发明申请
US20080120504A1 SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS 有权
防止布鲁姆力量攻击的系统和方法

SYSTEM AND METHOD FOR PROTECTING A PASSWORD AGAINST BRUTE FORCE ATTACKS
摘要:
In a system and method for authenticating a client device by an authentication device, the client device user is assigned a PIN generated by the authentication device. The user provides the PIN and a password to the client device, from which the client device generates a symmetric key and further generates a public/private key pair. The private key is encrypted using the symmetric key and stored in encrypted form only. The public key and a message authentication code generated from the PIN are provided to the authentication device, which stores the public key. Subsequently, when the user seeks to be authenticated, the user enters a password at the client device, which is used to generate a symmetric key to decrypt the encrypted private key. A message to the authentication device is signed using the resultant value. The authentication device uses the public key to verify the signature of the message.
信息查询
0/0