会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method and apparatus for extracting authentication information from a user
    • 从用户提取认证信息的方法和装置
    • US08639937B2
    • 2014-01-28
    • US10723416
    • 2003-11-26
    • Amit BaggaJon BentleyLawrence O'Gorman
    • Amit BaggaJon BentleyLawrence O'Gorman
    • G06F21/00
    • G06F21/46G07C9/00142
    • A method and apparatus are provided for extracting information from a user's memory that will be easily recalled during future authentication yet is hard for an attacker to guess. The information might be a little-known fact of personal relevance to the user or the personal details surrounding a public event. The user is guided to appropriate topics and forms an indirect hint that is useful to the user yet not to an attacker. Information extraction techniques verify that the information is not easily attacked and to estimate how many bits of assurance the question and answer provide. The information extracted may be, e.g., Boolean (Yes/No), multiple choice, numeric, textual, or a combination of the foregoing. The enrollment process may schedule the sending of one or more reminder messages to the user containing the question (but not the answer) to reinforce the memory of the user.
    • 提供了一种用于从用户的存储器提取信息的方法和装置,该信息将在以后的认证期间容易地被调用,但是攻击者很难猜测。 这些信息可能是一个鲜为人知的事实,即个人与用户的相关性或公共活动周围的个人信息。 用户被引导到适当的主题,并形成对用户而不是攻击者有用的间接提示。 信息提取技术验证信息不容易被攻击,并估计问题和答案提供的保证数量。 提取的信息可以是例如布尔(是/否),多项选择,数字,文本或前述的组合。 注册过程可以安排向包含问题(但不是答案)的用户发送一个或多个提醒消息以加强用户的存储器。
    • 3. 发明申请
    • Method and apparatus for extracting authentication information from a user
    • 从用户提取认证信息的方法和装置
    • US20050114679A1
    • 2005-05-26
    • US10723416
    • 2003-11-26
    • Amit BaggaJon BentleyLawrence O'Gorman
    • Amit BaggaJon BentleyLawrence O'Gorman
    • G07C9/00H04K1/00H04L9/00
    • G06F21/46G07C9/00142
    • A method and apparatus are provided for extracting information from a user's memory that will be easily recalled during future authentication yet is hard for an attacker to guess. The information might be a little-known fact of personal relevance to the user or the personal details surrounding a public event. The user is guided to appropriate topics and forms an indirect hint that is useful to the user yet not to an attacker. Information extraction techniques verify that the information is not easily attacked and to estimate how many bits of assurance the question and answer provide. The information extracted may be, e.g., Boolean (Yes/No), multiple choice, numeric, textual, or a combination of the foregoing. The enrollment process may schedule the sending of one or more reminder messages to the user containing the question (but not the answer) to reinforce the memory of the user.
    • 提供了一种用于从用户的存储器提取信息的方法和装置,该信息将在以后的认证期间容易地被调用,但是攻击者很难猜测。 这些信息可能是一个鲜为人知的事实,即个人与用户的相关性或公共活动周围的个人信息。 用户被引导到适当的主题,并形成对用户而不是攻击者有用的间接提示。 信息提取技术验证信息不容易被攻击,并估计问题和答案提供的保证数量。 提取的信息可以是例如布尔(是/否),多项选择,数字,文本或前述的组合。 注册过程可以安排向包含问题(但不是答案)的用户发送一个或多个提醒消息以加强用户的存储器。
    • 4. 发明申请
    • Method and apparatus for generating and reinforcing user passwords
    • 用于生成和加强用户密码的方法和装置
    • US20050071686A1
    • 2005-03-31
    • US10674288
    • 2003-09-29
    • Amit BaggaJon BentleyLawrence O'Gorman
    • Amit BaggaJon BentleyLawrence O'Gorman
    • G06F12/14G06F21/00
    • G06F21/46
    • A method and apparatus are provided for generating passwords that may be memorized by a user, yet not easily guessed by an attacker. A user is presented with one or more textual, audio or visual hints. A password is automatically generated based on the selected hint (and possibly further input from the user). The presented hints may include poems, songs, jokes, pictures or words. The generated password and selected hint can be presented to the user during enrollment for further reinforcement and stored in a user database for subsequent reinforcement and verification. The enrollment process may schedule the sending of one or more reminder messages to the user containing the hint to reinforce the password in the user's memory.
