IP Library › Granted Patent US 12,238,088
Granted Patent B2
US 12,238,088 · App. 18/093,003 · Granted Feb 25, 2025

Local hash salt to prevent credential stuffing attacks

Inventors: Vijay Kumar Yarabolu (Telangana, IN); Gowthaman Sundararaj (Tamilnadu, IN)
Assignee: Bank of America Corporation
H04L63/083H04L63/061H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,088
App. No.
18/093,003
Granted
Feb 25, 2025
Kind
B2
Abstract

Aspects of the disclosure relate to authentication. A computing platform may send, to a wearable device, an internet of things (IoT) vector key. The computing platform may receive an application access request from the wearable device, which may include authentication credentials. The computing platform may send, to the wearable device, a reference key comprising a sequence of row-column combinations corresponding to the IoT vector key, and the wearable device may be configured to identify a hash salt value using the reference key and the IoT. The computing platform may receive, from the wearable device, the hash salt value. The computing platform may generate, based on the hash salt value and the authentication credentials, a password. The computing platform may hash the password to produce a password hash, and may send the password hash to an application server for validation.

Claims (64)

1. A computing platform comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

send, to a wearable device, an internet of things (IoT) vector key comprising an N×N matrix of values for a client;

receive an application access request from the wearable device, wherein the application access request includes authentication credentials;

send, to the wearable device, a reference key comprising a sequence of row-column combinations corresponding to the IoT vector key, wherein the wearable device is configured to identify a hash salt value by identifying the values, in the IoT vector key, corresponding to the sequence of row-column combinations defined in the reference key;

receive, from the wearable device, the hash salt value;

generate, based on the hash salt value and the authentication credentials, a password;

hash the password to produce a password hash; and

send the password hash to an application server, wherein the application server is configured to validate the password hash by comparing the password hash to a reference password hash and grant the wearable device access to the application based on successful validation, wherein the application server is configured to:

update, after validating the password hash, the IoT vector key, and

provide, to the computing platform, the updated IoT vector key, wherein the computing platform distributes the updated IoT vector key to the wearable device for storage and use in subsequent application access requests.

2. The computing platform of claim 1 , wherein the IoT vector key is stored at the application server and the wearable device.

3. The computing platform of claim 1 , wherein the authentication credentials comprise one or more of: an alphanumeric passcode, biometric input, a retina scan, or a facial scan.

4. The computing platform of claim 1 , wherein the reference key is generated by the application server and stored at the application server.

5. The computing platform of claim 1 , wherein the application server is configured to generate the reference password hash by:

generating, based on the reference key and the IoT vector key, the hash salt value;

generating, based on the authentication credentials and the hash salt value, the password; and

hashing the password to produce the reference password hash.

6. The computing platform of claim 1 , wherein the authentication credentials are shared among a plurality of applications accessible at the computing platform.

7. The computing platform of claim 6 , wherein a plurality of wearable devices, including the wearable device, may be configured to access the plurality of applications.

8. The computing platform of claim 1 , wherein the password is further generated based on a second hash salt value, received from a different wearable device.

9. The computing platform of claim 1 , wherein:

the reference key is specific to the application,

a second reference key is assigned to a second application,

the authentication credentials for the application and the second application are the same; and

the password hashes for the application and the second application are different.

10. A method comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

sending, to a wearable device, an internet of things (IoT) vector key comprising an N×N matrix of values for a client;

receiving an application access request from the wearable device, wherein the application access request includes authentication credentials;

sending, to the wearable device, a reference key comprising a sequence of row-column combinations corresponding to the IoT vector key, wherein the wearable device is configured to identify a hash salt value by identifying the values, in the IoT vector key, corresponding to the sequence of row-column combinations defined in the reference key;

receiving, from the wearable device, the hash salt value;

generating, based on the hash salt value and the authentication credentials, a password;

hashing the password to produce a password hash; and

sending the password hash to an application server, wherein the application server is configured to validate the password hash by comparing the password hash to a reference password hash and grant the wearable device access to the application based on successful validation, wherein the application server is configured to:

update, after validating the password hash, the IoT vector key, and

provide, to the computing platform, the updated IoT vector key, wherein the computing platform distributes the updated IoT vector key to the wearable device for storage and use in subsequent application access requests.

