发明名称 Hash Synchronization for Preventing Unauthorized Server Access Using Stolen Passwords
摘要 Techniques for preventing unauthorized access to a server system using stolen passwords are provided. In one embodiment, the server system can store an ordered set of hash values for a user, where each hash value in the ordered set of hash values is generated by applying a hash function in an ordered set of hash functions to the user's password. The server system can further receive, from a client device, a login request for the user that includes a hashed version of the password, and can select a hash value in the ordered set of hash values using a server-side index that is synchronized with a client-side index on the client device. The server system can then grant the login request if the selected hash value matches the hashed version of the password.
申请公布号 US2015026784(A1) 申请公布日期 2015.01.22
申请号 US201313945530 申请日期 2013.07.18
申请人 VMware, Inc. 发明人 Kurkure Uday
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method for preventing unauthorized access to a server system using stolen passwords, the method comprising: storing, by the server system, an ordered set of hash values for a user, each hash value in the ordered set of hash values being generated by applying a hash function in an ordered set of hash functions to the user's password; receiving, by the server system, a login request for the user from a client device, the login request including a hashed version of the password; selecting, by the server system, a hash value in the ordered set of hash values using a server-side index that is synchronized with a client-side index on the client device; and granting, by the server system, the login request if the hash value matches the hashed version of the password.
地址 Palo Alto CA US