Authentication Using Well-Distributed Random Noise Symbols
By introducing noise symbols at the user-specified locations and using distance metrics for authentication, the problem of remote authentication in the prior art is solved that the problem of noise-influenced and eavesdropping attacks is achieved, and higher security and stability are achieved.
Patent Information
- Application Number
- CN202080042432.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-06-10
- Filing Date
- 2020-04-28
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2040-04-28
AI Technical Summary
Existing authentication systems are susceptible to the introduction of noise in remote authentication, resulting in authentication failure, and security vulnerabilities caused by eavesdroppers monitoring user input credentials.
Introduce noise symbols at the user-specified location and by decomposing the submitted symbols into multiple vectors, a distance metric is used to determine whether authentication should be allowed. The authenticator does not know the location and content of the noise symbol, which increases resistance to the eavesdropper.
Improves the security of the authentication system, prevents eavesdroppers and man-in-the-middle attacks, and reduces authentication failures caused by noise.
Smart Images

Figure CN113939816B_ABST
Abstract
Description
Background Art
[0001] A user attempting to access a secure access-controlled resource performs an authentication attempt, whereby the user enters one or more credentials, such as a username and password. The entered credentials are compared with stored credentials to determine whether the username and password match a valid account authorized to access the secure access-controlled resource. If the credentials match a valid account authorized to access the secure access-controlled resource, the system may grant access to the access-controlled resource. Brief Description of the Drawings
[0002] In the drawings, which are not necessarily drawn to scale, like numerals may describe like components in different views. Like numerals with different letter suffixes may represent different instances of like components. The drawings generally illustrate, by way of example and not limitation, the various embodiments discussed in this document.
[0003] Figure 1 An exemplary authentication environment is illustrated in accordance with some examples of the present disclosure, in which a user of a user device may be authenticated to access a secure access-controlled resource.
[0004] Figure 2 An exemplary authentication environment is illustrated in accordance with some examples of the present disclosure, in which a user may be authenticated to access a secure access-controlled resource.
[0005] Figure 3 A diagram of a data stream for authentication using additional, unspecified noise symbols is illustrated in accordance with some examples of the present disclosure.
[0006] Figure 4 A flowchart of a method for authenticating a user is illustrated in accordance with some examples of the present disclosure.
[0007] Figure 5 A flowchart of a method for authenticating a user is illustrated in accordance with some examples of the present disclosure.
[0008] Figure 6 A flowchart of a method for authenticating a user is illustrated in accordance with some examples of the present disclosure.
[0009] Figure 7 and Figures 8A - 8C A diagram of an exemplary graphical user interface (GUI) for allowing a user to enter authentication credentials is illustrated in accordance with some examples of the present disclosure.
[0010] Figure 9 A diagram of a user device and a remote device having distributed authentication functions is illustrated in accordance with some examples of the present disclosure.
[0011] Figure 10The figure illustrates a flowchart of a method for authenticating a user by using size constraints according to some examples of the present disclosure.
[0012] Figure 11 The figure illustrates a flowchart of a method for authenticating a user by using a dispersion metric criterion according to some examples of the present disclosure.
[0013] Figure 12 The figure illustrates a diagram of a data stream for authentication by using additional, unspecified noise symbols according to some examples of the present disclosure.
[0014] Figure 13 The figure illustrates a diagram of a data stream for an authentication attempt by using additional, unspecified noise symbols and a forced subset of credentials according to some examples of the present disclosure.
[0015] Figures 14 - 16 The figure illustrates a flowchart of a method for authenticating a user by using a subset of credentials according to some examples of the present disclosure.
[0016] Figure 17 The figure illustrates a block diagram of an exemplary machine that can implement one or more of the techniques (e.g., methods) discussed herein (e.g., methods). Detailed Description
[0017] Figure 1 The figure illustrates an exemplary authentication environment 100 according to some examples of the present disclosure, where a user of a user device 110 can be authenticated to access a secure access-controlled resource 130. As shown in Figure 1 The secure access-controlled resource 130 can be a secure access-controlled resource 130 of the user device 110 or a secure access-controlled resource 130 provided by a remote device 135 accessible via a network 175. The secure access-controlled resource 130 can include: access to one or more files, portions of files (e.g., fields or data structures), applications, access to an operating system, access to the user device 110 itself, access to one or more network-based services (e.g., social networking services, file sharing services, email, communication services, etc.), access to physical objects (e.g., unlocking an object by computer control), etc.
[0018] Network 175 can include any computing network, including: local area network (LAN), wide area network (WAN), Internet, etc. At user device 110, a user makes an authentication attempt to request access to a secure access-controlled resource 130. An authentication attempt is an attempt by the user to prove possession of a valid credential for accessing the secure access-controlled resource. As part of the authentication attempt, client 125 can cause a user interface (UI) 127 (which can be a graphical UI (GUI)) to be displayed that requests the user credentials required to access the secure access-controlled resource 130. Exemplary credentials include: username, password, biometrics, tokens, digital certificates, encryption keys, etc.
[0019] Client 125 can then pass the credentials entered by the user to authenticator 120. Authenticator 120 can determine whether the credentials entered by the user are valid. If the credentials are valid, authenticator 120 can grant access to the secure access-controlled resource 130. If the credentials are invalid, authenticator 120 can deny access to the secure access-controlled resource 130. If the secure access-controlled resource 130 is controlled by remote device 135, authenticator 120 can send a message across network 175 to indicate to remote device 135 whether the user is authorized to access the secure access-controlled resource. Client 125 can then notify the user via UI 127 whether access has been granted.
[0020] Figure 2 An exemplary authentication environment 200 is illustrated in accordance with some examples of the present disclosure, in which a user of user device 110 can be authenticated to access a secure access-controlled resource 130. Figure 2 Similar to Figure 1 except that authenticator 120 is located on remote device 250. As in Figure 1 a user enters credentials via UI 127 of client 125. In some examples, the UI can be provided entirely by client 125, but in other examples, the UI can be provided partially by remote device 250 (e.g., via one or more files transmitted by remote device 250 and presented by client 125 to create UI 127). The client transmits the credentials to authenticator 120 of remote device 250 via network 175. When transmitting the credentials across network 175, the credentials can be encrypted, e.g., by using a Secure Sockets Layer connection.
[0021] In Figure 2In the example, the secure access-controlled resource 130 can reside at the user device 110, the remote device 250, or the second remote device 255. The authenticator 120 can send an indication to the device where the secure access-controlled resource 130 is located to indicate whether the user is authenticated - either directly or through the client 125. In some examples, the indication can be a direct message to the device (e.g., such as the user device 110 or the second remote device 255). In other examples, if the user is successfully authenticated, the authenticator 120 can issue a token to the client 125. The token can be sent by the user device 110 to any device where the secure access-controlled resource 130 is located. The device (e.g., 110, 250, or 255) then verifies the token, and if the token is verified, grants the user access to the secure access-controlled resource.
[0022] In a conventional authentication system, a user types in credentials, which are checked (or otherwise verified) against stored credentials to determine whether the entered credentials exactly match the stored credentials. Although requiring an exact match is the most secure verification method in a conventional authentication system to prevent hackers from attempting to guess the credentials using a brute-force attack, requiring an exact match can be problematic for remote authentication because noise may be introduced over the communication channel, which can lead to authentication failures. Additionally, exact-match systems have security vulnerabilities because they expose the user's exact credentials to eavesdroppers. For example, the security vulnerability may be caused by a malicious user eavesdropping on the user's keyboard as the legitimate user types their password (so-called shoulder surfing), using a keylogger that directly steals data from the user's keyboard, or using a man-in-the-middle attack that intercepts communications such as the credentials that may be sent to the server. In a system that requires an exact match for user credentials, an eavesdropper only needs to intercept a single authentication attempt to compromise the user's account.
