发明名称 Password-based authentication
摘要 Apparatus and methods are provided for use in multi-server authentication of user passwords. A password authentication system 1 includes an access control server 2 for communication with user computers 3 via a network 4. The access control server 2 controls access by the user computers 3 to a resource 5 in dependence on authentication of user passwords associated with respective user IDs. The system 1 further includes a plurality n of authentication servers 6, storing respective secret values, for communication with the access control server 2 via the network 4. For each user ID, the access control server 2 stores a first ciphertext produced by encrypting the user password associated with that ID using a predetermined algorithm dependent on the secret values of the authentication servers 6. The access control server 2 and authentication servers 6 are adapted such that, in response to receipt from a user computer 3 of a user ID and an input password, the access control server 2 communicates with a plurality k < n of the authentication servers 6 implement a password authentication protocol, requiring use by the k authentication servers of their respective secret values, in which a second ciphertext is produced by encrypting the input password using said predetermined algorithm and the access control server 2 uses the first and second ciphertexts to determine whether the input password equals the user password for the received user ID. If so, the access control server 2 permits the user computer 3 access to the resource 5.
申请公布号 GB2526367(A) 申请公布日期 2015.11.25
申请号 GB20140009227 申请日期 2014.05.23
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 JAN LEONHARD CAMENISCH;ANJA LEHMANN;GREGORY NEVEN
分类号 G06F21/30;H04L9/08;H04L9/32 主分类号 G06F21/30
代理机构 代理人
主权项
地址