发明名称 Applying a partial password in a multi-factor authentication scheme
摘要 A method includes transmitting a User ID and a full Password of a user of a client device to a server via the client device, and then establishing a network connection between the client device and the server after the User ID and the full Password. The method also includes receiving, from the server via the client device, an encrypted secret PIN (ESPIN) and a challenge for corresponding positions of a Partial Password, entering the Partial Password via the client device, and computing a secret PIN (SPIN) from the ESPIN via the client device in response to a correct entry of the Partial Password. The Additional Factor is unlocked using the SPIN, and the unlocked Additional Factor is transmitted to the server to request authentication of the user of the client device. The client device includes a processor and memory having instructions for the above method.
申请公布号 US9210166(B2) 申请公布日期 2015.12.08
申请号 US201314105270 申请日期 2013.12.13
申请人 CA, Inc. 发明人 Sama VenkataBabji
分类号 H04L9/32;H04L29/06;G06F21/31 主分类号 H04L9/32
代理机构 Vierra Magen Marcus LLP 代理人 Vierra Magen Marcus LLP
主权项 1. A method comprising: transmitting a User ID and a full Password of a user of a client device to a server via the client device; establishing a network connection between the client device and the server after transmitting the User ID and the full Password; receiving, from the server via the client device, an encrypted secret PIN (ESPIN) and a challenge for corresponding positions of a Partial Password; receiving the Partial Password via the client device; computing a secret PIN (SPIN) from the ESPIN via the client device in response to a correct entry of the Partial Password into the client device; unlocking, via the client device, an Additional Factor using the SPIN; and transmitting the unlocked Additional Factor to the server to request an authentication by the server of the user of the client device.
地址 New York NY US