[0023] To obtain better security against these eavesdropping attacks, some exact-match authentication systems require the input of one or more noise symbols interspersed with the legitimate credentials. Noise symbols are one or more symbols that are not part of the user's credentials and are not checked against the stored credentials to determine a match with the user's stored credentials. A symbol is one or more data units, such as characters, bytes, words, etc. The device authenticating the password removes these noise symbols to check for an exact match with the stored credentials. These techniques may defeat shoulder surfers who attempt to spy on the user's password by observing the characters the user types. Additionally, adding noise characters to the password can also prevent specific keyloggers that monitor the keys the user types or man-in-the-middle attackers who intercept the user's communications from determining the user's password, as this may require multiple observations to discern the user's true password.
[0024] Authenticators in authentication systems that introduce noise symbols into credentials typically need to filter out the noise symbols in the credentials before checking for an exact match. To achieve this, the authenticator must know which symbols are noise symbols and which symbols are part of the credential. In some examples, the authentication system introduces noise symbols at credential positions specified for all authentication attempts. For example, the authentication system can specify that all authentication attempts must place noise symbols at the beginning, end, beginning and end, or at other predetermined positions within the credential symbols. These positions do not change in subsequent login attempts. That is, each login attempt uses additional noise symbols at one or more of these same positions.
[0025] In other examples, the authenticator (either on the user device or at a remote device) can specify for a particular authentication attempt that the user place noise symbols at specified positions in the credential. For example, the user can be instructed to insert three noise symbols N before the first symbol of password P, between the second and third symbols, and between the fourth and fifth symbols to produce the submitted symbols {N 1 ,P 1 ,P 2 ,N 2 ,P 3 ,P 4 ,N 3 ,P 5 ...P m}, where m is the length of password P. The symbols for these noise symbols N can be specified by the authenticator, or the user can decide when to type random characters. In some examples, the symbols can be characters and the credential can be a password, so the user can insert noise characters within the password at specified character positions within the password.
[0026] The authenticator then removes the noise symbols N from the submitted symbols. Authentication is easily achieved on these systems because knowing exactly the positions of the noise symbols enables those symbols to be easily removed and thus enables a direct comparison between the input symbols and the stored credential. These systems may not effectively address the problem of password eavesdropping because an eavesdropper may also be able to determine the positions where noise is inserted into the password and thus be able to accurately remove the noise. For example, if the positions are shown to the user, a peeping tom behind will also be able to see which positions are noise symbols. Additionally, if the authenticator is located remotely, the authenticator may send a message to the client device indicating where the user should insert the noise. This message may be intercepted by a man-in-the-middle attack. The potential ways for an attacker to access the specified positions make these systems inefficient.
[0027] Methods, systems, and machine-readable media are disclosed in some examples that allow for more secure authentication attempts by implementing an authentication system that utilizes a credential that includes scattered noise symbols. These systems allow the noise symbols N to be located in positions determined by the user, where the positions are not specified to the authenticator for authentication attempts, which creates a higher level of security against eavesdroppers because the eavesdropper cannot determine in advance where the noise symbols (e.g., characters) are. Although these systems are more secure, they are not easily authenticated. For example, since the authenticator does not know the location of the noise symbols, it is not easy to ignore the noise symbols N to determine if the remaining characters match the password.
[0028] In the disclosed examples, the noise symbols (e.g., characters) and their locations within the credential are not specified by the system for a particular authentication attempt. The user can decide where to place the random noise symbols and what the random noise symbols are when entering the credential. The authenticator compares the submitted characters (the credential with scattered noise symbols) to the stored credential without knowing where the noise symbols are within the credential symbols and also without knowing what symbols the noise symbols are.
[0029] To authenticate the user, the authenticator decomposes the submitted symbols into multiple vectors of length m, where m corresponds to the number of symbols in the valid credential (e.g., the length of the password). The order of the symbols is maintained in each of the multiple vectors such that the order of each symbol within the vector relative to another symbol in the vector matches the received order. Then, a distance metric that quantifies the distance between each vector and a vector that includes the credential symbols is calculated. Based on the distance metric, it can be determined whether the credential matches and whether the user is authenticated. In some examples, the credential is a password and the symbols are characters.
[0030] Accordingly, the present disclosure solves the technical problem of providing secure access to a controlled resource using one or more secure credentials (such as a password) that are resistant to keyloggers, eavesdroppers, and man-in-the-middle attacks. This is achieved by introducing user-specified noise symbols (e.g., characters) introduced at user-specified locations. The authenticator does not know where the noise symbols are introduced or what the noise symbols are. The authenticator decomposes the submitted symbols into multiple vectors and uses a distance metric to determine whether authentication should be granted. In some examples, the method can protect against brute force attacks by limiting the number of authentication attempts a user can make by locking the user out of their account (permanently or temporarily) after a threshold number of unsuccessful login attempts.
[0031] Figure 3FIG. illustrates a diagram of a data stream 300 for authentication using additional, unspecified noise symbols in accordance with some examples of the present disclosure. According to the exemplary data stream 300, an input credential 310 (e.g., a password) can include three symbols 312, 314, and 316 in the order of {P1, P2, P3}, which can be in the form of characters. When the user inputs the credential, one or more noise symbols 320 are added to the credential in the form of noise characters. In Figure 3 In the example shown, for ease of description, only one noise symbol 320 is added. The submission symbol 325 submitted by the user for authentication includes the credential symbols 312, 314, and 316 (in order) and one or more noise symbols 320 inserted into the credential symbols.
[0032] The authenticator 327 includes a vector creator 330 that receives the submission symbol 325 and creates a plurality of vectors of length m, where m is the number of symbols of the user's stored credential 350 (e.g., the length of a valid password). The vectors reflect each possible ordered combination of length m of the submission symbol 325. The order of the characters in each vector is the same as the order of the symbols in the submission symbol 325. That is, if the combination sequence is "plas" and the credential is "pas", then the length of the vectors will all be three and will reflect all possible ordered (i.e., each character maintains its order as it appears in the submission symbol 325) combinations. In this example, the vectors will be:
[0033] <p,1,a>,<p,a,s>,<p,1,s>,<1,a,s>
[0034] Each vector is then passed to a distance metric calculator 335 that calculates the distance between each vector in the vectors and the vector of the stored credential 350. In some examples, the distance metric can be the Levenshtein distance. In other examples, the distance metric can compare each symbol of each vector with the corresponding position in the stored credential 350. If the symbols match, the score may not be increased. If the symbols do not match, the score may be increased. In other examples, a higher score reflects a better match, and thus matching symbols may increase the score, and non-matching symbols may leave the score unchanged or may decrease the score. In still other examples, the distance metric can be related to the stored credential 350, such as the Pearson correlation coefficient. In other examples, other edit distance metrics or algorithms can be used.
[0035] Then, the distance metric for each of the vectors is passed to a match determination logic unit 340. In some examples, the match determination logic unit 340 identifies the distance metric (e.g., the minimum distance) that represents the closest match to the stored credential 350. This could be the highest score (in the case of assigning points for a match), or it could be the lowest score, depending on the desired implementation. If the distance metric representing the closest match is closer to the stored credential 350 than a threshold (e.g., the distance is less than the threshold), then the match determination logic unit 340 can return that a match has been found. In an example, meeting the threshold may require a perfect match. In other examples, the match determination logic unit identifies two distance metrics that represent the two closest matches to the stored credential 350 (e.g., the minimum distance and the next minimum distance). The match determination logic unit can then take the ratio of the two distance metrics and compare it to a threshold to determine if there is a match. In some examples, the use of the threshold allows for authentication even when the credential 310 entered in the submission symbol 325 does not perfectly match the stored credential 350. This can allow for a certain level of noise tolerance in cases where the symbols of the input credential 310 are replaced by noise symbols during transmission.
[0036] Access control 345 can then grant or deny access to the secure access-controlled resource based on the result from the match determination logic unit 340. For example, access control 345 can send a message to the computer device hosting the secure access-controlled resource to provide the result of the authentication attempt. In some examples, access control 345 can send a token to the user device or the device hosting the secure access-controlled resource. In other examples, access control 345 can provide the secure access-controlled resource. In some examples, the access control can send a signal to a physical device that can provide access to a physical resource (e.g., unlock a door).
