发明名称 ONE-TIME PASSWORD ACCESS TO PASSWORD-PROTECTED ACCOUNTS
摘要 Systems and methods facilitate secure one-time-password access to an account in a remote server from an untrusted client. The system consists of an intermediary component whose salient components are a proxy component, a webserver component, and an encryption/decryption component, and it preserves the characteristics of both the server and client. In a man-in-the-middle fashion, the proxy substitutes a one-time password entered at a login interface with a true password, and forwards it to the remote login server. True passwords are encrypted using a seed associated with user identifiers, and a list of one-time passwords is generated/updated and stored on media or transmitted to an electronic device. Substitution takes place by decrypting the one-time password with the seed used for encryption, ensuring the proxy avoids storing the true password.
申请公布号 US2008276098(A1) 申请公布日期 2008.11.06
申请号 US20070852393 申请日期 2007.09.10
申请人 MICROSOFT CORPORATION 发明人 FLORENCIO DINEI A.;HERLEY CORMAC E.
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址