    • 提供了一种方法和装置,用于产生可由用户存储但不容易被攻击者猜到的密码。 用户被呈现一个或多个文字,音频或视觉提示。 根据所选择的提示(以及可能从用户的进一步输入)自动生成密码。 所提供的提示可能包括诗歌,歌曲,笑话,图片或单词。 生成的密码和选择的提示可以在注册期间呈现给用户以进一步加强,并存储在用户数据库中用于随后的加强和验证。 注册过程可以安排向用户发送一个或多个提醒消息,其中包含用于在用户的存储器中强化密码的暗示。
    • 6. 发明授权
    • Method and apparatus for generating and reinforcing user passwords
    • 用于生成和加强用户密码的方法和装置
    • US07873995B2
    • 2011-01-18
    • US10674288
    • 2003-09-29
    • Amit BaggaJon BentleyLawrence O'Gorman
    • Amit BaggaJon BentleyLawrence O'Gorman
    • G06F12/00
    • G06F21/46
    • A method and apparatus are provided for generating passwords that may be memorized by a user, yet not easily guessed by an attacker. A user is presented with one or more textual, audio or visual hints. A password is automatically generated based on the selected hint (and possibly further input from the user). The presented hints may include poems, songs, jokes, pictures or words. The generated password and selected hint can be presented to the user during enrollment for further reinforcement and stored in a user database for subsequent reinforcement and verification. The enrollment process may schedule the sending of one or more reminder messages to the user containing the hint to reinforce the password in the user's memory.
    • 提供了一种方法和装置,用于产生可由用户存储但不容易被攻击者猜到的密码。 用户被呈现一个或多个文字,音频或视觉提示。 根据所选择的提示(以及可能从用户的进一步输入)自动生成密码。 所提供的提示可能包括诗歌,歌曲,笑话,图片或单词。 生成的密码和选择的提示可以在注册期间呈现给用户以进一步加强,并存储在用户数据库中用于随后的加强和验证。 注册过程可以安排向用户发送一个或多个提醒消息,其中包含用于在用户的存储器中强化密码的暗示。
    • 9. 发明申请
    • Secure recoverable passwords
    • 安全可恢复密码
    • US20070079143A1
    • 2007-04-05
    • US11238860
    • 2005-09-29
    • Lookman Y. FazalLawrence O'GormanAmit Bagga
    • Lookman Y. FazalLawrence O'GormanAmit Bagga
    • G06F12/14
    • G06F21/31G06F2221/2131
    • A method and apparatus are disclosed that enable a user who forgets one of his two passwords to securely recover the forgotten password. After a user logs in using one of his two passwords, the illustrative embodiment reveals the other password to the user. The passwords are stored in a persistent table in both hashed and encrypted forms, but not in their original forms. The illustrative embodiment is advantageous over the prior art, where forgotten passwords are reset to a default value, in two ways. First, it avoids the inconvenience of a user having to log in using the default password, think up a new string that would make a good password, and change the password from the default to the new string. Second, it avoids the use of default-value passwords that might compromise security.
    • 公开了一种方法和装置,其使得能够忘记他的两个密码之一的用户安全地恢复被忘记的密码。 在用户使用他的两个密码之一登录之后,说明性实施例向用户显示另一个密码。 密码以散列和加密形式存储在持久性表中,但不以原始形式存储。 说明性实施例相对于现有技术是有利的,其中忘记的密码以两种方式被重置为默认值。 首先,它避免了用户不得不使用默认密码登录的不便,考虑一个将创建良好密码的新字符串,并将密码从默认值更改为新字符串。 第二,它避免使用可能危及安全性的默认值密码。
    • 10. 发明申请
    • Method and apparatus for authenticating a user using query directed passwords
    • 用于使用查询定向密码认证用户的方法和装置
    • US20050039057A1
    • 2005-02-17
    • US10626483
    • 2003-07-24
    • Amit BaggaJon BentleyLawrence O'Gorman
    • Amit BaggaJon BentleyLawrence O'Gorman
    • G06F21/00G06F11/30G06F12/14
    • G06F21/46G06F21/40G06F2221/2103G06F2221/2131
    • A query directed password scheme is disclosed that employs attack-resistant questions having answers that generally cannot be correlated with the user using online searching techniques, such as user opinions, trivial facts, or indirect facts. During an enrollment phase, the user is presented with a pool of questions from which the user must select a subset of such questions to answer. Information extraction techniques optionally ensure that the selected questions and answers cannot be correlated with the user. A security weight can optionally be assigned to each selected question. The selected questions should optionally meet predefined criteria for topic distribution. During a verification phase, the user is challenged with a random subset of the questions that the user has previously answered and answers these questions until a level of security for a given application is exceeded as measured by the number of correct questions out of the number of questions asked. Security may be further improved by combining the query directed password protocol with one or more additional factors such as Caller ID that assure that the questions are likely asked only to the registered user.
    • 公开了一种查询定向密码方案,其采用具有通常不能使用在线搜索技术(例如用户意见,微不足道的事实或间接事实)与用户相关的答案的防攻击问题。 在注册阶段,向用户呈现一个问题池,用户必须从中选择一个这样的问题的子集来回答。 信息提取技术可选地确保所选问题和答案不能与用户相关联。 可以选择将安全权重分配给每个选定的问题。 选定的问题应该可选地满足主题分发的预定义标准。 在验证阶段期间,用户受到用户以前回答的问题的随机子集的挑战,并且回答这些问题,直到超过给定应用程序的安全级别超过了正确问题的数量 问题。 可以通过将查询定向密码协议与一个或多个附加因素(例如来电者ID)相结合来进一步改善安全性,以确保可能仅向注册用户询问问题。