[0037] Figure 4 A flowchart of a method 400 for authenticating a user according to some examples of the present disclosure is illustrated. At operation 410, an authenticator identifies a first set of symbols (e.g., characters) corresponding to a stored value such as a credential (e.g., username, password, encryption key). As used herein, a symbol is a data unit such as a character, word, byte, or other group of data. At operation 420, the authenticator receives a second set of symbols (e.g., characters) to be compared to the stored value, the second set of symbols including more symbols (e.g., noise characters) than the first set of symbols. For example, the symbols can be input credential symbols (e.g., a password) with additional noise symbols (e.g., characters), and the stored value can be a credential such as a password.
[0038] At operation 430, the authenticator determines whether the second set of symbols includes a first subset of symbols that match the stored value. For example, the authenticator determines whether the second set of characters includes credentials such as a password. If the second set of symbols does not include the stored value, access can be denied at operation 460. If the second set of symbols includes the stored value, the process moves to operation 440. In some examples, to determine whether the second set of symbols includes the stored value, the second set of symbols can be decomposed into a set of ordered vector combinations of the second set of values, each of size m, where m is the number of symbols in the stored credentials. The vectors reflect each possible ordered length m combination of the submitted symbols. A distance metric can be calculated for each vector in the vectors, which measures the distance between the stored value and each vector. The decision as to whether the second set of symbols includes the stored value can be based on the distance metric and whether at least one of the distance metrics is within a threshold distance of the stored value.
[0039] At operation 440, the authenticator determines whether the second set of symbols includes a second subset of unspecified symbols in one or more unspecified positions within the second set of symbols. For example, the authenticator determines whether noise characters have been added to password characters. In some examples, the authenticator can ensure that additional symbols are entered to protect the user from eavesdropping attacks. If no additional noise symbols are added, access is denied at operation 460. Otherwise, access can be granted at operation 450. Note that the authenticator does not specify where the noise symbols will be placed and what the noise symbols are for any authentication attempt. This protects the user by preventing eavesdropping on these positions.
[0040] Figure 5The figure illustrates a flowchart of a method 500 for authenticating a user according to some examples of the present disclosure. At operation 510, an authenticator receives a set of submitted symbols during an authentication attempt. In some examples, the symbols are characters. In some examples, the received set of symbols includes more symbols than a first set of symbols corresponding to a stored value, such as a credential. For example, the input characters include noise characters. At operation 520, the authenticator creates a set of two or more vectors, each vector having a length corresponding to the length of an ordered vector that includes the first set of symbols corresponding to the stored value (e.g., the stored credential), and each vector including a different ordered combination of the received set of symbols, the different ordered combinations of the received set of symbols being ordered in the same order as the symbols were received. For example, if the received set of characters is {p, #, a, r, s, s} and the password (stored value) is {p, a, s, s}, then a set of vectors of length 4 is created. In this example, the system will create a vector for each ordered combination of 4 characters of the received set of characters.
[0041] Ordered means that the symbols in the vector maintain the sorting of the symbols in the submitted symbols relative to each other. In other words, in the above example, if the character 'p' is in the vector, then that character will always be the first character in the password characters (regardless of noise symbols). The 'a' character in the vector will be the first character in the password characters (if 'p' is not in the vector) or the second character (if 'p' is in the vector) (similarly, regardless of noise symbols). Thus, in the above example, the following are valid vectors:
[0042] 1. p#ar
[0043] 2. #ars
[0044] 3. arss
[0045] 4. pars
[0046] 5. prss
[0047] 6. p#rs
[0048] 7. pass
[0049] 8. #rss
[0050] 9. #ass
[0051] 10. p#as
[0052] 11. p#ss
[0053] At operation 530, the authenticator may determine a set of distances between each respective vector and an ordered vector of a first set including symbols corresponding to the stored values. As previously noted, the set of distances may be determined by one or more distance metrics, such as the Levenshtein distance; a simple total number of points where points are added or subtracted based on symbol differences; or statistical correlation. For example, a system using a point value system may add a value of 1 to the score for a symbol position that does not match and add a value of 0 to the symbol position that matches the stored value (e.g., stored credentials). In the above example, using this simple distance metric, the distances would be: {3, 2, 2, 1, 1, 2, 0, 2, 2}. In still other examples, the vector may simply be compared to the stored value to determine if a match exists. In yet other additional examples, the distance metric may be statistical correlation.
[0054] At operation 540, the system may select a vector from the set of vectors based on the distances in the set of distances. For example, the system may select the vector having the shortest distance from the vector of the stored value. In the above example, the distance of the vector "pass" is "0", and thus this vector may be selected.
[0055] At operation 550, the system may cause access to computer resources to be granted based on a comparison of the value corresponding to the selected vector to a threshold. For example, a comparison of the distance value to a threshold. In other examples, the value may be a ratio of the distance value of the vector to a second vector (e.g., the second closest vector). The threshold may be predetermined or specified. In other examples, the threshold may be determined based on the length of the stored value. That is, for a shorter stored value, the threshold may be set such that a closer match between the submitted symbols and the stored value is required for increased security. Thus, a three-character stored value may have a lower threshold than a ten-character stored value (where lower is a closer match).
[0056] Figure 6 A flowchart of a method 600 for authenticating a user according to some examples of the present disclosure is illustrated. At operation 610, the client may cause a GUI to be displayed. For example, at Figure 7The GUI shown in []. The GUI may have one or more data input fields for a user to input one or more symbols of one or more credentials. For example, the GUI may include an input field for accepting characters of the requested authentication credentials from an input device. In some examples, the GUI accepts the requested authentication credentials in the form of a set of symbols (e.g., characters). Exemplary input devices may include: a keyboard, an on-screen keyboard, mouse input, touch input, biometric input, etc. In some examples, the GUI may require that the set of symbols (e.g., characters) includes more symbols (e.g., characters) than the stored credentials. For example, by checking the length of the characters entered by the user and checking that length against the length of the stored password. In some examples, the GUI may require that the set of characters includes a threshold number of symbols more than the stored credentials. The threshold may be pre-specified or may be determined based on the length of the credential. For example, if the credential (e.g., password) is short, the system may require more noise symbols than when the credential is long. In other examples, the system may compare the value of the submitted symbols of the input with the symbol values of the credential to determine if noise symbols have been added.
[0057] In some examples, the client can perform a check to ensure that noise symbols (e.g., characters) are scattered within the submitted credential. For example, if the noise symbols are at the beginning, end, or both the beginning and end, but not scattered within the submitted symbols, the client may display an error. For example, if the scatter measurement of the position of the noise symbols within the entire credential symbols is below a threshold, the client may show an error and prompt the user to fix the submitted symbols so that the scatter measurement is above or equal to the threshold. The scatter measurement is described in more detail below.
[0058] If any of the above checks indicates that the user's submitted symbols (e.g., characters) do not meet one or more of the above requirements, the client can display an error and prompt the user to correct the submitted symbols. The error can be displayed once the user submits the symbols by specifying the completion of the input of the symbols (e.g., pressing ENTER, clicking, or tapping a button indicating completion of the input, etc.). In other examples, the system can monitor the symbols being input as the user enters them. For example, after a predetermined number of symbols (e.g., the length of the stored credential), the system can check the symbols for length, noise symbols, and / or scatter measurement depending on the implementation. Exemplary warnings to the user are shown in Figures 8A - 8C are shown.
[0059] At operation 620, the client can accept symbols (e.g., characters) entered by the user in one or more data input fields of the GUI. For example, where the user has submitted input indicating that the symbol set is complete and the character set meets requirements (e.g., length greater than the credential; submitted symbols include noise characters; the noise is scattered; and / or the noise is scattered and the scatter measurement result is higher than a threshold).
