发明名称 USABLE SECURITY OF ONLINE PASSWORD MANAGMENT WITH SENSOR-BASED AUTHENTICATION
摘要 A multi-party security protocol that incorporates biometric-based authentication and withstands attacks against any single party (e.g., mobile phone, cloud, or the user). The protocol involves the function split between mobile and cloud and the mechanisms to chain-hold the secrets. A key generation mechanisms binds secrets to a specific device or URL (uniform resource locator) by adding salt to a master credential. An inline CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) handling mechanism uses the same sensor modality as the authentication process, which not only improves the usability, but also facilitates the authentication process. This architecture further enhances existing overall system security (e.g., handling untrusted or compromised cloud service, phone being lost, impersonation, etc.) and also improves the usability by automatically handling the CAPTCHA.
申请公布号 US2016055328(A1) 申请公布日期 2016.02.25
申请号 US201514832954 申请日期 2015.08.21
申请人 Microsoft Technology Licensing, LLC 发明人 SHEN Guobin;YANG Fan;ZHOU Lidong
分类号 G06F21/32;H04L9/32;H04L29/06;H04L9/08 主分类号 G06F21/32
代理机构 代理人
主权项
地址 Redmond WA US