IP Library Granted Patent US 8,667,568
Granted Patent B2
US 8,667,568 · App. 12/156,313 · Granted Mar 4, 2014

Securing a password database

Inventor: James Paul Schneider (Raleigh, NC)
Assignee: Red Hat, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,667,568
App. No.
12/156,313
Granted
Mar 4, 2014
Kind
B2
Abstract

An apparatus and a method for storing an encrypted username and password. In one embodiment, a username is encrypted. A password associated with the username is encrypted. A user identifier associated with the username is encrypted. The encrypted username, the encrypted password, and the user identifier are stored in one or more database.

Claims (42)

1. A method comprising:

encrypting, by a computer system, information pertaining to a user account, wherein the user account enables a user to access a system, and wherein the user account comprises a unique username and a password, and wherein the encrypting comprises:

encrypting, using a first hash algorithm, the username;

encrypting, using a second hash algorithm, the password;

encrypting a user identifier associated with the username, wherein the user identifier is encrypted using a third algorithm that comprises a username-derived salt value as a key; and

encrypting an account property of the user account, wherein the user identifier is a key for the account property;

storing in a first location, by the computer system, the encrypted username, the encrypted password, and the encrypted user identifier; and

storing in a second location, the encrypted account property.

2. The method of claim 1 , wherein the first location is a first database, and wherein the second location is a second database.

3. The method of claim 1 , wherein the username is augmented with a salt value prior to being encrypted.

4. The method of claim 3 , wherein the salt value is based on the encrypted password, the username, and an authentication context identifier.

5. The method of claim 1 , wherein the password is augmented with a salt value prior to being encrypted.

6. The method of claim 5 , wherein the salt value is based on the username and an authentication context identifier.

7. The method of claim 1 , wherein the encrypting of the password is based on a plaintext value of the username.

8. The method of claim 1 , wherein the third algorithm comprises a block cipher.

9. A server comprising:

a memory to store encrypted information pertaining to a user account, wherein the user account enables a user to access a system, and wherein the user account comprises a unique username and a password; and

a processing device coupled to the memory to:

encrypt, using a first hash algorithm, the username,

encrypt, using a second hash algorithm, the password,

encrypt a user identifier associated with the username, wherein the user identifier is encrypted using a third algorithm that comprises a username-derived salt value as a key,

encrypt an account property of the user account, wherein the user identifier is a key for the account property,

store in a first location the encrypted username, the encrypted password, and the encrypted user identifier, and

store in a second location, the encrypted account property.

10. The server of claim 9 , wherein the first location is a first database, and wherein the second location is a second database.

11. The server of claim 9 , wherein the processing device is further to augment the username with a salt value prior to the encrypting of the username, wherein the salt value is based on the encrypted password, the username, and an authentication context identifier.

12. The server of claim 9 , wherein the processing device is further to augment the password with a salt value prior to the encrypting of the password, wherein the salt value is based on the username and an authentication context identifier.

13. The server of claim 9 wherein the encrypting of the password is based on a plaintext value of the username.

14. A non-transitory computer-accessible storage medium comprising instructions stored therein which, when executed, cause a processing device to perform operations comprising:

encrypting, by the processing device, information pertaining to a user account, wherein the user account enables a user to access a system, and wherein the user account comprises a unique username and a password, and wherein the encrypting comprises:

encrypting, using a first hash algorithm, the username;

encrypting, using a second hash algorithm, the password;

encrypting a user identifier associated with the username, wherein the user identifier is encrypted using a third algorithm that comprises a username-derived salt value as a key; and

encrypting an account property of the user account, wherein the user identifier is a key for the account property;

storing in a first location, by the processing device, the encrypted username, the encrypted password, and the encrypted user identifier; and

storing in a second location, the encrypted account property.

15. The non-transitory computer-accessible storage medium of claim 14 , wherein the first location is a first database, and wherein the second location is a second database.

16. The non-transitory computer-accessible storage medium of claim 14 , wherein the username is augmented with a salt value prior to being encrypted; and wherein the salt value is based on the encrypted password, the username, and an authentication context identifier.

17. The non-transitory computer-accessible storage medium of claim 14 , wherein the password is augmented with a salt value prior to being encrypted.

18. The non-transitory computer-accessible storage medium of claim 17 , wherein the salt value is based on the username and an authentication context identifier.

19. The non-transitory computer-accessible storage medium of claim 14 , wherein the encrypting of the password is based on a plaintext value of the username.

20. The transitory computer-accessible storage medium of claim 14 , wherein the third algorithm comprises a block cipher.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2008
From: SCHNEIDER, JAMES PAUL
To: RED HAT, INC.
Reel/Frame 021084/0488 →
Continuity (1)
Related Publication 20090327740A1 · Dec 31, 2009