首页> 外国专利> Protecting passwords and biometrics against back-end security breaches

Protecting passwords and biometrics against back-end security breaches

机译:保护密码和生物识别技术免受后端安全漏洞的侵害

摘要

A method and system are provided for authenticating a user to an application back-end using a key pair and one or more bearer tokens such as a password, a biometric code, or a biometric key, while protecting the bearer tokens against back-end security breaches. In one embodiment, an application front-end authenticates the user by sending the bearer tokens and a public key to the application back-end, and demonstrating knowledge of a private key. The application back-end compares an authentication-phase tag derived from a joint hash of the public key and the bearer tokens against a registration-phase tag stored in a device record within a back-end database. The public key is not stored in the database, thereby depriving an adversary who breaches back-end security of information needed to test guesses of the bearer tokens.
机译:提供了一种方法和系统,用于使用密钥对和一个或多个承载令牌(例如密码,生物识别码或生物识别密钥)将用户认证到应用程序后端,同时保护承载令牌不受后端安全性的影响。违反。在一个实施例中,应用程序前端通过将承载令牌和公钥发送到应用程序后端,并展示对私钥的知识来认证用户。应用程序后端将源自公钥和承载令牌的联合哈希的认证阶段标签与存储在后端数据库内设备记录中的注册阶段标签进行比较。公钥未存储在数据库中,从而使攻击者破坏了后端安全性,而这些信息无法测试测试承载令牌的猜测所需的信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号