IP Library Granted Patent US 8,191,131
Granted Patent B2
US 8,191,131 · App. 11/466,494 · Granted May 29, 2012

Obscuring authentication data of remote user

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,191,131
App. No.
11/466,494
Granted
May 29, 2012
Kind
B2
Abstract

A system and method in which authentication data, such as a password, which is sent to a server/firewall as part of an authentication request, for example a logon request, is received at the server/firewall in a plurality of messages at a plurality of logical ports from the user, thus improving protection against replay attacks. In one embodiment, a plurality of user authentication data parts is obtained from a remote user device as part of an authentication request, the plurality of user authentication data parts is assembled into user authentication data; the authenticity of the authentication request is checked using the user authentication data; and communication with the remote user device is enabled if the authentication request data is determined to be authentic.

Claims (30)

1. A method comprising:

obtaining a plurality of user authentication data parts from a remote user device as part of an authentication request, wherein the user authentication data parts were received in a plurality of messages, at least two of the plurality of messages having been received at different logical ports of a firewall;

assembling the plurality of user authentication data parts into user authentication data;

checking the authenticity of the authentication request using the user authentication data; and

enabling communication with the remote user device if the authentication request data is determined to be authentic.

2. The method of claim 1 further comprising:

receiving, for each message, an indication that the message has been received and that the part of the user authentication data which it comprises has been written to a location in storage,

wherein obtaining the plurality of user authentication data parts comprises reading each of the user authentication data parts from the location in storage.

3. The method of claim 1 wherein the step of assembling the plurality of user authentication data parts comprises:

obtaining, for each of the plurality of authentication data parts, an associated value;

using the values associated with each of the plurality of authentication data parts to determine how to assemble the authentication data parts into the authentication data.

4. The method of claim 3 wherein at least one of the plurality of messages includes an identifier which identifies the user device and the step of using the values to determine how to assemble the authentication data parts into the authentication data further uses the identifier to determine the order.

5. The method of claim 1 wherein the set of logical ports is predefined and the step of checking the authenticity of the authentication request further comprises:

checking that a message part was received at each of the set of logical ports.

6. The method of claim 1 wherein at least one of the plurality of messages includes an identifier which identifies the user device and a plurality of sets of logical ports are predefined and the step of checking the authenticity of the authentication request further comprises:

using the identifier to select one of the plurality of sets of logical ports; and

checking that a message part was received at each of the selected set of logical ports.

7. A method comprising:

receiving a plurality of messages from a user device at a plurality of logical ports of a firewall;

determining each message comprises a part of an authentication request from the user device,

providing each of the plurality of message to a data processing host for processing as part of an authentication request.

8. The method of the claim 7 further comprising the step:

responsive to determining a message is not part of an authentication request, rejecting the message.

9. A computer program product comprising:

a computer readable transmission medium; and

computer program instructions stored on the computer readable transmission medium that, when executed, cause a computer to carry out the steps of:

obtaining a plurality of user authentication data parts from a remote user device as part of an authentication request, wherein the user authentication data parts were received in a plurality of messages, at least two of the plurality of messages having been received at different logical ports of a firewall;

assembling the plurality of user authentication data parts into user authentication data;

checking the authenticity of the authentication request using the user authentication data; and

enabling communication with the remote user device if the authentication request data is determined to be authentic.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2014
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: LENOVO INTERNATIONAL LIMITED
Reel/Frame 034194/0291 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2006
From: JENNINGS, JEFFREY BART; KEKESSIE, KOFI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 018342/0352 →