IP Library › Granted Patent US 11,741,218
Granted Patent B2
US 11,741,218 · App. 17/177,019 · Granted Aug 29, 2023

System and method for improving the security of stored passwords for an organization

Inventor: Kenneth J. Sanchez (San Francisco, CA)
Assignee: STATE FARM MUTUAL AUTOMOBILE INSURANCE COMPANY
G06F21/46H04L9/0643H04L9/3226H04L63/083H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,741,218
App. No.
17/177,019
Granted
Aug 29, 2023
Kind
B2
Abstract

A hashed fried password method includes receiving a password value, a global pepper value and fry values; generating a random salt value and selecting a fry value; generating a fried password; and authenticating the user when a hashed fried password value matches a candidate hash. The method may include receiving the fried password and/or salt. A system includes processor and a memory storing instructions that, when executed by the processor cause the system to receive a password value, a global pepper value and fry values; receive a hashed fried password value and salt value; apply a hashing function; and authenticate the user when the hashed fried password value matches a candidate.

Claims (72)

1. A computer-implemented method for creating a hashed fried password in a computing device, comprising:

receiving a password value of a user;

receiving a global pepper value;

receiving a set of fry values;

generating, via a random number generator, a salt value;

selecting at least one fry value from the set of fry values;

generating a fried password by combining the password value, the salt value, the global pepper value, and the at least one fry value;

applying a hashing function to the fried password to generate a hashed fried password; and

authenticating the user when the hashed fried password value appears within a set of candidate hashes.

2. The computer-implemented method of claim 1 , further comprising:

storing the hashed fried password and the salt value in association with the user.

3. The computer-implemented method of claim 1 , further comprising:

specifying an adjustable work factor as a parameter of the hashing function.

4. The computer-implemented method of claim 1 , further comprising:

selecting the hashing function a plurality of hashing functions.

5. The computer-implemented method of claim 1 , wherein the hashing function is a cryptographic hash function.

6. A computer-implemented method for authenticating a hashed fried password at a computing device, comprising:

receiving a password value of a user;

receiving a global pepper value;

receiving a set of fry values;

receiving a hashed fried password value and salt value associated with the user;

applying a hashing function to the password value, salt value, global pepper value, and each of the set of fry values to generate a hashed fried password; and

authenticating the user when the hashed fried password value appears within a set of candidate hashes.

7. The computer-implemented method of claim 6 , further comprising:

transmitting, in response to authenticating the user, an indication to a remote computing device.

8. The computer-implemented method of claim 6 , wherein the remote computing device is a mobile computing device of a user.

9. The computer-implemented method of claim 6 , further comprising:

generating a portion of the set of candidate hashes in parallel using one or both of (i) an application-specific integrated circuit (ASIC), and (ii) a graphics processing unit (GPU).

10. The computer-implemented method of claim 6 , further comprising:

selecting an updated fry value from the set of fry values;

combining the password value, the salt value, the global pepper value, and the updated fry value to generate an updated fried password;

applying a hashing function to the updated fried password to generate an updated hashed fried password; and

storing the updated hashed fried password and the salt value in association with the user.

11. The computer-implemented method of claim 10 , further comprising:

applying a cryptographic hash function.

12. The computer-implemented method of claim 6 , further comprising:

receiving the password value via an HTML form.

13. The computer-implemented method of claim 6 , further comprising:

validating the password value of the user.

14. A computing system comprising:

one or more processors; and

one or more memories storing instructions that, when executed by the one or more processors, cause the computing system to

receive a password value of a user;

receive a global pepper value;

receive a set of fry values;

receive a hashed fried password value and salt value associated with the user;

apply a hashing function to the password value, salt value, global pepper value, and each of the set of fry values to generate a set of candidate hashes; and

authenticate the user when the hashed fried password value appears within the set of candidate hashes.

15. The computing system of claim 14 , wherein the instructions further cause the computing system to:

transmit, in response to authenticating the user, an indication to a remote computing device.

16. The computing system of claim 14 , wherein the remote computing device is a mobile computing device of a user.

17. The computing system of claim 14 , wherein the instructions further cause the computing system to:

generate a portion of the set of candidate hashes in parallel using one or both of (i) a graphics processing unit (GPU), and (ii) an application-specific integrated circuit (ASIC).

18. The computing system of claim 14 , wherein the instructions further cause the computing system to:

select an updated fry value from the set of fry values;

combine the password value, the salt value, the global pepper value, and the updated fry value to generate an updated fried password; and

apply a hashing function to the updated fried password to generate an updated hashed fried password; and

store the updated hashed fried password and the salt value in association with the user.

19. The computing system of claim 18 , wherein the instructions further cause the computing system to:

apply a cryptographic hashing function to generate the updated hashed fried password.

20. The computing system of claim 14 , wherein the instructions further cause the computing system to:

receive the password value via an HTML form.

21. A computer-implemented method of authenticating a user, comprising:

receiving a first password value of the user;

transmitting, to a remote computing device, the first password value of the user;

receiving a fry value;

storing the fry value securely;

receiving a second password value of the user;

transmitting, to the remote computing device, the second password value of the user, a pepper value, a salt value, and the securely-stored fry value;

receiving authentication information;

applying a hashing function to a password value including the second password value, the pepper value, the salt value and the securely-stored fry value, to generate a hashed fried password; and

authenticating the user when the hashed fried password value appears within a set of candidate hashes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2021
From: SANCHEZ, KENNETH J.
To: STATE FARM MUTUAL AUTOMOBILE INSURANCE COMPANY
Reel/Frame 055518/0643 →
Continuity (6)
Continuation 15976494 · May 10, 2018
Provisional Application 62617905 · Jan 16, 2018
Provisional Application 62539892 · Aug 1, 2017
Provisional Application 62534068 · Jul 18, 2017
Provisional Application 62522678 · Jun 20, 2017
Related Publication 20210182379A1 · Jun 17, 2021