首页> 外国专利> Using trusted communication channel to combat user name/password theft

Using trusted communication channel to combat user name/password theft

机译:使用受信任的通信渠道来打击用户名/密码盗窃

摘要

A technique for defining a system with enhanced trust is disclosed, in which an immediate contact is made with the user on the enhanced trust system when a compromise is first detected, e.g. when there is a second log in attempt from another location. Using these communications channels, the service can often contact the compromised user and ask for confirmation of the results, i.e. to change password or login, from a reduced trust machine. As a result, even if an attacker steals a password, the true user on the enhanced trust machine is able to preclude a login or preclude a password change. In each case, if the user of the enhanced trust machine does not respond within some short period of time, then a less trusted machine can be allowed to proceed. The invention comprehends two definitions of an enhanced trust machine. In a first embodiment of the invention, an enhanced trust machine is a machine where the user is currently logged in at the time that the second, less trusted machine attempts a login. A second embodiment of the invention comprehends an enhanced trust machine where the user has logged in repeatedly over a course of numerous weeks, as compared with a lesser trusted machine that the user has never logged into before and which is now asking for a change of the password. In this case, the system may or may not find the less trusted machine to be just that based on actions that are experientially inconsistent with what is expected.
机译:公开了一种用于定义具有增强的信任度的系统的技术,其中,当首先检测到损害时,例如在第一次发现损害时,立即与用户在增强的信任度系统上进行直接联系。当尝试从另一个位置进行第二次登录时。使用这些通信渠道,服务通常可以与受感染的用户联系,并要求对结果进行确认,即从简化的信任机器上更改密码或登录。结果,即使攻击者窃取了密码,增强型信任计算机上的真实用户也能够阻止登录或阻止密码更改。在每种情况下,如果增强型信任机的用户在短时间内都没有响应,则可以允许信任度较低的机器继续运行。本发明包含增强信任机的两个定义。在本发明的第一实施例中,增强型信任机是这样一种机器,在该机器中,当第二个不太受信任的机器尝试登录时,用户当前正在登录。本发明的第二实施例包括一种增强的信任机,其中与用户之前从未登录过并且现在正在要求更改密码的次信任度较低的机器相比,用户已经在多个星期的过程中重复登录。密码。在这种情况下,系统可能会或可能不会发现信任度较低的机器仅仅是基于经验上与预期不一致的动作。

著录项

  • 公开/公告号US6938167B2

    专利类型

  • 公开/公告日2005-08-30

    原文格式PDF

  • 申请/专利权人 JAMES ROSKIND;

    申请/专利号US20020323230

  • 发明设计人 JAMES ROSKIND;

    申请日2002-12-18

  • 分类号H04L9/00;

  • 国家 US

  • 入库时间 2022-08-21 22:20:15

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号