DISPERSED SUB-KEY CREDENTIALS
A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method begins by receiving from a requesting entity, at a first user device of at least a first and second user device, a request to authenticate item m, the request including at least a request for a key N. The method continues by obtaining a first password, retrieving a first portion x of the key N based on the first password, obtaining a factor m y of a second portion y of the key N based on a factor request including m, generating a signature utilizing the first portion x of the key N and the factor m y of the second portion y of the key N, generating an authentication response that includes the signature and sending the authentication response to the requesting entity.
1 . A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:
receiving from a requesting entity, at a first user device of at least a first and second user device, a request to authenticate item m, the request including at least a request for a key N;
obtaining a first password;
retrieving a first portion x of the key N based on the first password;
obtaining a factor m y of a second portion y of the key N based on a factor request including variable m;
generating a signature utilizing the first portion x of the key N and the factor m y of the second portion y of the key N;
generating an authentication response that includes the signature; and
sending the authentication response to the requesting entity.
2 . The method of claim 1 , wherein the request to authenticate is from a service provider.
3 . The method of claim 1 , wherein the request further includes an instruction to provide a digital signature of the variable m.
4 . The method of claim 3 , wherein the obtaining includes generating a factor m y of a second portion of the request for a key N that includes the variable m, identifying the second user device, sending the factor request to the second user device, and receiving a response from the second user device that includes the factor m y .
5 . The method of claim 4 further comprises generating a signature utilizing an expression signature S=(m x *m y ) mod N.
6 . The method of claim 4 , wherein the identifying a second user device is based on a lookup, a list, a query, or an affiliation.
7 . The method of claim 1 , wherein the obtaining a password includes at least one of: outputting a user prompt, receiving a user input, a query, receiving the password, or a lookup.
8 . The method of claim 1 , wherein the obtaining a password includes outputting a user prompt and receiving a user input that includes a multi-digit alphanumeric password.
9 . The method of claim 1 , wherein the retrieving includes at least one of: a lookup utilizing the first password as an index or retrieving the first portion x of the key N from a distributed key storage system utilizing the first password.
10 . The method of claim 9 , wherein the retrieving the first portion x of the key N from the distributing key storage system utilizing the first password includes: generating a set of blinded passwords based on the first password and a set of random numbers, sending the set of blinded passwords to a set of authentication servers of the distributed key storage system, receiving a set of passkeys from the set of authentication servers, generating a set of keys based on the set of passkeys and the set of random numbers, retrieving a set of encrypted first portion key slices from the set of authentication servers, decrypting the set of encrypted first portion key slices utilizing the set of keys to produce a set of first portion key slices, and dispersed storage error decoding the set of first portion key slices to reproduce the first portion x of the key N.
11 . A computing device of a group of computing devices of a dispersed storage network (DSN), the computing device comprises:
an interface;
a local memory; and
a processing module operably coupled to the interface and the local memory, wherein the processing module functions to:
receive from a requesting entity, at a first user device of at least a first and second user device, a request to authenticate item m, the request including at least a request for a key N;
obtain a first password;
retrieve a first portion x of the key N based on the first password;
obtain a factor m y of a second portion y of the key N based on a factor request including m;
generate a signature utilizing the first portion x of the key N and the factor m y of the second portion y of the key N;
generate an authentication response that includes the signature; and
send the authentication response to the requesting entity.
12 . The computing device of claim 11 , wherein the request to authenticate further includes an instruction to provide a digital signature of a variable m.
13 . The computing device of claim 12 , wherein the obtain a factor m y of a second portion y of the key N based on a factor request including m includes generating a factor m y of a second portion of the request for a key N that includes the variable m, identifying the second user device, sending the factor request to the second user device, and receiving a response from the second user device that includes the factor m y .
14 . The computing device of claim 13 further comprises generating a signature utilizing an expression signature S=(m x *m y ) mod N.
15 . The computing device of claim 11 , wherein the retrieve a first portion x of the key N based on the first password includes at least one of: a lookup utilizing the first password as an index or retrieving the first portion x of the key N from a distributed key storage system utilizing the first password.
16 . The computing device of claim 15 , wherein the retrieving the first portion x of the key N from the distributing key storage system utilizing the first password includes: generating a set of blinded passwords based on the first password and a set of random numbers, sending the set of blinded passwords to a set of authentication servers of the distributed key storage system, receiving a set of passkeys from the set of authentication servers, generating a set of keys based on the set of passkeys and the set of random numbers, retrieving a set of encrypted first portion key slices from the set of authentication servers, decrypting the set of encrypted first portion key slices utilizing the set of keys to produce a set of first portion key slices, and dispersed storage error decoding the set of first portion key slices to reproduce the first portion x of the key N.
17 . A method for execution by one or more processing modules of one or more computing devices of a dispersed storage network (DSN), the method comprises:
receiving from a requesting entity, at a second user device of at least two user devices, a request for a factor m y of a second portion y of a two-portion key N from a first user device, wherein m is variable of the request;
obtaining a second password of at least a first and second password;
retrieving the second portion y of the two-portion key N based on the second password, wherein the retrieving includes at least one of a lookup utilizing the second password as an index and retrieving the second portion y of the two-portion key N from a distributed key storage system utilizing the second password;
generating a factor m y of the second portion y of the two-portion key N based on the second portion y of the two-portion key N and the variable m of the request;
generating a factor response that includes the factor m y ; and
sending the factor response to the requesting entity.
18 . The method of claim 17 , wherein the retrieving the second portion y of the two-portion key N from the distributing key storage system utilizing the second password includes one or more of generating a set of blinded passwords based on the second password and a set of random numbers, sending the set of blinded passwords to a set of authentication servers of the distributed key storage system, receiving a set of passkeys from the set of authentication servers, generating a set of keys based on the set of passkeys and the set of random numbers, retrieving a set of encrypted second portion key slices from the set of authentication servers, decrypting the set of encrypted second portion key slices utilizing the set of keys to produce a set of second portion key slices, and dispersed storage error decoding the set of second portion key slices to reproduce the second portion y of the two-portion key N.
19 . The method of claim 18 , wherein the requesting entity includes a server that is operable to receive one or more of the factor of the second portion y of the two-portion key N, a factor of a first portion x of the two-portion key N, a signature utilizing a first portion x of the two-portion key N, and the factor of the second portion y of the two-portion key N to verify an authentication sequence.
20 . The method of claim 19 , wherein the server is a service provider that verifies the signature by calculating a reproduced variable m′ in accordance with an expression m′=s e mod N, wherein e is another two-portion key N element, and comparing m′ to a variable m, and indicating signature verification when the comparing indicates that m′ and m are substantially the same.