or
Bookmark and Share
System and method for controlling access to a computer resource
   
Document Number
US Patent 6587032
Issued Date
July 1, 2003
Link
Map
Abstract
A stealth system and method that allows a resource to be practically invulnerable to fast online brute-force attacks is disclosed. The method for controlling access to a computer resource consists in performing a user authentication procedure upon receiving a request from a user to access the computer resource. As part of the user authentication procedure, a password verification procedure is performed which comprises the steps of requesting a password from the user and comparing the entered password with an expected valid one. The next steps are to compute the number of ungranted access for the user during a predefined time interval N if the password matches the expected one and to grant access to the user only if the computed number is lower than a predetermined number K of authorized requests. Otherwise, if either the password does not match the expected one or the number of unsuccessful attempts to log is higher than the predetermined number, the access is denied to the user and a time stamp of the ungranted access is stored.
Tags:
Description:
Amusing 0%
Clever 0%
Complex 0%
Efficient 0%
Historic 0%
Important 0%
Innovative 0%
Interesting 0%
Practical 0%
Simple 0%
Number of Claims:
17
Comments:
no comments yet
Published
July 1, 2003
Application Number
09/994,275
Filed
November 26, 2001
US Classification
340/5.31   340/5.27 340/5.28 340/5.54 340/5.74 340/5.85
Int'l Classification
G06F   1/00   (20060101)   G06F   21/00   (20060101)  
Examiner
Assistant Examiner
Attorney/Law Firm
Priority Data
Nov 28, 2000 [EP] 00480107
USPTO Field of Search
340/825.56   340/540   340/576   340/5.28   340/5.31   340/5.54   340/5.74   340/5.27   340/5.85  
Related Patents
7389535 - Password management - Owned by Sun Microsystems, Inc. (Santa Clara, CA)

A computer system (for example a blade server system) includes a connection framework for receiving at least two replaceable units (e.g., service processor units). Where a first replaceable unit is provided in the connection framework, the first replaceable unit can, on a second replaceable unit being received in the framework, allow restricted use of a default admin user login without a password for up to the end of predetermined period following receipt of the second replaceable unit. On receipt of an admin login with a configured password during the period, or on expiry of the period, the system can revert to normal operation.

7313664 - Apparatus and system for controlling access to a data storage device - Owned by Hitachi Global Storage Technologies Netherlands B.V. (Amsterdam,NL)

A data storage device is secured by extracting timing information encoded within a password-related symbol stream received by the storage device and denying access if the timing information is incorrect or the symbol stream is not identical to a valid authentication sequence. In one embodiment, each symbol corresponds to a password, and at least one symbol is transmitted within a specified timing window while at least one other symbol must be transmitted at a random time that varies with each authentication attempt. In certain embodiments, a computing device associated with the data storage device is configured to provide a single password prompt, receive a character sequence corresponding to a plurality of passwords from a user, and communicate an encrypted symbol stream to the storage device with a specified timing pattern imposed thereon.

7315927 - Machine readable medium and method for controlling access to a data storage device - Owned by Hitachi Global Storage Technologies Netherlands B.V. (Amsterdam,NL)

A data storage device is secured by extracting timing information encoded within a password-related symbol stream received by the storage device and denying access if the timing information is incorrect or the symbol stream is not identical to a valid authentication sequence. In one embodiment, each symbol corresponds to a password, and at least one symbol is transmitted within a specified timing window while at least one other symbol must be transmitted at a random time that varies with each authentication attempt. In certain embodiments, a computing device associated with the data storage device is configured to provide a single password prompt, receive a character sequence corresponding to a plurality of passwords from a user, and communicate an encrypted symbol stream to the storage device with a specified timing pattern imposed thereon.

7512804 - Data storage security apparatus and system - Owned by Hitachi Global Storage Technologies Netherlands B.V. (Amsterdam,NL)

A data storage device is secured by extracting timing information encoded within a password-related symbol stream received by the storage device and denying access if the timing information is incorrect or the symbol stream is not identical to a valid authentication sequence. In one embodiment, each symbol corresponds to a password, and at least one symbol is transmitted within a specified timing window while at least one other symbol must be transmitted at a random time that varies with each authentication attempt. In certain embodiments, a computing device associated with the data storage device is configured to provide a single password prompt, receive a character sequence corresponding to a plurality of passwords from a user, and communicate an encrypted symbol stream to the storage device with a specified timing pattern imposed thereon.

7512805 - Machine readable medium and method for data storage security - Owned by Hitachi Global Storage Technologies Netherlands B.V. (Amsterdam,NL)

A data storage device is secured by extracting timing information encoded within a password-related symbol stream received by the storage device and denying access if the timing information is incorrect or the symbol stream is not identical to a valid authentication sequence. In one embodiment, each symbol corresponds to a password, and at least one symbol is transmitted within a specified timing window while at least one other symbol must be transmitted at a random time that varies with each authentication attempt. In certain embodiments, a computing device associated with the data storage device is configured to provide a single password prompt, receive a character sequence corresponding to a plurality of passwords from a user, and communicate an encrypted symbol stream to the storage device with a specified timing pattern imposed thereon.

Claims
Description
About| FAQs| Terms & Disclaimer| Link to Us| Contact Us