Patent ReferencesMethod and apparatus for protecting the confidentiality of passwords in a distributed data processing system Public key data communications system under control of a portable security device Method and apparatus for retrieving X.509 certificates from an X.500 directory Distributed authentication system and method Patent #: 6230269 InventorsAssigneeApplicationNo. 09672496 filed on 09/29/2000US Classes:380/286, Key escrow or recovery380/281, Using master key (e.g., key-encrypting-key)380/277, KEY MANAGEMENT713/194, Tamper resistant707/9, Privileged access713/156, By certificate713/159, Including intelligent token713/182, SYSTEM ACCESS CONTROL BASED ON USER IDENTIFICATION BY CRYPTOGRAPHY713/189DATA PROCESSING PROTECTION USING CRYPTOGRAPHYExaminersPrimary: Rimell, SamAssistant: Betit, Jacob F. Attorney, Agent or FirmInternational ClassH04L009/00AbstractTo protect a private cryptographic key, two values are derived. The two values together can reconstruct the key. One value is sent to a server and deleted from the local machine. The other value is held by the local machine. To use the key, the user will enter a password, which will be used to authenticate the user to the server, and retrieve the value from the server. The password is also used to unlock the value held by the local machine. The private cryptographic key is thus protected against brute force password attacks without changing the behavior of the user. | |