Verification of password using a keyboard with a secure password entry mode

    公开(公告)号:US10187211B2

    公开(公告)日:2019-01-22

    申请号:US15441976

    申请日:2017-02-24

    申请人: BIOBEX, LLC

    摘要: The present invention includes a device and method to authenticate a user to a computer prior to the user having access to the computer or network. As user name and password protocols are nearly ubiquitous in authentication applications used today, there have been developed many nefarious techniques to defeat the security of such systems. It is relatively easy to write a computer program to guess passwords and then use those passwords to defeat security and cause harm and mischief to a computer, its users and others. To thwart such activity, the present invention provides a novel device that can be provided within a keyboard, in a computer, or in a third device having connectivity thereto. The device in conjunction with the method provides a secure password mode and a challenge/response protocol to verify that the password is entered in response to a particular request for a password.

    VERIFICATION OF PASSWORD USING A KEYBOARD WITH A SECURE PASSWORD ENTRY MODE
    2.
    发明申请
    VERIFICATION OF PASSWORD USING A KEYBOARD WITH A SECURE PASSWORD ENTRY MODE 有权
    使用具有安全密码输入模式的键盘验证密码

    公开(公告)号:US20140181529A1

    公开(公告)日:2014-06-26

    申请号:US14136069

    申请日:2013-12-20

    IPC分类号: H04L29/06

    摘要: The present invention includes a device and method to authenticate a user to a computer prior to the user having access to the computer or network. As user name and password protocols are nearly ubiquitous in authentication applications used today, there have been developed many nefarious techniques to defeat the security of such systems. It is relatively easy to write a computer program to guess passwords and then use those passwords to defeat security and cause harm and mischief to a computer, its users and others. To thwart such activity, the present invention provides a novel device that can be provided within a keyboard, in a computer, or in a third device having connectivity thereto. The device in conjunction with the method provides a secure password mode and a challenge/response protocol to verify that the password is entered in response to a particular request for a password.

    摘要翻译: 本发明包括在用户访问计算机或网络之前向计算机认证用户的设备和方法。 由于用户名和密码协议在今天使用的认证应用中几乎普遍存在,所以已经开发了许多恶意技术来打败这些系统的安全性。 编写计算机程序来猜测密码是相对容易的,然后使用这些密码来抵御安全性,并对计算机,其用户和其他用户造成危害和恶作剧。 为了阻止这种活动,本发明提供了可以在键盘,计算机或具有连接到其中的第三设备中提供的新型设备。 与该方法相结合的设备提供安全密码模式和质询/响应协议,以便根据具体的密码请求来验证输入密码。

    Verification of authenticity and responsiveness of biometric evidence and/or other evidence
    3.
    发明授权
    Verification of authenticity and responsiveness of biometric evidence and/or other evidence 有权
    验证生物特征证据和/或其他证据的真实性和反应性

    公开(公告)号:US09160536B2

    公开(公告)日:2015-10-13

    申请号:US13308462

    申请日:2011-11-30

    摘要: Authenticity and responsiveness of evidence (e.g., biometric evidence) may be validated without regard for whether there is direct control over a sensor that acquired the evidence. In some implementations, only a data block containing evidence that is (1) appended with a server-generated challenge (e.g., a nonce) and (2) signed or encrypted by the sensor may validate that the evidence is responsive to a current request and belongs to a current session. In some implementations, trust may be established and/or enhanced due to one or more security features (e.g., anti-spoofing, anti-tampering, and/or other security features) being collocated with the sensor at the actual sampling site.

    摘要翻译: 可以验证证据的真实性和反应性(例如,生物特征证据),而不考虑是否对获得证据的传感器有直接控制。 在一些实现中,只有包含(1)附加服务器生成的质询(例如,随机数)和(2)由传感器签名或加密的证据的数据块可以验证证据对当前请求的响应, 属于当前会话。 在一些实施方式中,由于与实际采样点处的传感器并置的一个或多个安全特征(例如,防欺骗,防篡改和/或其他安全特征),可以建立和/或增强信任。

    SECURE DISPLAY
    4.
    发明申请
    SECURE DISPLAY 有权
    安全显示

    公开(公告)号:US20130208103A1

    公开(公告)日:2013-08-15

    申请号:US13371175

    申请日:2012-02-10

    IPC分类号: H04N7/18 G06F21/00

    摘要: An electronic display is provided for facilitating authentication. The display may integrate one or more of a camera, microphone, fingerprint sensor, card reader, touch screen, and communication interface to collect biometric and other identification information to authenticate a user requesting access to the display. An integrated proximity or motion sensor may be used to track presence of the user. The user may be required to re-authenticate his identity after an absence from the display. The display may be a standalone device or may cooperate with an external computing device. The display may be configured to verify its identity to the external computing device. The display may be configured to perform its own authentication and authorization procedures before presenting content from an external device.