11. The method of claim 10 , wherein the IoT vector key is stored at the application server and the wearable device.

12. The method of claim 10 , wherein the authentication credentials comprise one or more of: an alphanumeric passcode, biometric input, a retina scan, or a facial scan.

13. The method of claim 10 , wherein the reference key is generated by the application server and stored at the application server.

14. The method of claim 10 , wherein the application server is configured to generate the reference password hash by:

generating, based on the reference key and the IoT vector key, the hash salt value;

generating, based on the authentication credentials and the hash salt value, the password; and

hashing the password to produce the reference password hash.

15. The method of claim 10 , wherein the authentication credentials are shared among a plurality of applications accessible at the computing platform.

16. The method of claim 15 , wherein a plurality of wearable devices, including the wearable device, may be configured to access the plurality of applications.

17. The method of claim 10 , wherein the password is further generated based on a second hash salt value, received from a different wearable device.

18. The method of claim 10 , wherein:

the reference key is specific to the application,

a second reference key is assigned to a second application,

the authentication credentials for the application and the second application are the same; and

the password hashes for the application and the second application are different.

19. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

send, to a wearable device, an internet of things (IoT) vector key comprising an N×N matrix of values for a client;

receive an application access request from the wearable device, wherein the application access request includes authentication credentials;

send, to the wearable device, a reference key comprising a sequence of row-column combinations corresponding to the IoT vector key, wherein the wearable device is configured to identify a hash salt value by identifying the values, in the IoT vector key, corresponding to the sequence of row-column combinations defined in the reference key;

receive, from the wearable device, the hash salt value;

generate, based on the hash salt value and the authentication credentials, a password;

hash the password to produce a password hash; and

send the password hash to an application server, wherein the application server is configured to validate the password hash by comparing the password hash to a reference password hash and grant the wearable device access to the application based on successful validation, wherein the application server is configured to:

update, after validating the password hash, the IoT vector key, and

provide, to the computing platform, the updated IoT vector key, wherein the computing platform distributes the updated IoT vector key to the wearable device for storage and use in subsequent application access requests.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2023
From: SUNDARARAJ, GOWTHAMAN; YARABOLU, VIJAY KUMAR
To: BANK OF AMERICA CORPORATION
Reel/Frame 062271/0384 →
Continuity (1)
Related Publication 20240223549A1 · Jul 4, 2024
References Cited (24)
US 7228417B2 · Roskind · 2007 [cited by applicant]
US 11265148B1 · Griffin et al. · 2022 [cited by applicant]
US 11291921B1 · Schindler et al. · 2022 [cited by applicant]
US 11356244B2 · Yarabolu · 2022 [cited by applicant]
US 11366928B2 · Goel et al. · 2022 [cited by applicant]
US 11379606B2 · Wang · 2022 [cited by applicant]
US 11386372B2 · Koppel et al. · 2022 [cited by applicant]
US 11398907B1 · Fodere et al. · 2022 [cited by applicant]
US 11405211B2 · Yarabolu · 2022 [cited by applicant]
US 11405377B2 · Bhargava et al. · 2022 [cited by applicant]
US 11409709B1 · Capello et al. · 2022 [cited by applicant]
US 11412373B2 · Medwed et al. · 2022 [cited by applicant]
US 11431476B2 · Brown et al. · 2022 [cited by applicant]
US 11438378B1 · Dell'Amico · 2022 [cited by applicant]
US 11463260B2 · Chan · 2022 [cited by applicant]
US 20170346853A1 · Wyatt · 2017 [cited by examiner]
US 20180205544A1 · Norton · 2018 [cited by applicant]
US 20210224808A1 · Al-Ansari et al. · 2021 [cited by applicant]
US 20210248616A1 · Foster · 2021 [cited by applicant]
US 20210326432A1 · Kaidi · 2021 [cited by applicant]
US 20210365433A1 · Heo et al. · 2021 [cited by applicant]
US 20220269816A1 · Qian et al. · 2022 [cited by applicant]
US 20220327882A1 · Komo et al. · 2022 [cited by applicant]
US 20220345459A1 · Tseng et al. · 2022 [cited by applicant]