IP Library › Granted Patent US 12,489,617
Granted Patent B2
US 12,489,617 · App. 18/428,461 · Granted Dec 2, 2025

Password authentication using cryptographic key handle-based authentication records

Inventors: Chaitanya Gali Kumar (Bangalore, IN); Amit Prajapati (Bangalore, IN); Ancitta Alphonse (Bangalore, IN)
Assignee: Hewlett Packard Enterprise Development LP
H04L9/0863H04L9/0869H04L9/0897
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,617
App. No.
18/428,461
Granted
Dec 2, 2025
Kind
B2
Abstract

A process includes receiving credentials associated with a request to access a computer platform. The credentials include a password and a user identification. The process includes determining a key handle and a reference cryptographic digest corresponding to the user identification. The process includes determining a second cryptographic digest corresponding to the user identification. Determining the second cryptographic digest includes providing the key handle and the password to a security processor of the computer platform and initiating an operation by the security processor to apply a keyed-hashing function to the password based on a cryptographic key corresponding to the key handle to provide the second cryptographic digest. The security processor stores the cryptographic key. The process includes regulating access to the computer platform based on a comparison of the second cryptographic digest to the reference cryptographic digest.

Claims (28)

1 . A computer platform comprising:

a security processor comprising:

a memory to store a cryptographic key, wherein the security processor associates the cryptographic key with a key handle; and

a keyed-hash generator; and

a hardware processor to:

responsive to a request to access the computer platform, access a password and a user identification associated with the request;

access an authentication record that corresponds to the user identification;

determine, from the authentication record, a key handle and a first cryptographic hash;

provide the key handle and the password to the security processor and initiate an operation of the security processor in which the keyed-hash generator generates a second cryptographic hash based on the password and the cryptographic key; and

regulate whether the request is allowed based on a comparison of the second cryptographic hash to the first cryptographic hash.

2 . The computer platform of claim 1 , wherein the hardware processor to further, in response to a creation of the password:

initiate an operation of the security processor to load an object into the secure storage; and

pass the cryptographic key to the operation as the object.

3 . The computer platform of claim 2 , wherein the operation of the security processor to load the object into the secure storage causes the security processor to designate the cryptographic key as a transient object and return a transient handle that the security processor associates with the cryptographic key.

4 . The computer platform of claim 3 , wherein the hardware processor to further:

initiate an operation of the security processor to cause the security processor to designate the cryptographic key as a persistent object and return a persistent handle that the security processor associates with the cryptographic key; and

store the persistent handle in the authentication record as the key handle.

5 . The computer platform of claim 1 , wherein:

the security processor further comprises a random number generator;

the hardware processor to further, in response to a creation of the password:

initiate an operation of the security processor in which the random number generator generates a number;

designate the number as the cryptographic key;

initiate an operation of the security processor to load an object into the secure storage; and

pass the cryptographic key as the object to the operation to load the object into the secure storage.

6 . The computer platform of claim 1 , wherein the hardware processor to further, responsive to the password changing to a second password:

provide the key handle and the second password to the security processor and initiate an operation of the security processor in which the keyed-hash generator generates a third cryptographic hash based on the second password and the cryptographic key; and

modify the authentication record responsive to the password changing, including replacing the first cryptographic hash with the third cryptographic hash.

7 . The computer platform of claim 1 , wherein the security processor comprises a trusted platform module (TPM).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2024
From: KUMAR, CHAITANYA GALI; PRAJAPATI, AMIT; ALPHONSE, ANCITTA
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 066331/0781 →
Priority Claims (1)
IN 202341084771 · Dec 12, 2023 · national
Continuity (1)
Related Publication 20250192999A1 · Jun 12, 2025
References Cited (14)
US 4924515A · Matyas · 1990 [cited by examiner]
US 6370250B1 · Stein · 2002 [cited by examiner]
US 6950523B1 · Brickell · 2005 [cited by examiner]
US 7961884B2 · Edgett · 2011 [cited by examiner]
US 20020141575A1 · Hird · 2002 [cited by examiner]
US 20030021417A1 · Vasic · 2003 [cited by examiner]
US 20080092239A1 · Sitrick · 2008 [cited by examiner]
US 20140140508A1 · Kamath · 2014 [cited by examiner]
US 20180367316A1 · Cheng · 2018 [cited by examiner]
US 20190052467A1 · Bettger · 2019 [cited by examiner]
US 20240283645A1 · Lavine · 2024 [cited by examiner]
US 20240406010A1 · Chotrani · 2024 [cited by examiner]
US 20250192999A1 · Kumar · 2025 [cited by examiner]
Trusted Computing Group, “TPM 2.0 Library”, available online at <https://trustedcomputinggroup.org/resource/tpm-library-specification/>, 2024, 11 pages. [cited by applicant]