Invention Grant
- Patent Title: Authentication based on shared secret updates
-
Application No.: US16264897Application Date: 2019-02-01
-
Publication No.: US11463430B2Publication Date: 2022-10-04
- Inventor: Brian C. Mullins , Kevin Bowers
- Applicant: RSA Security LLC
- Applicant Address: US MA Bedford
- Assignee: RSA Security LLC
- Current Assignee: RSA Security LLC
- Current Assignee Address: US MA Bedford
- Agency: Danielson Legal LLC
- Main IPC: H04L9/26
- IPC: H04L9/26 ; H04L9/40 ; H04L9/08

Abstract:
Techniques are provided for authenticating a user using shared secret updates. One method comprises, in response to a first authentication of a client using a given shared secret, updating, by the server, the given shared secret using information from the first authentication as part of a secret update protocol to generate an updated shared secret; and evaluating a second authentication using the updated shared secret. An anomaly may be detected when the client attempts the second authentication using a shared secret and the server determines that the shared secret was previously used for an authentication. The server may detect a breach of shared secrets of multiple users by monitoring a number of the detected anomalies across a user population and initiate a predefined recovery flow depending upon a number of impacted users.
Public/Granted literature
- US20200252385A1 Authentication Based on Shared Secret Updates Public/Granted day:2020-08-06
Information query