首页> 外国专利> A method implemented by computer to prevent attacks against user authentication and software products thereof

A method implemented by computer to prevent attacks against user authentication and software products thereof

机译:一种计算机实现的防止对用户认证的攻击的方法及其软件产品

摘要

A computer implemented method to avoid attacks against user authentication, the method comprising: - receiving, through a first server (300), from a user, a request to log in to a service of said first server (300); said request including the provision of identification information that validates the identity of the user on the first server (300); and - authenticating by means of said first server (300), said identification information of said user to authorize said request for service session initiation, characterized in that the method comprises - using a second server (200), in connection with a computing device ( 100) of the user through a specialized program (101) installed in the user's computing device (100), to manage a status of the accounts that the user has on the first server (300), in which said status of accounts it is set as valid or invalid by the user through the specialized program (101) and stores in a memory of the second server (200), after a secure channel is defined between the second server (200) and the computing device (100), and wherein said secure channel is defined after a credential exchange is made between the second server (200) and the user; - receiving, through the second server (200), from said first server (300) a request about a status regarding a user account on the first server (300); - in response to receiving the request, initializing, through the second server (200), an exchange of credentials with the first server (300) to provide mutual authentication, the exchange of credentials being performed through an authentication procedure based on exchange of certificates between the first server (300) and the second server (200); - verify, through the second server (200), said account statement; and - sending, through the second server (200), said account statement to the first server (300), using this the account statement received to authorize said service login request if said account statement is set as valid or reject said service login request if said account status is set to invalid.
机译:一种避免攻击用户认证的计算机实现的方法,该方法包括:-通过第一服务器(300)从用户接收登录到所述第一服务器(300)的服务的请求;所述请求包括提供标识信息,该标识信息在第一服务器(300)上验证用户的身份; -通过所述第一服务器(300)对所述用户的所述标识信息进行认证,以授权所述服务会话发起请求,其特征在于,所述方法包括:-使用第二服务器(200),与计算设备连接(用户通过安装在用户计算设备(100)中的专用程序(101)来管理用户在第一服务器(300)上拥有的帐户状态,在该服务器中设置了帐户的所述状态在第二服务器(200)和计算设备(100)之间定义了安全通道之后,用户通过专用程序(101)将其确定为有效或无效并存储在第二服务器(200)的存储器中,其中在第二服务器(200)和用户之间进行凭证交换之后,定义所述安全信道; -通过第二服务器(200)从所述第一服务器(300)接收关于与第一服务器(300)上的用户账户的状态有关的请求; -响应于接收到该请求,通过第二服务器(200)初始化与第一服务器(300)的凭证交换以提供相互认证,凭证的交换通过基于认证之间的证书交换的认证过程来执行。第一服务器(300)和第二服务器(200); -通过第二服务器(200)验证所述帐户对帐单; -通过第二服务器(200)将所述帐户对帐单发送到第一服务器(300),如果所述帐户对帐单被设置为有效,则使用该帐户对帐单来授权所述服务登录请求,或者如果所述帐户对帐单被拒绝,则拒绝所述服务登录请求表示帐户状态设置为无效。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号