IP Library Granted Patent US 11,968,202
Granted Patent B2
US 11,968,202 · App. 16/422,591 · Granted Apr 23, 2024

Secure authentication in adverse environments

Inventors: Karel Fuka (Prague, CZ); Vojt{hacek over (e)}ch Tůma (Brtnice, CZ)
Assignee: Avast Software s.r.o.
H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,968,202
App. No.
16/422,591
Granted
Apr 23, 2024
Kind
B2
Abstract

A method of authenticating a user to a computer in an adverse environment includes receiving the user's password in a trusted user device, such as by the user typing the password, and encoding a keyword with a hash of the entered password to create an encoded keyword. The encoded keyword is sent from the trusted user device to the computer using a physical communication channel perceivable by the user; and the encoded keyword is compared in the computer with a keyword encoded with a known hash of the user's password in the computer to authenticate the user.

Claims (40)

1. A method of authenticating a user to a computer in an adverse environment, comprising:

receiving a user's password in a trusted user device;

initiating a login process in the computer;

generating a random challenge comprising a character string in the computer;

encoding generated random challenge in a first message and appending a known prefix and a known suffix to the first message to generate a random challenge message in the computer;

sending the random challenge message to the trusted user device via a speaker coupled to the computer, wherein the generated random challenge is used a single time in authenticating the user;

receiving the random challenge message in the trusted user device via a microphone coupled to the trusted user device;

validating the received random challenge message by finding the known prefix and the known suffix in the random challenge message and extracting the generated random challenge in the trusted user device;

encoding the extracted random challenge using a hash of the user's received password in the trusted user device to generate an entered password hash-encoded random challenge, wherein encoding the random challenge comprises performing a bitwise exclusive-OR of the hash of the user's received password and the random challenge;

sending the entered password hash-encoded random challenge from the user's trusted device to the computer via a speaker coupled to the user's trusted device;

receiving the entered password hash-encoded random challenge in the computer via a microphone coupled to the computer;

encoding the random challenge using a known hash value of the user's password to generate a known password hash-encoded random challenge; and

authenticating the user by comparing the known password hash-encoded random challenge to the entered password hash-encoded random challenge in the computer.

2. The method of authenticating a user to a computer in an adverse environment of claim 1 , further comprising appending one or more communications between the trusted user device and the computer with at least one of a known prefix and a known suffix in a sending device, and verifying the known prefix and/or the known suffix in the receiving device to verify integrity of the message.

3. The method of authenticating a user to a computer in an adverse environment of claim 1 , wherein one or more communications between the trusted device and the computer comprise a frequency modulated signal or an amplitude modulated signal.

4. The method of authenticating a user to a computer in an adverse environment of claim 1 , wherein the trusted device comprises a smartphone, a personal computer, or a tablet computer.

5. The method of authenticating a user to a computer in an adverse environment of claim 1 , wherein the computer queries an authentication server in comparing the known password hash-encoded random challenge to the entered password hash-encoded random challenge in the computer to authenticate the user.

6. The method of authenticating a user to a computer in an adverse environment of claim 1 , wherein the generated random challenge is changed for every authentication transaction.

7. The method of authenticating a user to a computer in an adverse environment of claim 1 , wherein the adverse environment comprises an environment where the user does not have exclusive control of the computer.

8. The method of authenticating a user to a computer in an adverse environment of claim 1 , wherein receiving the user's password in a trusted user device comprises receiving the password from the user via a keyboard or via a password management application.

9. A method of authenticating a user to a computer in an adverse environment, comprising:

receiving a user's password in a trusted user device;

initiating a login process in the computer;

generating a random challenge comprising a character string in the computer;

encoding generated random challenge in a first message and appending a known prefix and a known suffix to the first message to generate a random challenge message in the computer;

sending the random challenge message to the trusted user device via a display coupled to the computer, wherein the generated random challenge is used a single time in authenticating the user;

receiving the random challenge message in the trusted user device via a camera coupled to the trusted user device;

validating the received random challenge message by finding the known prefix and the known suffix in the random challenge message and extracting the generated random challenge in the trusted user device;

encoding the extracted random challenge using a hash of the user's password in the trusted user device to generate an entered password hash-encoded random challenge, wherein encoding the random challenge comprises performing a bitwise exclusive-OR of the hash of the user's received password and the random challenge;

sending the entered password hash-encoded random challenge from the user's trusted device to the computer via a display coupled to the user's trusted device;

receiving the entered password hash-encoded random challenge in the computer via a camera coupled to the computer;

encoding the random challenge using a known hash value of the user's password to generate a known password hash-encoded random challenge; and

authenticating the user by comparing the known password hash-encoded random challenge to the entered password hash-encoded random challenge in the computer.

10. The method of authenticating a user to a computer in an adverse environment of claim 9 , further comprising appending one or more communications between the trusted user device and the computer with at least one of a known prefix and a known suffix in a sending device, and verifying the known prefix and/or the known suffix in the receiving device to verify integrity of the message.

11. The method of authenticating a user to a computer in an adverse environment of claim 9 , wherein one or more communications between the trusted device and the computer comprise a barcode, a QR code, or optical character recognition.

12. The method of authenticating a user to a computer in an adverse environment of claim 9 , wherein the trusted device comprises a smartphone, a personal computer, or a tablet computer.

13. The method of authenticating a user to a computer in an adverse environment of claim 9 , wherein the computer queries an authentication server in comparing the known password hash-encoded random challenge to the entered password hash-encoded random challenge in the computer to authenticate the user.

14. The method of authenticating a user to a computer in an adverse environment of claim 9 , wherein the generated random challenge is changed for every authentication transaction.

15. The method of authenticating a user to a computer in an adverse environment of claim 9 , wherein the adverse environment comprises an environment where the user does not have exclusive control of the computer.

16. The method of authenticating a user to a computer in an adverse environment of claim 9 , wherein receiving the user's password in a trusted user device comprises receiving the password from the user via a keyboard or via a password management application.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2021
From: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
To: AVAST SOFTWARE, S.R.O.
Reel/Frame 055726/0435 →
SECURITY INTEREST Recorded May 6, 2020
From: AVAST SOFTWARE S.R.O.
To: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
Reel/Frame 052582/0285 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2019
From: TUMA, VOJTECH; FUKA, KAREL
To: AVAST SOFTWARE S.R.O.
Reel/Frame 049317/0063 →
Continuity (1)
Related Publication 20200374277A1 · Nov 26, 2020