U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Method and apparatus for protecting the confidentiality of passwords in a distributed data processing system

Patent 5418854 Issued on May 23, 1995. Estimated Expiration Date: Icon_subject May 23, 2012. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

Fast real-time public key cryptography
Patent #: 4399323
Issued on: 08/16/1983
Inventor: Henry

Digital signature system and method based on a conventional encryption function
Patent #: 4881264
Issued on: 11/14/1989
Inventor: Merkle

Secure management of keys using extended control vectors
Patent #: 4924515
Issued on: 05/08/1990
Inventor: Matyas, et al.

Method and apparatus for user identification based on permuted kernels
Patent #: 4932056
Issued on: 06/05/1990
Inventor: Shamir

Unforgeable personal identification system
Patent #: 4993068
Issued on: 02/12/1991
Inventor: Piosenka, et al.

Method for generating public and private key pairs without using a passphrase
Patent #: 5201000
Issued on: 04/06/1993
Inventor: Matyas, et al.

Cryptographic method for communication and electronic signatures
Patent #: 5297206
Issued on: 03/22/1994
Inventor: Orton

Fair cryptosystems and methods of use Patent #: 5315658
Issued on: 05/24/1994
Inventor: Micali

Inventors

Assignee

Application

No. 875050 filed on 04/28/1992

US Classes:

713/156, By certificate380/28, PARTICULAR ALGORITHMIC FUNCTION ENCODING380/30, Public key713/183Solely password entry (no record or token)

Examiners

Primary: Bowler, Alyssa H.
Assistant: Follansbee, John

Attorney, Agent or Firm

International Class

H04K 001/00

Abstract

Apparatus for protecting the confidentiality of a user's password during a remote login authentication exchange between a user node and a directory service node of a distributed, public key cryptography system includes a specialized server application functioning as an intermediary agent for the login procedure. The login agent has responsibility for approving the user's login attempt and distributing a private key to the user. However, the login agent is not trusted with the user's password and is therefore a "semi-trusted" node. In another aspect of the invention, a login protocol enables remote authentication of the user password without transmitting the password over the network.

Other References

  • Article entitled, "Reducing the Risks from Poorly Chosen Keys" by T. Mark et al., University of Cambridge Computer Laboratory Cambridge, England, from 12th Symposium on Operating System Principles 1989 at pp. 14-18
  • Article entitled, "SPX: Global Authentication Using Public Key Certificates" by J. J. Tardo et al. from Proceeding of IEEE Symp. Research in Security and Privacy, IEEE CS Press, 1991, at pp. 232-244
  • Article entitled, "Authentication for Distributed Systems" by T. Y. C. Woo et al., University of Texas at Austin, from Computer, IEEE Computer Society, Jan. 1992, at pp. 49-5
PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$18.95more info
 
Sign InRegister
Username  
Password   
forgot password?