[0060] At operation 630, the client can receive or recognize an indication of whether access is granted. In some examples, the client can send the submitted symbols to a remote authenticator in a remote computing device, such as shown in Figure 2 The client can then receive an indication from the remote device as to whether access is granted. In other examples, the client itself can include an authenticator and can perform authentication as shown in Figure 1 In these examples, the indication can be an indication received from the authenticator, via function return, inter - process communication, etc., as to whether access is granted.
[0061] At operation 632, the system can determine whether the indication is that access is granted or denied. If access is denied, then at operation 645, the GUI can be caused to display a message that access is denied. In some examples, the user can retry authentication. In some examples, a limit on the number of retry attempts can be implemented to prevent the user from retrying the authentication after a determined number of authentication failures within a determined amount of time.
[0062] If at operation 632 access is granted, then at operation 635, the system can indicate that access has been granted. For example, the system can cause the GUI to display an indication that access is granted. In other examples, the system can simply remove the login screen and expose access to the access - controlled resource. In other examples, the system can provide the requested access - controlled resource. At operation 640, in some examples, the client can facilitate access to the requested secure access - controlled resource, such as by redirecting the user's browser to the address for the resource, performing a function that provides the resource, etc.
[0063] Figure 7 A diagram illustrating an exemplary GUI for allowing a user to enter authentication credentials, according to some examples of the present disclosure. In the example of Figure 7 there are two credentials: a username and a password. The user can select one of the boxes next to the requested credential and type the symbols for the requested credential. For example, the user can type the symbols for the username and / or password. When the user is done, the user can enter an input specifying that the input of the characters is complete (e.g., press ENTER, click, or tap a submit button indicating input completion, etc.).
[0064] Figures 8A - 8C A diagram illustrating an exemplary GUI for allowing a user to input their authentication credentials according to some examples of the present disclosure. In Figure 8A , the user has started typing the user's password, and the client has recognized that the user has not added any noise characters. The client then uses a warning to prompt the user. The warning can be in response to the user typing a threshold number of characters that do not include noise characters. In some examples, once the user inputs the first noise character, the warning can disappear. In other examples, the client can calculate the ratio between the noise characters and the legitimate password characters. When the ratio is below a specified threshold ratio, the warning can be displayed. In some examples, a warning can be displayed when the spread metric is not within the target spread metric (e.g., not higher or lower than a threshold, or not within a specified range). In other examples, the warning can be shown in response to the user selecting "Submit", and the user can be prohibited from continuing until it is corrected.
[0065] In Figure 8B , the user has started typing the password, and the client has recognized that the password is longer or shorter than a fixed length. In this example, a fixed length is required for the user's input. The fixed length can include a fixed total length for all characters of the input, or a fixed length for the noise characters. In an example, the password input box can restrict the user so that preventing the input of more characters than the fixed limit. In an example, the client can use a warning about the fixed length issue to prompt the user. In some examples, once the user inputs the number of characters equal to the fixed length, the warning can disappear. In other examples, the fixed length can be a minimum length, such that when the input is of the fixed length or more characters, the warning can disappear. In other examples, the warning can be shown in response to the user selecting "Submit", and the user can be prohibited from continuing until it is corrected.
[0066] In Figure 8C , the user has started typing the password, and the client has recognized that the input characters do not include a subset of a valid password. For example, the input characters may include the entire password or may not include any subset of the password. In this example, a subset of a valid password (and optionally not the entire valid password) is required for the user's input. In an example, the client can use a warning about the fixed length issue to prompt the user. In an example, a minimum length subset may be required, and the warning can be displayed when the input characters do not include a subset of a valid password of sufficient length (e.g., meeting or exceeding the minimum length). Once the user inputs a subset of a valid password, the warning can disappear. In other examples, the warning can be shown in response to the user selecting "Submit", and the user can be prohibited from continuing until it is corrected.
[0067] Split Authenticator Function for Distributed Computing
[0068] Although the examples noted above include authenticators in user devices or remote devices, in other examples, some functions of the authenticator may be performed in the user device and other functions may be performed in the remote device. For example, the authenticator in the user device may create vectors and / or compute distance metrics and send the results to the authenticator on the remote device. In some examples, this can allow for the distribution of computing resources required for authentication by having the client device share some of the computational burden.
[0069] In some examples, encryption can be used to protect intermediate results in transit. In some examples, to prevent tampering, the results can be protected by a secure symmetric key given to a trusted application. The authenticator on the remote device can then use the corresponding key to unlock the results. By successfully unlocking the results, the authenticator on the remote device can be confident that the results were produced by a trusted application. In some examples, to further prevent tampering, the authenticator on the user device can be executed in one or more protected environments, such as a Software Guard Extensions (SGX) environment, etc.
[0070] Figure 9 FIG. 900 illustrates a user device 110 and a remote device 250 having distributed authentication functionality in accordance with some examples of the present disclosure. Figure 9 FIG. illustrates a system in which the user device 110 performs portions of an authentication process and provides intermediate computations or partial results to the remote device 250. For example, the user device 110 includes a local authenticator 920, which includes a vector creator 330 and an optional distance metric calculator 335. In these examples, submission symbols (e.g., characters) are submitted to the vector creator 330, which creates a set of vectors (e.g., those shown in Figure 3 and sends those sets to the remote device 250.
[0071] In some examples, the local authenticator 920 can include a distance metric calculator 335 that can calculate the distance between a credential (e.g., a password) and a vector and send the distance to the remote device 250. The remote device 250 includes a remote authenticator 950 that can include a match determination logic unit 340 and / or a distance metric calculator 335 (depending on whether the user device includes a distance metric calculator 335). If the user device 110 provides the vectors to the remote device, the remote device 250 can provide those vectors to the distance metric calculator 335 for calculating the distance metric. If the user device 110 provides the distance metric (e.g., the user device 110 has a distance metric calculator 335), the remote device receives those metrics and passes them to the match determination logic unit. The match determination logic unit 340 uses the distance metric to determine whether access is granted as previously described. As shown in Figure 9 the secure access-controlled resource 130 can be on the user device 110 or the remote device 250.
[0072] Length check of the submission symbol
[0073] Although the authentication system disclosed above can well prevent eavesdropping, it may also be computationally expensive. In some examples, an attacker may attempt to cause a denial-of-service (DOS) attack on the authenticator by submitting symbols of a longer length. For example, the attacker may submit an authentication attempt of 150 characters. If the password is only 10 characters long, there are many ordered combinations of length ten for the submission symbols. The large number of generated vectors may also trigger the generation of many distance measurement results. These operations may utilize a large amount of processing and memory resources of the authenticator. A sophisticated attack may have hundreds of such attack authentication attempts, which may overwhelm the authenticator and prevent the authentication of legitimate users because the authenticator may be busy servicing illegal attacks and have no time for legitimate authentication.
[0074] In some examples, to prevent this problem, the client and / or the authenticator can reject authentication requests with submission symbols (e.g., submission characters) that do not meet the length requirements. For example, submission symbols with a length higher than a length threshold can be accepted. The length threshold can be measured relative to the total length of the submission symbol (e.g., password characters and noise characters), the length of only the noise symbols, the length of only the password symbols, the ratio of the noise symbols to the password symbols, etc. In other examples, the length can be a specified length. That is, it may be required that the submission symbol, the noise symbol, and / or the credential symbol have a specified length. The rejection can be processed before creating the vector so that the rejected authentication attempts are not processed to create vectors.
[0075] The present disclosure solves the technical problem of providing secure access to computing resources using a secure password that resists keyloggers, eavesdroppers, man-in-the-middle attacks, and denial-of-service attacks. The symbols entered are restricted to a threshold to prevent overly complex calculations at the authenticator.
[0076] Figure 10 A flowchart of a method 1000 for authenticating a user using size restrictions in accordance with some examples of the present disclosure is illustrated. At operation 1010, an authenticator identifies a first set of symbols corresponding to a stored value, such as a password, other credentials, or other stored value. At operation 1020, the authenticator receives a second set of symbols to be compared with the stored value, the second set of symbols including more symbols than the first set of symbols. For example, the symbols may be input password characters.
