRs and PGRs, with their institution decisions and outcomes.

Log in to unlock

Citations

See every patent this one cites and every patent that cites it back — publication, assignee, and how each one was found.

Log in to unlock