首页> 外国专利> PROTECTING AGAINST MALICIOUS DISCOVERY OF ACCOUNT EXISTENCE

PROTECTING AGAINST MALICIOUS DISCOVERY OF ACCOUNT EXISTENCE

机译:防范恶意的帐户存在发现

摘要

A sign-in system can be protected against enumeration attacks while providing an improved sign-in experience for legitimate users by disclosing whether or not an account exists. An account within a specified domain can be identified by an account identifier such as a username. Before a threshold throttling value is reached, account existence/non-existence information can be provided in response to an access request. In response to reaching or exceeding a specified threshold throttling value, account existence/non-existence information can cease to be provided. Entering a valid account identifier/authenticating credential credentials pair provides access to the computer system regardless of whether or not the threshold was reached or exceeded or not reached.
机译:通过公开帐户是否存在,可以保护登录系统免受枚举攻击,同时为合法用户提供更好的登录体验。指定域中的帐户可以通过帐户标识符(例如用户名)进行标识。在达到阈值调节值之前,可以响应于访问请求来提供帐户存在/不存在信息。响应于达到或超过指定的阈值限制值,可以停止提供帐户存在/不存在信息。输入有效的帐户标识符/身份验证凭据凭据对将提供对计算机系统的访问权限,而不管是否达到或超过了阈值。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号