IP Library Granted Patent US 11,558,374
Granted Patent B2
US 11,558,374 · App. 17/219,581 · Granted Jan 17, 2023

Systems, apparatus, and methods for verifying a password utilizing commitments

Inventors: Igor Stolbikov (Apex, NC); Joshua N. Novak (Wake Forest, NC); Scott Wentao Li (Cary, NC)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04L63/0846H04L9/3066H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,558,374
App. No.
17/219,581
Granted
Jan 17, 2023
Kind
B2
Abstract

Methods that can verify a password utilizing commitments are provided. One method includes receiving from a client device and storing, by a processor, an initial commitment representing a password for a user account without storing the actual password on the apparatus, receiving, from the client device, a subsequent commitment, and verifying that the subsequent commitment represents the password for the user account based on a difference between the initial commitment and the subsequent commitment. Systems and apparatus that can include, perform, and/or implement the methods are also provided.

Claims (79)

1. An apparatus, comprising:

a processor of an information handling device; and

a memory configured to store code executable by the processor to:

receive, from a client device, and store an initial commitment representing a password for a user account without storing the actual password on the apparatus,

receive, from the client device, a subsequent commitment, and

verify that the subsequent commitment represents the password for the user account based on a difference between the initial commitment and the subsequent commitment,

wherein the initial commitment and the subsequent commitment are each time-based commitments.

2. The apparatus of claim 1 , wherein the initial commitment and the subsequent commitment are each Pedersen time-based commitments.

3. The apparatus of claim 1 , wherein:

the initial commitment is represented by a first commitment equation C0=(S0*G+R0*H0), and

the subsequent commitment is represented by a second commitment equation C1=(S1*G+R1*H1),

where,

S0 is a first hashed value of the password,

G is an elliptical generator value for an elliptical curve,

R0 is a first salt value,

H0 is the G elliptical generator value hashed to an initial timestamp value to a point on the elliptical curve,

S1 is a second hashed value of the password,

R1 is a second salt value,

H1 is the G elliptical generator value hashed to a subsequent timestamp value to the point on the elliptical curve.

4. The apparatus of claim 3 , wherein the password is verified in response to C1−C0=(R1*H1—R0*H0).

5. The apparatus of claim 4 , wherein:

R0 is a first random salt value;

R1 is a second random salt value; and

S0 and S1 are a same hashed value for the password.

6. The apparatus of claim 3 , wherein:

R0 is a first random salt value;

R1 is a second random salt value; and

S0 and S1 are a same hashed value for the password.

7. A method, comprising:

receiving from a client device and storing, by a processor, an initial commitment representing a password for a user account without storing the actual password on the apparatus;

receiving, from the client device, a subsequent commitment; and

verifying that the subsequent commitment represents the password for the user account based on a difference between the initial commitment and the subsequent commitment,

wherein the initial commitment and the subsequent commitment are each time-based commitments.

8. The method of claim 7 , wherein the initial commitment and the subsequent commitment are each Pedersen time-based commitments.

9. The method of claim 7 , wherein:

the initial commitment is represented by a first commitment equation C0=(S0*G+R0*H0), and

the subsequent commitment is represented by a second commitment equation C1=(S1*G+R1*H1),

where,

S0 is a first hashed value of the password,

G is an elliptical generator value for an elliptical curve,

R0 is a first salt value,

H0 is the G elliptical generator value hashed to an initial timestamp value to a point on the elliptical curve,

S1 is a second hashed value of the password,

R1 is a second salt value,

H1 is the G elliptical generator value hashed to a subsequent timestamp value to the point on the elliptical curve.

10. The method of claim 9 , wherein the password is verified in response to C1−C0=(R1*H1−R0*H0).

11. The method of claim 10 , wherein:

R0 is a first random salt value;

R1 is a second random salt value; and

S0 and S1 are a same hashed value for the password.

12. The method of claim 9 , wherein:

R0 is a first random salt value;

R1 is a second random salt value; and

S0 and S1 are a same hashed value for the password.

13. A computer program product comprising a non-transitory computer-readable storage medium configured to store code executable by a processor, the executable code comprising code to perform:

receiving from a client device and storing an initial commitment representing a password for a user account without storing the actual password on the apparatus;

receiving, from the client device, a subsequent commitment; and

verifying that the subsequent commitment represents the password for the user account based on a difference between the initial commitment and the subsequent commitment,

wherein the initial commitment and the subsequent commitment are each time-based commitments.

14. The computer program product of claim 13 , wherein the initial commitment and the subsequent commitment are each Pedersen time-based commitments.

15. The computer program product of claim 13 , wherein:

the initial commitment is represented by a first commitment equation C0=(S0*G+R0*H0), and

the subsequent commitment is represented by a second commitment equation C1=(S1*G+R1*H1),

where,

S0 is a first hashed value of the password,

G is an elliptical generator value for an elliptical curve,

R0 is a first salt value,

H0 is the G elliptical generator value hashed to an initial timestamp value to a point on the elliptical curve,

S1 is a second hashed value of the password,

R1 is a second salt value,

H1 is the G elliptical generator value hashed to a subsequent timestamp value to the point on the elliptical curve.

16. The computer program product of claim 15 , wherein the password is verified in response to C1−C0=(R1*H1—R0*H0).

17. The computer program product of claim 16 , wherein:

R0 is a first random salt value;

R1 is a second random salt value; and

S0 and S1 are a same hashed value for the password.

18. The apparatus of claim 1 , wherein the processor is configured to utilize a time-based commitment schema to verify that the subsequent commitment represents the password for the user account based on the difference between the initial commitment and the subsequent commitment.

19. The method of claim 7 , wherein verifying that the subsequent commitment represents the password for the user account based on a difference between the initial commitment and the subsequent commitment comprises utilizing a time-based commitment schema to verify that the subsequent commitment represents the password for the user account based on the difference between the initial commitment and the subsequent commitment.

20. The computer program product of claim 13 , wherein the executable code to perform verifying that the subsequent commitment represents the password for the user account based on a difference between the initial commitment and the subsequent commitment comprises executable code to perform utilizing a time-based commitment schema to verify that the subsequent commitment represents the password for the user account based on the difference between the initial commitment and the subsequent commitment.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: LENOVO PC INTERNATIONAL LIMITED
To: LENOVO SWITZERLAND INTERNATIONAL GMBH
Reel/Frame 070269/0092 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2025
From: LENOVO (SINGAPORE) PTE LTD.
To: LENOVO PC INTERNATIONAL LIMITED
Reel/Frame 070266/0906 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2021
From: STOLBIKOV, IGOR; NOVAK, JOSHUA; LI, SCOTT WENTAO
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 057375/0813 →
Continuity (1)
Related Publication 20220321555A1 · Oct 6, 2022