IP Library Granted Patent US 7,886,345
Granted Patent B2
US 7,886,345 · App. 11/172,378 · Granted Feb 8, 2011

Password-protection module

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,886,345
App. No.
11/172,378
Granted
Feb 8, 2011
Kind
B2
Abstract

A method of protecting a password being used to establish interaction between a user and an application includes detecting a request for the password from the application by receiving a notification from the user indicating the request. The method further includes combining the password with information identifying the application, so as to produce a protected password, and authenticating to the application using the protected password. The method may also include a mutual authentication capability between user and the application.

Claims (52)

1. A method, performed in a computer processor, of protecting a password being used to establish interaction between a user and an application, comprising:

detecting, across a user interface, a request for the password from the application by receiving a notification from the user indicating the request;

combining the password with information identifying the application, so as to produce a protected password; and

authenticating to the application using the protected password;

wherein authenticating to the application includes communicating with the application in a challenge-response protocol using a derivative of the protected password;

wherein the method further includes preventing the user from providing the password directly to the application;

wherein the derivative of the protected password includes a key generated from the protected password.

2. The method of claim 1 , wherein the notification from the user includes entering a control sequence of at least one sequence element from a user input device.

3. The method of claim 1 , wherein the notification from the user includes activating a control on a security device that is in communication with a computer platform associated with the user.

4. The method of claim 1 , wherein the notification from the user includes establishing communication between a security device and a computer platform associated with the user.

5. The method of claim 1 , wherein the information identifying the application is selected from the group consisting of a URL, an IP address, a name in a certificate, and a public key.

6. The method of claim 1 , wherein combining the password with information identifying the application includes hashing the password and the information identifying the application.

7. The method of claim 1 , wherein combining the password with information identifying the application includes combining additional information with the password and the information identifying the application.

8. The method of claim 1 , wherein authenticating to the application includes providing the protected password to the application.

9. The method of claim 1 , wherein the password is at least a portion of a one-time password.

10. The method of claim 1 , wherein authenticating to the application includes interacting with an authentication authority.

11. The method of claim 1 , further including transferring control over user interaction from the application to a password-protection module upon detecting the request for the password.

12. The method of claim 11 , further including transferring control back to the application after the protected password is provided to the application.

13. The method of claim 1 , further including receiving assurance that the application is entitled to interact with the user.

14. The method of claim 13 wherein receiving assurance includes the application demonstrating knowledge of the password.

15. The method of claim 14 , wherein demonstrating knowledge of the password includes communicating with the user via a protocol involving the password.

16. The method of claim 13 , wherein receiving assurance includes the application demonstrating knowledge of the protected password.

17. The method of claim 13 , wherein receiving assurance includes the application interacting with an authentication authority.

18. The method of claim 1 , wherein detecting the request for the password further includes decoding information provided by the application.

19. The method of claim 1 wherein the request for the password from the application is generated in response to the user being subject to a phishing scheme.

20. A method, performed in a computer processor, of protecting a password being used to establish interaction between a user and an application, comprising:

detecting, across a user interface, a request for the password from the application;

combining the password with information identifying the application, so as to produce a protected password;

authenticating to the application using the protected password; and

determining, based on the password, whether the application is entitled to interact with the user;

wherein determining whether the application is entitled to interact with the user includes the application demonstrating knowledge of the password;

wherein the application demonstrating knowledge of the password includes providing a derivative of the password to the user; and

wherein the derivative of the password is an alternative combination of the password and the value identifying the application, such that the alternative combination is a different combination from the one that produced the protected password.

21. A method, performed in a computer processor, of protecting a password being used to establish interaction between a user and an application, comprising:

detecting, across a user interface, a request for the password from the application;

combining the password with information identifying the application, so as to produce a protected password;

authenticating to the application using the protected password; and

determining, based on the password, whether the application is entitled to interact with the user;

wherein determining whether the application is entitled to interact with the user includes the application demonstrating knowledge of the password; and

wherein the demonstration of knowledge of the password includes deriving a key from the password, computing message authentication code with the derived key, and sending the message authentication code to the user.

22. The method of claim 21 , wherein determining whether the application is entitled to interact with the user includes interacting with an authentication authority.

23. The method of claim 21 , further including (i) allowing further user interaction with the application if the application is determined to be entitled to interact with the user, or (ii) preventing user interaction with the application if the application is determined not to be entitled to interact with the user.

24. The method of claim 21 wherein the request for the password from the application is generated in response to the user being subject to a phishing scheme.

25. A non-transitory computer readable storage medium including stored instructions, which, when performed by a computer, are adapted for protecting a password being used to establish interaction between a user and an application, comprising:

instructions for detecting a request for the password from the application by receiving a notification from the user across a user interface indicating the request;

instructions for combining the password with a value identifying the application, so as to produce a protected password; and

instructions for authenticating to the application using the protected password;

wherein the instructions for authenticating to the application include instructions for communicating with the application in a challenge-response protocol using a derivative of the protected password;

wherein the derivative of the protected password includes a key generated from the protected password.

26. The non-transitory computer readable medium of claim 25 , wherein at least a portion of the stored instructions is designated to be a plug-in associated with a browser.

27. The non-transitory computer readable medium of claim 25 , wherein at least a portion of the stored instructions is designated to be run as a component of an operating system.

28. The non-transitory computer readable medium of claim 25 wherein the request for the password from the application is generated in response to the user being subject to a phishing scheme.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC.
To: RSA SECURITY LLC
Reel/Frame 023852/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0721 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2007
From: KALISKI, BURTON S., JR.; NYSTROM, MAGNUS
To: RSA SECURITY, INC.
Reel/Frame 019898/0974 →