[0077] At operation 1030, the system may determine whether the symbols meet one or more length criteria. If the symbols meet one or more length criteria, processing continues to operation 1040, otherwise authentication is denied at operation 1060. The length criteria may be a minimum length, a maximum length, or a range of minimum and maximum lengths.
[0078] In some examples, the symbols checked against the criteria at operation 1030 are submission symbols (e.g., characters entered by a user that include both credential characters and noise characters), and the criteria is that the number of submission symbols is less than a threshold - e.g., operation 1030 is to determine whether the total length of the submission symbols is less than a threshold length. Thus, if a user enters 30 characters and the threshold is 25, authentication will fail the determination at operation 1030 and access will be denied at operation 1060. In some examples, in addition to a maximum length, there may also be a required minimum total length (e.g., to ensure enough noise symbols are entered).
[0079] In another example, the symbol checked against the criterion at operation 1030 is a noise symbol, and the criterion includes a limit that the number of noise symbols is less than a threshold. That is, operation 1030 is to determine whether the number of noise symbols is less than the threshold number of noise symbols. This can be achieved by subtracting the total number of symbols in the submitted symbols from the length of the credential and comparing the result with the threshold. For example, if the length of the submitted symbols is 12 symbols and the stored credential length is 5 symbols long, then (12 - 5)=7 is compared with the threshold. If the threshold is 8 or more, the process can continue; otherwise, access is denied at operation 1060. In other examples, the number of noise symbols can be determined by removing the symbols corresponding to the credential from the submitted symbols and then comparing the count of the remaining symbols with the threshold. For example, when the credential is a password and the valid password is "pass", and the submitted symbols are the characters entered by the user and are "pass12345", the characters "p", "a", "s", "s" are removed, leaving "12345", which is five characters long. Then, five is compared with the threshold. If five does not meet or exceed the threshold, access is denied at operation 1060. As pointed out above, in some examples, a minimum number of noise symbols may also be required, such that a minimum and a maximum number of noise symbols may be required.
[0080] In other examples, the length criterion is not a threshold length, but an exact symbol count (e.g., the amount of symbols is not greater than and not less than a specified symbol). For example, it may be required that the submitted symbols have a predefined count. In other examples, it may be required that the noise symbols have a predefined count. In other examples, it may be required that the ratio of noise symbols to credential symbols is a predefined ratio. For example, when it is required that the submitted symbols are ten symbols and the credential is "pass", then the system may need to add four credential symbols (e.g., characters) and six symbols as noise symbols (e.g., characters) because the total (noise and credential symbols) must equal ten symbols. For example, if the total count of the submitted symbols does not equal the predefined count, access may be denied. In some examples, the predefined count can be global for all authentication attempts, or can be specified for each authentication attempt.
[0081] At operation 1040, the authenticator determines whether the second set of symbols includes a first subset of symbols that match the stored value. If the second set of symbols does not include the first subset of symbols that match the stored value, access is denied at operation 1060. If the second set of symbols includes the first subset of symbols that match the stored value, processing continues at operation 1045. For example, the authenticator searches the second set of symbols for stored credentials. As previously explained, this may include splitting the submitted symbols into vectors and calculating the distance between each vector and the stored credentials. The distance can be used to determine whether the second set of symbols includes a first subset that matches the stored value (e.g., the stored credentials).
[0082] At operation 1045, the authenticator may determine whether the second set of symbols includes a second subset of non-designated symbols. That is, the authenticator ensures that noise symbols have been added to the submitted symbols. In some examples, this operation may have been performed because the result of the symbols that meet the length criteria at operation 1030 can ensure a minimum number of noise symbols. If noise symbols have been added, access may be granted at operation 1050. If noise symbols have not been added, access may not be granted at operation 1060. As described herein, the authenticator may also require that the noise symbols meet criteria related to a dispersion metric, that a minimum number of noise symbols be present, etc.
[0083] Note that the authenticator does not specify where the noise characters will be placed and what the noise characters are for any authentication attempt. This protects the user by preventing eavesdropping on these locations. By requiring a maximum number of submitted symbols, external attacks on the authenticator that could result in a denial of service can be avoided.
[0084] Required insertion
[0085] As previously noted, in some examples, the system may force the user to enter noise symbols within the input symbols of the credentials. This can prevent the user from simply typing their normal credentials without the additional protection provided by the noise symbols for eavesdroppers. The addition of noise symbols (such as noise characters) can be enforced at the authenticator or at the client. For example, at the client, the client may have a local copy of the user's credentials and can compare the submitted symbols to the credentials to determine whether the submitted symbols include noise symbols interleaved with the credential symbols. When the submitted symbols do not include noise symbols, the authenticator can reject the authentication attempt.
[0086] In an example of checking for the insertion of noise symbols at the client, determining whether the input symbol includes a noise character may include: determining that a minimum number of symbols have been input (e.g., the sum of the password length and the threshold number of noise characters). In some examples, it may be sufficient to input a single noise symbol, but in other examples, a threshold amount of noise symbols may be required. In some examples, the system may combine an upper limit on the length of the submitted symbols with forced character insertion, such that the user must input a plurality of symbols that fall within a minimum and maximum number of symbols.
[0087] In some examples, to prevent the user from simply repeating the symbols of the credential (which may not be as secure as random symbols), the system may compare the credential with the submitted symbols. For example, the system may require that the noise symbols be symbols that do not exist in the credential symbols. Thus, if the credential is a password with the characters "pass", then the noise characters must be characters other than "p", "a", "s", "s". If the noise symbols include symbols from the credential, the authentication may be rejected. In some other examples, rather than making a direct comparison, some repetition of characters from the credential may be allowed, but the client may calculate a difference metric that quantifies the difference between the stored credential and the submitted symbols. A minimum difference value may be required for authentication success. If the submitted symbols do not meet these criteria, the client may enforce these criteria by refusing to pass the submitted symbols to the authenticator.
[0088] In an example where the authenticator forces the insertion of noise symbols, determining whether the submitted symbols include noise symbols may be done in a similar manner as described for the client, such as determining that a minimum number of symbols have been input (e.g., the sum of the password length and the threshold number of noise characters). In other examples, the authenticator may utilize a distance metric to quickly determine whether a noise symbol has been inserted. For example, the authenticator may require that at least one distance metric be above a threshold difference (e.g., not a perfect match). In other examples, the distance metric may be used to quickly determine whether the user has previously used the exact same submitted symbols. For example, the system may compare one or more distance metrics with one or more past distance metrics of vectors created from past authentication attempts. If there is an exact match for a past distance metric from a previous authentication attempt, the system may reject the authentication request.
[0089] Forced symbol distribution
[0090] Users may not always adhere to the goals of this system - either intentionally or unintentionally - by selecting positions for predictable and non-random noise symbols. For example, a user may add noise symbols both before, after, or both before and after - rather than randomly scatter them within a credential (e.g., a password). By doing so, they may not achieve the level of protection provided by the disclosed authentication scheme, as they may be attempting to simply enter noise before, after, and / or both before and after a legitimate credential. If the distribution of noise symbols introduced by the user within the credential is uneven, an eavesdropper may still be able to discern the user's credential by observing the symbol patterns across multiple authentication attempts.
[0091] As an example, consider the following sequence of authentication attempts, where the user credential is "pass":
[0092] 1. "1234pass567"
[0093] 2. "p343423ass"
[0094] 3. "passxyzabc"
[0095] In these examples, an eavesdropper (even a shoulder surfer) may be able to observe multiple login attempts and discern the user's credential, as the common characters between each authentication attempt can be quickly separated from the noise symbols by observation. To prevent this, the system can determine one or more metrics for determining how evenly the noise symbols are distributed within the credential (or equivalently, how evenly the credential is distributed within the noise symbols). In some examples, a metric called the spread metric can quantify how evenly a set of symbols is distributed within a second set of symbols.
