Systems and methods for obscuring entry of electronic security term
    4.
    发明授权
    Systems and methods for obscuring entry of electronic security term 有权
    阻止电子安全术语进入的系统和方法

    公开(公告)号:US09276927B1

    公开(公告)日:2016-03-01

    申请号:US14484514

    申请日:2014-09-12

    摘要: A security service determines whether to grant a user access to a resource. The service receives from the user a security term in an obscured form derived from a revealed form of the security term according to a predefined padding scheme known to the user and to the security service. The service applies the padding scheme to the received term to result in a de-padded security term and confirms that the de-padded security term matches the retrieved revealed security term. Additionally, the service confirms that the received term has not been previously employed within a predetermined frame of reference. Accordingly, if the received obscured security term is purloined and re-used within the predetermined frame of reference, the security service denies access to the resource.

    摘要翻译: 安全服务确定是否授予用户对资源的访问权限。 根据用户已知的预定义的填充方案和安全服务,该服务从用户接收从安全术语的透露形式导出的模糊形式的安全术语。 该服务将填充方案应用于所接收的术语,以得到解除填充的安全术语,并确认解除填充的安全术语与检索到的透露的安全术语匹配。 另外,该服务确认在预定参考系中尚未使用所接收的项。 因此,如果接收到的隐蔽安全术语在预定参考帧内被排除和重新使用,则安全服务拒绝对资源的访问。