US2008134323A1PendingUtilityA1

Secure Authentication Systems and Methods

Assignee: INTERTRUST TECH CORPPriority: Apr 25, 2002Filed: Oct 29, 2007Published: Jun 5, 2008
Est. expiryApr 25, 2022(expired)· nominal 20-yr term from priority
G06F 21/6218G06F 21/36H04L 63/12H04L 63/083G06F 21/34H04L 63/105H04L 63/1458H04L 63/0815
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for authentication by combining a Reverse Turing Test (RTT) with password-based user authentication protocols to provide improved resistance to brute force attacks. In accordance with one embodiment of the invention, a method is provided for user authentication, the method including receiving a username/password pair associated with a user; requesting one or more responses to a first Reverse Turing Test (RTT); and granting access to the user if a valid response to the first RTT is received and the username/password pair is valid.

Claims

exact text as granted — not AI-modified
1 . A method for user authentication, the method comprising:
 receiving a username/password pair associated with a user;   requesting one or more responses to a first Reverse Turing Test (RTT); and   granting access to the user, if a valid response to the first RTT is received and the username/password pair is valid.   
   
   
       2 . The method of  claim 1 , wherein the step of requesting one or more responses comprises:
 checking if an entered username/password pair is valid; and   if the username/password pair is valid, requesting one or more responses based on a first RTT.   
   
   
       3 . The method of  claim 1 , the step of requesting one or more responses comprises:
 checking if an entered username/password pair is valid; and   if the username/password pair is invalid, requesting one or more responses based on a first RTT.   
   
   
       4 . The method of  claim 1 , the step of requesting one or more responses comprises:
 checking if an entered username/password pair is valid; and   if the username/password pair is invalid, not requesting one or more responses based on a first RTT.   
   
   
       5 . The method of  claim 1 , further comprising:
 if an invalid response to the first RTT is received:   requesting one or more responses based on a second RTT; and   denying access to the respondent regardless of whether the one or more responses to the second RTT are valid.   
   
   
       6 . The method of  claim 1 , wherein the first RTT is a deterministic function of the username/password pair. 
   
   
       7 . The method of  claim 1 , wherein the first RTT is a non-deterministic or random function that depends on the username/password pair with a predetermined probability. 
   
   
       8 . A method as in  claim 1 , wherein the first RTT is independent of the username/password pair. 
   
   
       9 . The method of  claim 1 , wherein the type of RTT used is selected from one or more types of RTTs. 
   
   
       10 . The method of  claim 9 , wherein for each type of RTT, the time between receiving a username/password pair and requesting one or more responses to a first RTT is the same. 
   
   
       11 . A method as in  claim 1 , further comprising:
 providing the user with a cookie, wherein the cookie indicates the user provided a valid response to the first RTT.   
   
   
       12 . A method for user authentication, the method comprising:
 sending to a user a request for username/password pair and a request for a response to a Reverse Turing Test (RTT);   receiving a valid response to the RTT from the user; and   authenticating user based on a valid user/password pair.   
   
   
       13 . A method as in  claim 12 , further comprising:
 providing the user with a cookie, wherein the cookie indicates the user correctly answered the RTT.   
   
   
       14 . A method as in  claim 12 , wherein sending to the user comprising:
 checking for a cookie stored on the user computer; and   if the cookie exists, sending to the user a request for username/password pair and not sending the request for a response to the RTT.   
   
   
       15 . A computer program package for user authentication, the computer program package providing instructions, which, if executed by a computer system, cause the system to perform operations comprising:
 receiving a username//password pair associated with a user;   requesting one or more responses to a first Reverse Turing Test (RTT); and   granting access to the user, if a valid response to the first RTT is received and the username/password pair is valid.   
   
   
       16 . A computer program package as in  claim 15 , wherein the step of requesting one or more responses comprises:
 checking if an entered username/password pair is valid; and   if the username/password pair is valid, requesting one or more responses based on a first RTT.   
   
   
       17 . A computer program package as in  claim 15 , wherein the step of requesting one or more responses comprises:
 checking if an entered username/password pair is valid; and   if the username/password pair is invalid, not requesting one or more responses based on a first RTT.   
   
   
       18 . A computer program package as in  claim 15 , the computer program package providing instructions, which, if executed by a computer system, cause the system to perform operations further comprising:
 if an invalid response to the first RTT is received:   requesting one or more responses based on a second RTT; and   denying access to the respondent regardless of whether the one or more responses to the second RTT are valid.   
   
   
       19 . A computer program package as in  claim 15 , wherein the first RTT is a deterministic function of the username/password pair. 
   
   
       20 . A computer program package as in  claim 15 , wherein the first RTT is a non-deterministic or random function that depends on the username/password pair with a predetermined probability. 
   
   
       21 . (canceled)

Join the waitlist — get patent alerts

Track US2008134323A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.