首页> 外国专利> One-time password authentication employing local testing of candidate passwords from one-time password server

One-time password authentication employing local testing of candidate passwords from one-time password server

机译:一次性密码认证,采用一次密码服务器对候选密码进行本地测试

摘要

A computing system has a local computing domain coupled to a one-time password (OTP) server. The OTP server maintains user-specific secret data used in a one-time-password (OTP) process to generate OTPs for user authentication. An authentication server in the computing domain sends an OTP request identifying a user to the OTP server. The OTP server executes the OTP process to generate a set of candidate OTPs, any one of which is expected to match a user-generated OTP for a valid authentication. The OTP server returns a response to the authentication server which includes second hashed OTP values, each generated by applying a hash function to a respective candidate OTP. The authentication server performs a comparison function between a first hashed OTP value from the user and the second hashed OTP values. Only upon determining that the first hashed OTP value matches one of the second hashed OTP values, the authentication server performs a protected function in the computing domain that is permitted only upon authentication of the user. Applications include authentication in a ticket-based authentication scheme such as a Kerberos system, in which the protected function may be the granting of a ticket-granting ticket enabling the user to engage service servers in the computing domain.
机译:计算系统具有耦合到一次性密码(OTP)服务器的本地计算域。 OTP服务器维护一次性密码(OTP)流程中使用的用户特定秘密数据,以生成用于用户身份验证的OTP。计算域中的身份验证服务器向OTP服务器发送一个标识用户的OTP请求。 OTP服务器执行OTP流程以生成一组候选OTP,这些候选OTP均应与用户生成的OTP匹配以进行有效身份验证。 OTP服务器向认证服务器返回响应,该响应包括第二散列的OTP值,每个散列的OTP值通过将散列函数应用于相应的候选OTP而生成。认证服务器在来自用户的第一哈希的OTP值和第二哈希的OTP值之间执行比较功能。仅在确定第一散列OTP值与第二散列OTP值之一匹配时,认证服务器才在计算域中执行仅在用户认证时才允许的受保护功能。应用包括基于票证的认证方案(例如Kerberos系统)中的认证,其中受保护的功能可能是授予票证的票证,使用户能够使用计算域中的服务服务器。

著录项

  • 公开/公告号US8412928B1

    专利类型

  • 公开/公告日2013-04-02

    原文格式PDF

  • 申请/专利权人 PIERS BOWNESS;

    申请/专利号US20100750758

  • 发明设计人 PIERS BOWNESS;

    申请日2010-03-31

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 16:43:29

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号