    摘要翻译: 提供电子显示器以便于认证。 显示器可以集成照相机,麦克风,指纹传感器,读卡器,触摸屏和通信接口中的一个或多个,以收集生物识别信息和其他识别信息,以认证请求访问显示器的用户。 可以使用集成的接近或运动传感器来跟踪用户的存在。 可能需要用户在不在显示器之后对其身份进行重新认证。 显示器可以是独立设备,或者可以与外部计算设备协作。 显示器可以被配置为验证其与外部计算设备的身份。 显示器可以被配置为在从外部设备呈现内容之前执行其自己的认证和授权过程。

    Verification of Authenticity and Responsiveness of Biometric Evidence And/Or Other Evidence
    5.
    发明申请
    Verification of Authenticity and Responsiveness of Biometric Evidence And/Or Other Evidence 有权
    验证生物特征证据和/或其他证据的真实性和反应性

    公开(公告)号:US20130111222A1

    公开(公告)日:2013-05-02

    申请号:US13286119

    申请日:2011-10-31

    IPC分类号: H04L9/00

    摘要: Authenticity and responsiveness of evidence (e.g., biometric evidence) may be validated without regard for whether there is direct control over a sensor that acquired the evidence. In some implementations, only a data block containing evidence that is (1) appended with a server-generated challenge (e.g., a nonce) and (2) signed by the sensor may validate that the evidence is responsive to a current request and belongs to a current session. In some implementations, trust may be established and/or enhanced due to one or more security features (e.g., anti-spoofing, anti-tampering, and/or other security features) being collocated with the sensor at the actual sampling site.

    摘要翻译: 可以验证证据的真实性和反应性(例如,生物特征证据),而不考虑是否对获得证据的传感器有直接控制。 在一些实现中,只有包含(1)附加服务器生成的质询(例如,随机数)和(2)由传感器签名的证据的数据块可以验证证据响应于当前请求并且属于 当前会话。 在一些实施方式中,由于与实际采样点处的传感器并置的一个或多个安全特征(例如,防欺骗,防篡改和/或其他安全特征),可以建立和/或增强信任。

    Secure display
    6.
    发明授权
    Secure display 有权
    安全显示

    公开(公告)号:US09066125B2

    公开(公告)日:2015-06-23

    申请号:US13371175

    申请日:2012-02-10

    摘要: An electronic display is provided for facilitating authentication. The display may integrate one or more of a camera, microphone, fingerprint sensor, card reader, touch screen, and communication interface to collect biometric and other identification information to authenticate a user requesting access to the display. An integrated proximity or motion sensor may be used to track presence of the user. The user may be required to re-authenticate his identity after an absence from the display. The display may be a standalone device or may cooperate with an external computing device. The display may be configured to verify its identity to the external computing device. The display may be configured to perform its own authentication and authorization procedures before presenting content from an external device.

    摘要翻译: 提供电子显示器以便于认证。 显示器可以集成照相机,麦克风,指纹传感器,读卡器,触摸屏和通信接口中的一个或多个,以收集生物识别信息和其他识别信息,以认证请求访问显示器的用户。 可以使用集成的接近或运动传感器来跟踪用户的存在。 可能需要用户在不在显示器之后对其身份进行重新认证。 显示器可以是独立设备,或者可以与外部计算设备协作。 显示器可以被配置为验证其与外部计算设备的身份。 显示器可以被配置为在从外部设备呈现内容之前执行其自己的认证和授权过程。

    VERIFICATION OF AUTHENTICITY AND RESPONSIVENESS OF BIOMETRIC EVIDENCE AND/OR OTHER EVIDENCE
    7.
    发明申请
    VERIFICATION OF AUTHENTICITY AND RESPONSIVENESS OF BIOMETRIC EVIDENCE AND/OR OTHER EVIDENCE 有权
    验证生物识别证据和/或其他证据的正当性和反应性

    公开(公告)号:US20130138964A1

    公开(公告)日:2013-05-30

    申请号:US13308462

    申请日:2011-11-30

    IPC分类号: H04L9/32

    摘要: Authenticity and responsiveness of evidence (e.g., biometric evidence) may be validated without regard for whether there is direct control over a sensor that acquired the evidence. In some implementations, only a data block containing evidence that is (1) appended with a server-generated challenge (e.g., a nonce) and (2) signed or encrypted by the sensor may validate that the evidence is responsive to a current request and belongs to a current session. In some implementations, trust may be established and/or enhanced due to one or more security features (e.g., anti-spoofing, anti-tampering, and/or other security features) being collocated with the sensor at the actual sampling site.

    摘要翻译: 可以验证证据的真实性和反应性(例如,生物特征证据),而不考虑是否对获得证据的传感器有直接控制。 在一些实现中,只有包含(1)附加服务器生成的质询(例如,随机数)和(2)由传感器签名或加密的证据的数据块可以验证证据对当前请求的响应, 属于当前会话。 在一些实施方式中,由于与实际采样点处的传感器并置的一个或多个安全特征(例如,防欺骗,防篡改和/或其他安全特征),可以建立和/或增强信任。