CN1446331A

System, methods, and software for remote password authentication using multiple servers

Abstract

The system, method and software adopt the zero-knowledge password (ZKP) protocol to provide strong authentication using low-level passwords that are easy for users to remember. The protocol we describe allows multiple servers to verify passwords without providing any single server, client, or capable cyber attacker to confirm the password guess offline. Additional improvements include eliminating reliance on existing secure channels and client-stored passwords or certificates, increasing performance without introducing new password assumptions, and better management of errors in password input. To register, the user selects a password and processes the master key K composed of multiple shared parts. The master key can be used for multiple purposes, such as decrypting the user's private key or other sensitive data. Choose a set of random values {y1, Y2,...Yn}, press K in the appropriate finite groupi=PyiCalculate each shared part. Will each yiThe value is assigned to the i-th of N serversthA. For verification, the client chooses a random security x, and with each server, sends Px, Search for mi=(Px)yiAnd calculate Ki=mi1/x. The client reconstructs K, performs a confirmation test on K, and uses K to decrypt the private digital signature key U. When the test is confirmed to be successful, the client signs the message with U containing Px and any other values sent by the client based on the wrong password entered by the same user in the verification attempt. Each server verifies the signed message to verify the user and forgive the user for some reasonably counted errors. Through knowledge of valid messages, errors, etc., the server fine-tunes the statistics of invalid access attempts. No single server knows K, P, or any KiThe shared part, and there is no server receiving enough information to launch a dictionary attack on K or P. Use a very simple model to maintain password security, without requiring existing security or server authentication channels between the client or any server. This model further prevents the risks inherent in the system where people have to verify the server, but the model does not need to verify the server. Data protected by a small password and no other keys are still safe even if any one of two or more collaborative authentication servers is compromised, but not all opponents.

CN1446331A, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 31 May 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

