发明申请
- 专利标题: SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS
- 专利标题(中): 防止布鲁姆力量攻击的系统和方法
-
申请号: US11555030申请日: 2006-10-31
-
公开(公告)号: US20080120504A1公开(公告)日: 2008-05-22
- 发明人: Michael G. Kirkup , Herbert A. Little , Neil P. Adams
- 申请人: Michael G. Kirkup , Herbert A. Little , Neil P. Adams
- 申请人地址: CA Waterloo
- 专利权人: Research In Motion Limited
- 当前专利权人: Research In Motion Limited
- 当前专利权人地址: CA Waterloo
- 主分类号: H04L9/00
- IPC分类号: H04L9/00
摘要:
In a system and method for authenticating a client device by an authentication device, the client device user is assigned a PIN generated by the authentication device. The user provides the PIN and a password to the client device, from which the client device generates a symmetric key and further generates a public/private key pair. The private key is encrypted using the symmetric key and stored in encrypted form only. The public key and a message authentication code generated from the PIN are provided to the authentication device, which stores the public key. Subsequently, when the user seeks to be authenticated, the user enters a password at the client device, which is used to generate a symmetric key to decrypt the encrypted private key. A message to the authentication device is signed using the resultant value. The authentication device uses the public key to verify the signature of the message.
公开/授权文献
信息查询