[0096] The system (client or authenticator) can require that the spread metric of the positions of the noise symbols among the credential symbols be higher than a specified threshold to ensure that the noise symbols are distributed throughout the credential. In some examples, the system (client or authenticator) can also specify that the spread metric be lower than a specified threshold to ensure that a perfect distribution of the noise symbols throughout the credential is also avoided, as a perfect distribution may also be easily figured out by an eavesdropper. The system may wish to obtain a random distribution of the noise symbols among the credential symbols by requiring a spread metric within a specific range.
[0097] In some examples, the system may also store a history of calculated dispersion metrics for past authentication attempts for a specified number of logins or time range. The system may require the dispersion metric to vary over time such that authentication attempts with the same or similar (e.g., within a threshold amount) dispersion metrics of submitted symbols may be rejected. This may help promote the randomness of the distributed noise symbols. In some examples, the system may statistically analyze a user's dispersion measurements for past authentication attempts. Exemplary statistical analyses include the calculation of the standard deviation of the dispersion measurements. If the standard deviation is below a threshold, the system may adjust the target range of the dispersion measurements to move the standard deviation towards the threshold. In this way, the system monitors the distribution of noise symbols in the password symbols over time to better achieve random occurrences.
[0098] In some examples, when a user is entering their credentials, the system may calculate the dispersion metric in real time and provide an indication of whether the user is within the desired range. This may be a simple indication that the user is within an acceptable range or that the user is not within an acceptable range. If the user is not within the acceptable range, the system may provide a prompt to move into the acceptable range (e.g., "Insert more noise characters" or "Remove some noise characters").
[0099] Accordingly, the present disclosure solves the technical problem of providing secure access to access-controlled resources using secure credentials that are resistant to keyloggers, eavesdroppers, and man-in-the-middle attacks. By enforcing a good distribution of noise symbols, the system can ensure that users take advantage of the security enhancements of the present disclosure by ensuring that the credentials are not easily decipherable from the submitted symbols. For example, the system can ensure that the noise symbols occur randomly rather than following a discernible pattern.
[0100] Figure 11 A flowchart of a method 1100 for authenticating a user using a dispersion metric criterion in accordance with some examples of the present disclosure is illustrated. At operation 1110, the authenticator identifies a first set of symbols corresponding to a stored value, such as a password. At operation 1120, the authenticator receives a second set of symbols to be compared with the stored value, the second set of symbols including more symbols than the first set of symbols. For example, the symbols may be input password characters.
[0101] At operation 1130, the authenticator determines whether the second set of symbols includes a first subset of symbols that match the stored value. For example, the authenticator determines whether the second set of characters includes a stored credential (e.g., a password). If the second set of characters does not include the stored credential, access may be denied at operation 1160. If the second set of characters includes the stored credential, the process moves to operation 1140. In some examples, to determine whether the second set of characters includes the stored credential, the second set of symbols may be decomposed into a set of ordered vector combinations of size m of the second set of characters, where m is the number of symbols in the stored credential. The vectors reflect each possible ordered combination of length m of the submitted symbols. A distance metric may be calculated for each vector in the vectors, the distance metric measuring the distance between the stored credential and each vector. The determination as to whether the second set of characters includes the stored credential may be based on the distance metric and whether at least one of the distance metrics is within a threshold distance of the stored credential.
[0102] At operation 1140, the authenticator determines whether the second set of symbols includes a second subset of unspecified symbols in one or more unspecified positions within the second set of symbols. For example, the authenticator determines whether noise characters have been added to password characters. In some examples, the authenticator may ensure that additional characters are entered to protect the user from eavesdropping attacks. If no additional noise characters are added, access is denied at operation 1160. Otherwise, the process may continue at operation 1145. Note that the authenticator does not specify where the noise characters will be placed and what the noise characters are for any authentication attempt. This protects the user by preventing eavesdropping on these positions.
[0103] At operation 1145, the system may determine whether a measure of the spread of the corresponding positions of the first subset or the second subset within the second set of symbols is within a threshold range or otherwise meets one or more specified criteria. Thus, the system may (depending on the design) determine the distribution of the first subset within the second set of symbols (e.g., the distribution of password characters), or the distribution of the noise symbols within the second set of symbols.
[0104] Exemplary dispersion measurement results include calculating the maximum distance between the corresponding positions of subsequent symbols of a first subset or a second subset of symbols within the second set of the symbols. For example, if the password is "pass" and the user enters "p1a2s3s4", the dispersion measurement result will be 1. In these examples, the system may require a minimum dispersion measure - for example, the maximum distance between the corresponding positions of subsequent symbols of a second subset of symbols within the second set of the symbols is less than a threshold. In other examples, the dispersion measurement result may be the average distance between the corresponding positions of subsequent symbols of a first subset or a second subset of symbols within the second set of the symbols.
[0105] In still other examples, the dispersion measurement result may be the variance of the corresponding positions of a first subset or a second subset of symbols within the second set of the symbols. In yet some other examples, the dispersion measurement result may be the standard deviation of the corresponding positions of a first subset or a second subset of symbols within the second set of the symbols.
[0106] In some examples, the threshold range may be an upper threshold, a lower threshold, or both an upper threshold and a lower threshold. The threshold may be specified or may be derived. For example, the threshold may be derived based on the length of the credential. For example, a higher dispersion level may be required for shorter credentials (to increase security) than for longer credentials, and vice versa. In some examples, both the upper and lower limits ensure that the noise symbols are noisy - that is, they do not conform to a pattern that is easily decipherable. For example, the case where the user's password is "pass" and the user enters "p1a2s3s4" may not be as secure as the case where the user enters "p12as22s" because inserting noise symbols every other symbol in the former may be more predictable than inserting them more randomly in the latter. By requiring a dispersion higher than a minimum but not perfect dispersion, the system can require more randomness.
[0107] If the dispersion measure is not within the threshold range at operation 1145, access may be denied at operation 1160. If the dispersion measure is within the threshold range at operation 1145, access may be granted at operation 1150.
[0108] In an example, the spread of noise in a password within a set of input characters can be determined by creating a set of vectors of the input characters. The set of vectors can be generated as described herein. A distance metric from one or more vectors in the set of vectors to a vector of the password can be compared. In an example, an average, median, or total vector distance can be evaluated and compared to a threshold. When the average, median, or total distance exceeds the threshold, it can be determined that the set of input characters has sufficient spread. In another example, a subset of the set of vectors can be used (e.g., only vectors between two thresholds, a "close" threshold and a "far" threshold), and the subset may be required to have a minimum number of vectors.
[0109] In yet another example, the vector subset can be generated by taking ordered characters whose total length is equal to the order of the password. For example, the password can be "pass", and the input characters are "p#arss", which is an example of well-spread noise. In this example, the set of vectors can be constructed as "p#ar", "#ars", and "arss". None of these are particularly close in distance to something like "pass". An example of insufficient spread of the input characters would be "#rpass". In this example, the set of vectors can include "#rpa", "rpas", and "pass". These vectors are closer to the password (including the password itself), and thus it can be determined that the input characters do not have sufficient spread.
[0110] Figure 12 A diagram illustrating a data stream 1200 for authentication utilizing additional, unspecified noise symbols in accordance with some examples of the present disclosure. Figure 12 Similar to Figure 3 except that in Figure 12 the authenticator 1227 includes a spread checker 1237. The spread checker 1237 can compute a spread metric that quantifies the distribution of the noise symbols 320 of the user input within the submission symbols 325 (or the distribution of the credential symbols within the submission symbols 325). The spread checker 1237 can be included in the authenticator 327, or in the user device 110, or in the remote device 135, as shown in Figure 1 and Figure 2 The spread checker 1237 can also be part of the client 125. For example, the spread metric can be computed when the user inputs the credential and can be fed back to the user in real time to indicate whether the spread metric is within an acceptable range.
[0111] The scatter checker 1237 can calculate the scatter of noise symbols 320 (e.g., characters) entered by the user within the total submission symbol 325 or the scatter of credential symbols 312, 314, and 316 entered by the user within the total submission symbol 325. As previously noted, exemplary scatter measurement results include calculating the maximum or average distance, variance, standard deviation, etc. between cryptographic or noise characters.
