IP Library Granted Patent US 12,120,113
Granted Patent B2
US 12,120,113 · App. 17/376,376 · Granted Oct 15, 2024

Distributed / multi-level server authentication

Inventors: Victor Salamon (Edmonton, CA); Paul Berube (Edmonton, CA)
H04L63/0876H04L63/0435H04L63/20H04L67/01H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,120,113
App. No.
17/376,376
Granted
Oct 15, 2024
Kind
B2
Abstract

Methods, system, and non-transitory processor-readable storage medium for distributed and multi-level server authentication are provided herein. An example method includes receiving, by a plurality of second servers, a plurality of authentication secret slices, where a first server transmits each of the plurality of authentication secret slices to a respective second server of the plurality of second servers, receiving, by the first server, an authentication confirmation from each of the plurality of second servers and confirming, by the first server to a client, that an authentication request has succeeded.

Claims (56)

1. A method, comprising:

receiving, by a plurality of second servers, a plurality of authentication secret slices, wherein a first server transmits each of the plurality of authentication secret slices to a respective second server of the plurality of second servers;

receiving, by the first server, an authentication confirmation from each of the plurality of second servers;

confirming, by the first server to a client, that an authentication request has succeeded;

processing, by the client, a request input into a secret;

splitting, by the client, the secret into a plurality of secret slices;

transmitting the plurality of secret slices from the client to the first server in a random order; and

maintaining, on the first server, a sequence number associated with each of the plurality of secret slices, and identification of a respective second server of the plurality of second servers to which each of the plurality of secret slices is transmitted.

2. The method of claim 1 wherein receiving, by the plurality of second servers, the plurality of authentication secret slices comprises:

transmitting the plurality of authentication secret slices individually from the first server to each respective second server.

3. The method of claim 2 wherein transmitting the plurality of authentication secret slices individually from the first server to the second server comprises:

transmitting each authentication secret slice from the first server to the respective second server through an encrypted channel, wherein a plurality of encryption methods is utilized.

4. The method of claim 1 wherein receiving, by the plurality of second servers, the plurality of authentication secret slices comprises:

receiving, by the first server, the authentication request from the client, wherein the client processes authentication input into the plurality of authentication secret slices, wherein the authentication request comprises the plurality of authentication secret slices.

5. The method of claim 1 wherein receiving, by the plurality of second servers, the plurality of authentication secret slices comprises:

generating the authentication confirmation, by the second server, if a received authentication secret slice matches a registration secret slice persisted on the second server.

6. The method of claim 1 wherein receiving, by the plurality of second servers, the plurality of authentication secret slices comprises:

performing a registration process between the client and the second server.

7. The method of claim 6 wherein performing the registration process between the client and the second server comprises:

receiving, by the first server, a registration request from the client, wherein the client processes registration input into a plurality of registration secret slices, wherein the registration request comprises the plurality of registration secret slices;

receiving, by the plurality of second servers, the plurality of registration secret slices, wherein the first server transmits each of the plurality of registration secret slices to a respective second server of the plurality of second servers;

receiving, by the first server, confirmation from each of the plurality of second servers that each received registration secret slice has been persisted on the respective second server; and

confirming, by the first server to the client, that the registration request has succeeded.

8. The method of claim 7 wherein receiving, by the plurality of second servers, the plurality of registration secret slices comprises:

transmitting the plurality of registration secret slices individually from the first server to each respective second server.

9. The method of claim 7 wherein receiving, by the plurality of second servers, the plurality of registration secret slices comprises:

persisting, by each of the plurality of second servers, a respective received registration secret slice and a username associated with the plurality of registration secret slices.

10. The method of claim 1 further comprising:

receiving, by the client, a registration request or an authentication request along with request input.

11. The method of claim 10 wherein an assembly order of the plurality of secret slices is associated with the plurality of secret slices.

12. The method of claim 10 wherein a sequence order is encoded in each of the plurality of secret slices.

13. The method of claim 1 further comprising: hashing at least one of the secret slices from the first server to the second server.

14. A system comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to receive, by a plurality of second servers, a plurality of authentication secret slices, wherein a first server transmits each of the plurality of authentication secret slices to a respective second server of the plurality of second servers;

to receive, by the first server, an authentication confirmation from each of the plurality of second servers;

to confirm, by the first server to a client, that an authentication request has succeeded;

to process, by the client, the request input into a secret;

to split, by the client, the secret into a plurality of secret slices;

to transmit the plurality of secret slices from the client to the first server in a random order; and

to maintain, on the first server, a sequence number associated with each of the plurality of secret slices, and identification of a respective second server of the plurality of second servers to which each of the plurality of secret slices is transmitted.

15. The system of claim 14 wherein the at least one processing device configured to receive, by the plurality of second servers, the plurality of authentication secret slices is further configured to:

transmit the plurality of authentication secret slices individually from the first server to each respective second server.

16. The system of claim 14 wherein the at least one processing device configured to receive, by the plurality of second servers, the plurality of authentication secret slices is further configured to:

generate the authentication confirmation, by the second server, if a received authentication secret slice matches a registration secret slice persisted on the second server.

17. The system of claim 14 further configured to:

receive, by the client, a registration request or an authentication request along with request input.

18. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device:

to receive, by a plurality of second servers, a plurality of authentication secret slices, wherein a first server transmits each of the plurality of authentication secret slices to a respective second server of the plurality of second servers;

to receive, by the first server, an authentication confirmation from each of the plurality of second servers;

to confirm, by the first server to a client, that an authentication request has succeeded;

to receive, by the client, a registration request or an authentication request along with request input;

to process, by the client, the request input into a secret;

to split, by the client, the secret into a plurality of secret slices;

to transmit the plurality of secret slices from the client to the first server in a random order and to maintain, on the first server, a sequence number associated with each of the plurality of secret slices, and identification of a respective second server of the plurality of second servers to which each of the plurality of secret slices is transmitted.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2021
From: SALAMON, VICTOR; BERUBE, PAUL
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 056864/0500 →
Continuity (1)
Related Publication 20230016852A1 · Jan 19, 2023