24 claims: 3 independent, 21 dependent

  1. 1
    一种系统,提供远程密码验证,包括:客户计算机;多个验证服务器;网络,互联客户计算机和多个验证服务器;在客户计算机和多个验证服务器上运行的软件,用来在客户机上输入密码,在每个服务器上存储唯一随机值yi、从密码导出群元素(P),将隐秘密码值(Px)发送给服务器,从服务器检索隐秘密钥共享部分不隐秘和结合共享部分来创建主密钥(Km)以及使用主密钥(Km)在客户计算机上解密加密的私有数据。
  2. 2
    如权利要求1所述的系统,其中在客户机上操作的软件用来确认主密钥(Km)。
  3. 3
    如权利要求1所述的系统,其中在客户机上操作的软件用来使用主密钥(Km)解密加密的私有数据。
  4. 4
    如权利要求2所述的系统,其中在客户机上操作的软件用来使用确认的主密钥(Km)来解密加密的私有数据。
  5. 5
    如权利要求2所述的系统,其中在客户机上操作的软件用来将验证的主密钥(Km)的证明以及每个隐秘密码值(Px)发送给服务器。
  6. 6
    一种方法,使用包括客户计算机、多个验证服务器以及互联客户计算机和多个验证服务器的网络,提供远程密码验证,该方法包括步骤:输入密码;从密码导出群元素(P);将隐秘密码值(Px)发送给服务器;从服务器检索隐秘密码共享部分 不隐秘并结合共享部分来创建主密钥(Km);以及使用主密钥(Km)解密在客户计算机上的加密的私有数据。
  7. 7
    如权利要求6所述的方法,进一步包括确认主密钥(Km)的步骤。
  8. 8
    如权利要求6所述的方法,其中在客户机上操作的软件使用主密钥(Km)来解密加密的私有数据。
  9. 9
    如权利要求7所述的方法,进一步包括使用确认的主密钥(Km)解密加密的私有数据的步骤。
  10. 10
    如权利要求7所述的方法,进一步包括将确认的主密钥(Km)的证明和每个隐秘密码值(Px)发送给服务器的步骤。
  11. 11
    一种包含在计算机可读介质上的计算机程序,用于启动在多服务器系统中的远程密码验证,多服务器系统包括客户计算机、多个验证服务器以及互联客户计算机和多个验证服务器的网络,计算机程序包括:输入密码的代码段;数据存储区域,包含在每个服务器上的唯一随机值yi;从密码导出群元素(P)的代码段;将隐秘密码值(Px)发送给服务器的代码段;从服务器检索隐秘密码部分 的代码段;不隐秘并结合共享部分来创建主密钥(Km)的代码段;以及使用主密钥(Km)解密在客户计算机上的加密私有数据的代码段。
  12. 12
    如权利要求11所述的计算机程序,进一步包括确认主密钥(Km)的代码段。
  13. 13
    如权利要求11所述的计算机程序,进一步包括使用主密钥(Km)解密加密私有数据的代码段。
  14. 14
    如权利要求12所述的计算机程序,进一步包括使用确认的主密钥(Km)解密加密的私有数据的代码段。
  15. 15
    如权利要求12所述的计算机程序,进一步包括将确认主密钥(Km)的证明和隐秘密码值(Px)发送给服务器的代码段。
  16. 16
    如权利要求1所述的系统,其中软件用来:保持无效登录尝试的计数、最近放大的次数、最近密码Px放大请求值的列表以及与在服务器上的最近密码放大请求值列表有关的时间戳列表;接收隐秘密码(Px)请求;在短期列表中记录隐秘密码;核对用户帐户以查看是否被锁定;如果未被锁定,创建隐秘密钥共享部分 以及将隐秘密钥共享部分发送给客户计算机。
  17. 17
    如权利要求16所述的系统,其中软件:记录时间戳值以记下接收请求的时间;定期核对当任一时间戳值与当前时间间的差值大于特定时间周期时确定的失效请求;删除相应的密码放大请求值以及时间戳;以及递增无效尝试的计数。
  18. 18
    如权利要求16所述的系统,其中,当成功登录时,软件:发送QA以及来自在相同登录会话中先前运行的用于QA的任一在前值给加密消息中的每个服务器,QA等于密码自乘以随机次幂;以及使用主密钥Km验证该消息。
  19. 19
    如权利要求6所述的方法,进一步包括步骤保持无效登录尝试计数、最近放大的次数、最近密码Px放大请求值的列表以及与服务器上的最近密码放大请求值列表有关的时间戳列表;接收隐秘密码(Px)请求;在短期列表中记录隐秘密码;核对用户帐户以查看是否被锁定;如果未被锁定,创建隐秘密钥共享部分 以及将隐秘密钥共享部分发送给客户计算机。
  20. 20
    如权利要求19所述的系统,其中软件:记录时间戳值以记下接收请求的时间;定期核对当任一时间戳值与当前时间间的差值大于特定时间周期时确定的失效请求;删除相应的密码放大请求值以及时间戳;以及递增无效尝试的计数。
  21. 21
    如权利要求19所述的方法,进一步包括步骤发送QA以及来自在相同登录会话中先前运行的用于QA的任一在前值给加密消息中的每个服务器,QA等于密码自乘以随机次幂;以及使用主密钥Km验证该消息。
  22. 22
    如权利要求11所述的计算机系统,进一步包括代码段:保持无效登录尝试计数、最近放大的次数、最近密码Px放大请求值的列表以及与服务器上的最近密码放大请求值列表有关的时间戳列表;接收隐秘密码(Px)请求;在短期列表中记录隐秘密码;核对用户帐户以查看是否被锁定;如果未被锁定,创建隐秘密钥共享部分 以及将隐秘密钥共享部分发送给客户计算机。
  23. 23
    如权利要求22所述的计算机程序,进一步包括代码段:记录时间戳值以记下接收请求的时间;定期核对当任一时间戳值与当前时间间的差值大于特定时间周期时确定的失效请求;删除相应的密码放大请求值以及时间戳;以及递增无效尝试的计数。
  24. 24
    如权利要求22所述的计算机程序,进一步包括代码段:发送QA以及来自在相同登录会话中先前运行的用于QA的任一在前值给加密消息中的每个服务器,QA等于密码自乘以随机次幂;以及使用主密钥Km验证该消息。
Independent claims24