[0112] The scatter checker 1237 can compare the calculated scatter to determine if the scatter measure meets a specified criterion. For example, the criterion can be whether the scatter measure is above a first threshold. In other examples, the criterion can be whether the scatter measure is below a second threshold. In still other examples, the criterion can be whether the scatter measure is both above the first threshold and below the second threshold (and thus within a desired range). If the result is that the scatter measure of the submission symbol 325 meets the criterion, the process continues with vector creation by the vector creator 330. If the scatter measure does not meet the criterion, authentication can be determined to be rejected by the match determination logic unit 340.
[0113] Prevent duplicate input
[0114] In some examples, an eavesdropper may not attempt to decrypt the password from the noise characters. Instead, the eavesdropper may utilize a replay attack, whereby the entire input sequence is captured and then "replayed", including the noise characters. To prevent this, in some examples, the system can take measures to detect and reject authentication attempts that are the same as or similar to past authentication attempts.
[0115] For example, the authenticator can store the submission symbols for multiple past authentication attempts. When a new authentication attempt is made, the newly received submission symbol is compared to the stored submission symbols for past authentication attempts. If the newly received submission symbol for the current authentication attempt matches or is within a specified threshold level of similarity to one of the stored past submission symbols for past authentication attempts (to prevent simple alterations), the system can reject the authentication attempt.
[0116] The system can store the submission symbols for multiple past authentication attempts for a specified time period (e.g., yesterday, last week, last month, etc.), a specified number of authentication attempts, etc.
[0117] In other examples, instead of storing past-submitted symbols, the system can store one or more of the distance metrics or spread measurements of past authentication attempts. For example, the system can store two or three of the most recent distance metrics for each authentication attempt. If one or more of the distance metrics and / or spread measurements of the current authentication attempt are within a threshold difference of one or more of the distance metrics and / or spread measurements of past authentication attempts, the current authentication attempt can be rejected. By storing distance metrics or spread measurements instead of submitted symbols, the system can reduce the storage amount required to prevent replay attacks.
[0118] Partial password subset
[0119] In some examples, an eavesdropper can access a user's communication through multiple authentication attempts. For example, keyloggers and man-in-the-middle attacks can observe the user through multiple authentication attempts. An attacker may be able to discern the user's password by detecting common characters across multiple authentication attempts. Even if the system enforces a pseudo-random distribution of noise symbols in the credentials, sophisticated algorithms can find patterns in the captured data.
[0120] To prevent this, the system can force the user to enter a subset of their credentials. For example, the user's password can be "password", and the user can authenticate using "pass", "sswor", "word", etc. In some systems, where the user's password is "password", other combinations such as "pawo" or "psrd" (e.g., in the same character order as in "password", but not necessarily consecutive) can be used. In some examples, the system may require the user to use a different subset of credentials for each authentication attempt. This makes it more difficult for an eavesdropper to observe the user's credentials by detecting common symbols (e.g., characters) across multiple authentication attempts. In an example, different subsets of credentials can be repeated after multiple non-uses or after a period of time (e.g., after 20 different subsets, the first-entered subset can be repeated, or after six months, a subset that has already been entered can be repeated).
[0121] The system can enforce a minimum subset length (e.g., the subset meets a minimum number of characters, a minimum percentage of the total password, etc.). The system can enforce a rule that the same subset can only be used a specified number of times within a specified number of authentication attempts (or a specified time period). For example, the same credential subset can only be used twice in ten authentication attempts. In some examples, the subset may need to consist of consecutive symbols, but in other examples, skipping symbols may be allowed. In some examples, the subset must be ordered. That is, if the user's password is "password", then the subset "pssord" is a valid subset, while "dpssor" is not.
[0122] Accordingly, the present disclosure solves the technical problem of providing secure access to an access-controlled resource using secure credentials that are resistant to keyloggers, eavesdroppers, man-in-the-middle attacks, and replay attacks. This is achieved by introducing user-specified random noise symbols introduced at user-specified random positions. The authentication device decomposes the submitted symbols into multiple vectors and uses a distance metric to determine whether authentication should be granted. By utilizing a subset of the credentials in addition to the noise symbols, the system can make it more difficult for an attacker eavesdropping on the user to determine the user's credentials.
[0123] Figure 13 A diagram illustrating a data flow 1300 for an authentication attempt using additional, unspecified noise symbols and forced credential subsets according to some examples of the present disclosure. A credential 1310 (e.g., a password) can include six symbols P1 - P6 in character form. In Figure 13 the example, the user has entered P2, P3, and P4 as subset credential symbols 1315. The user adds one or more noise symbols 320 (e.g., characters) to the subset when entering the credential. In Figure 13 the example shown, for ease of description, only one noise symbol 320 is added. The submitted symbol 1325 entered by the user includes the subset credential symbols 1315 and one or more noise symbols 320 scattered among the credential characters.
[0124] The authenticator 1327 includes a subset creator 1340 that identifies a plurality of ordered vectors, referred to as credential subset vectors, that include an ordered subset of the user's stored credentials 1350. In an example where the subset must have a minimum number of symbols, the subset creator 1340 creates credential subset vectors of a minimum size and larger sizes (up to the size of the stored credentials 1350 or a maximum subset size). For example, if the minimum size is five characters, then each of the credential subset vectors is five or more characters, and the credential subset vectors include the set of all possible subsets of the stored credentials 1350 that are five or more characters (optionally as a strict subset, e.g., not including the entire credential 1350).
[0125] The check vector creator 1330 receives the submission symbols 1325 entered by the user and creates a plurality of vectors, each having a length corresponding to the length of the credential subset vectors created by the subset creator 1340. These vectors may be referred to as "check vectors". The plurality of check vectors reflect the ordered combinations of each possible length m of the submission symbols 1325, where m is the length of a valid subset of the stored credentials. The order of the symbols in each of the check vectors is the same as the order of the credential symbols in the submission symbols 1325. As shown in Figure 13 m is a vector of lengths three, four, and five. In other examples, m may be of a different length. For example, the user may submit a credential length using the submission symbols 1325 (e.g., P2, N1, P3, P4 plus "4"). In another example, the user interface may indicate the credential length to submit (e.g., a random number greater than some minimum value but less than the total credential length, or a number assigned by a credential service such as access control 345).
[0126] Each check vector and each credential subset vector are then passed to a distance metric calculator 1335 that calculates the distance between each combination of the credential subset vectors and each of the plurality of check vectors. In other examples, the distance metric calculator 1335 calculates the distance between each combination of the same size of the credential subset vectors and each of the plurality of check vectors. In some examples, the distance metric can be the Levenshtein distance. In other examples, the distance metric can compare each symbol of each check vector with the corresponding symbol of each credential subset vector. If the symbols match, the score may not increase. If the symbols do not match, the score may increase. In other examples, a higher score reflects a better match, and thus matching symbols may increase the score, and non-matching symbols may leave the score unchanged or may decrease the score. In other examples, the distance metric can be a correlation, such as the Pearson correlation coefficient.
[0127] The distance metric is then passed to a match determination logic unit 340. In some examples, the match determination logic unit 340 identifies the distance metric (e.g., the minimum distance) representing the closest match between a check vector and one of the credential subset vectors. This may be the highest score (in the case of assigning points for a match) or may be the lowest score, depending on the desired implementation. If the distance metric representing the closest match is closer to one of the credential subset vectors than a threshold (e.g., the distance is less than the threshold), the match determination logic unit 340 can return that a match has been found. In other examples, the match determination logic unit identifies the two distance metrics (e.g., the minimum distance and the next minimum distance) representing the two closest matches to the credential subset vector. The match determination logic unit 340 can then take the ratio of the two distance metrics and compare it to a threshold to determine if there is a match.
[0128] Access control 345 can then grant or deny access to a securely access-controlled resource based on the result from the match determination logic unit 340. For example, access control 345 can send a message to the computer device hosting the securely access-controlled resource to provide the result of the authentication attempt. In some examples, access control 345 can send a token to a user device or the device hosting the securely access-controlled resource. In other examples, access control 345 can provide the securely access-controlled resource. In some examples, the access control can send a signal to a physical device that can provide access to a physical resource (e.g., unlock a door).
[0129] In some examples, the check vector creator 1330 may verify that the submission symbol 1325 includes a subset, but not all, of the storage credentials 1350. For example, the check vector creator 1330 may determine a count of the number of symbols in the submission symbol that match, in order, symbols from the credential. In some examples, the check vector creator 1330 may ensure that this is within an acceptable range. For example, the check vector creator 1330 may compare this number of symbols to a minimum threshold (to ensure a minimum subset size) and a maximum threshold (to ensure the subset is not too close to the entire password). If the number of symbols is within the range, the check vector creator 1330 may determine that authentication is to proceed. If the number of symbols is not within the range, the check vector creator 1330 may cause the authentication to be rejected.
[0130] In some examples, the presence of a subset (rather than the entire credential) may be determined by verifying that a check vector having a closest distance metric to any credential subset vector is within a desired distance range. The range may enforce a minimum proximity and a maximum proximity. This ensures that the subset is complete enough to constitute authentication, but not the entire (or nearly entire) credential.
[0131] In another example, a ratio of the distance of the vector with the closest distance to the distance of the vector with the next closest distance may be compared to a minimum threshold. In this example, the system may also enforce a maximum threshold on the distance of the vector with the closest distance. In this example, a hybrid threshold is used to enforce a minimum and a maximum, where the minimum threshold is for the ratio and the maximum threshold is for the distance itself.
[0132] The check vector creator 1330 may verify that the subset meets a minimum length. For example, the minimum length may be a specified length or may be calculated based on the length of the storage credential 1350. For example, the shorter the credential length, the shorter the minimum subset length may be. In some examples, the minimum subset length may increase as the credential length increases until a defined maximum value, at which point a longer credential length does not increase the minimum subset length.
[0133] In some examples, the check vector creator 1330 may enforce a repeated input limit such that the credential subsets entered are compared across authentication attempts to determine if a user is frequently exploiting the same subset (e.g., occurring more than a threshold). If the user's use of a particular subset violates the threshold incidence rate, the authenticator 1327 may reject the authentication attempt. In some examples, the incidence rate may be defined as the number of uses or specified login attempts within a specified amount of time (e.g., the past day, week, month).
[0134] In some examples, the threshold frequency can be based on the length of the stored credential 1350. For example, depending on the length of the stored credential 1350, there may only be x valid subsets of a minimum length l. In some examples, the threshold frequency can be set based on x, such as x divided by 2, or x, or x - a configurable or specified margin.
[0135] In some examples, in addition to enforcing the requirements for different subsets, the check vector creator 1330 can enforce that the noise symbols 320 can be different across multiple authentication attempts or be scattered at different positions in the input credential 1310.
[0136] Figure 14 FIG. shows a flowchart of a method 1400 for authenticating a user using a subset of a credential according to some examples of the present disclosure. At operation 1410, the authenticator identifies a first set of symbols corresponding to a stored value, such as a credential. At operation 1420, the authenticator receives a second set of symbols to be compared with the stored value, the second set of symbols including more symbols than the first set of symbols. For example, the symbols can be input password characters.
[0137] At operation 1425, the authenticator can determine whether any subset of the second set of symbols matches the symbols of the stored value. For example, the authenticator can determine a plurality of ordered vectors (referred to as credential subset vectors) including ordered subsets of the user's stored credential of all possible lengths greater than a minimum subset length. For example, if the stored credential is "password" and the minimum subset length is three (in some examples, skipping symbols is not allowed, but other examples can allow skipping, such as "pwd" in this example), then the credential subset vectors will be all possible ordered subsets of three, four, five, six, seven, and eight characters. In some examples, a maximum subset size can also be specified. In these examples, the credential subset vectors can be limited to the maximum size to enforce that the input credential is a subset (rather than the entire credential). The maximum size can be specified (e.g., by an administrator) or can be calculated based on the size of the credential. In the above example where the credential is "password", if the maximum subset size is limited to six, then the credential subset vectors will be all possible ordered subsets of three, four, five, and six symbols (the following examples show skipping prohibited for ease of reading):
[0138] 3: pas; ass; ssw; swo; word; ord;
[0139] 4: pass; assw; sswo; swor; word;
[0140] 5: passw; asswo; sswor; sword;
[0141] 6: passwo; asswor; ssword;
[0142] The authenticator then creates a plurality of vectors (check vectors) based on the second set of symbols, each vector having a length corresponding to the length of the corresponding subset of credential vectors. Each check vector reflects every possible ordered combination of the second set of symbols having a length corresponding to the length of the corresponding subset of credential vectors. For example, if there are four sets of subset credential vectors having lengths of 3, 4, 5, and 6 symbols respectively, a first plurality of check vectors are created having all possible ordered combinations of three symbols in length from the second set of symbols; a second plurality of check vectors are created having all possible ordered combinations of four symbols in length from the second set of symbols; a third plurality of check vectors are created having all possible ordered combinations of five symbols in length from the second set of symbols; and a fourth plurality of check vectors are created having all possible ordered combinations of six symbols in length from the second set of symbols. Ordered means that the order of the characters in each check vector of the plurality of check vectors is the same as the order of the symbols in the second set of symbols.
[0143] In some examples, a distance is computed between each subset of credential vectors having a particular length and each check vector of the plurality of check vectors having the same particular length. The distance quantifies the difference between each check vector and each subset of credential vectors. In other examples, a distance is computed between each combination of subset credential vectors (regardless of size) and each check vector of the plurality of check vectors.
[0144] The authenticator then determines whether the second set of symbols includes a first subset of symbols that matches a portion of the stored value. For example, the authenticator determines whether the second set of symbols includes a subset of a stored credential (e.g., a password). In some examples, to determine whether the second set of symbols includes a first subset that matches a portion of the stored value, the system may utilize the distance metric and whether at least one of the distance metrics is within a threshold distance of the subset of credential vectors. If the second set of characters does not include a subset of the stored credential, access may be denied at operation 1460. If the second set of characters includes a subset of the stored credential, the process moves to operation 1440.
[0145] At operation 1440, the authenticator determines whether the second set of symbols includes a second subset of non-designated symbols at one or more non-designated positions within the second set of symbols. For example, the authenticator determines whether noise symbols have been added to the credential. In some examples, the authenticator may ensure that additional characters are entered to protect the user from eavesdropping attacks. If no additional noise symbols are added, access is denied at operation 1460. Otherwise, access may be granted at operation 1450. Note that the authenticator does not specify where the noise characters will be placed and what the noise characters are for any authentication attempt. This protects the user by preventing eavesdropping on these positions.
[0146] Figure 15 FIG. illustrates a flowchart of a method 1500 for authenticating a user using a subset of a credential in accordance with some examples of the present disclosure. At operation 1510, the authenticator may receive a set of symbols (e.g., submission symbols) as part of an authentication request (e.g., an access request). At operation 1520, the authenticator determines that no subset of the submission symbol set exactly matches a stored value (e.g., a credential such as a password). This ensures that the entered credential is a subset, rather than the entire credential. If a subset of the received symbol set exactly matches the stored value, authentication may fail in some examples.
[0147] At operation 1530, the authenticator may identify an ordered vector (e.g., a credential subset vector) that includes an ordered subset of the stored value having a length less than the length of the stored value. At operation 1540, the authenticator creates a plurality of check vectors having lengths corresponding to the length of the credential subset vector. At operation 1550, the authenticator may determine a set of distances between the plurality of check vectors and the credential subset vector. As noted, in some examples, the set of distances includes the distance between each combination of a check vector and the credential subset vector, but in other examples, the set of distances includes only the distance between each combination of a check vector and a credential subset vector of the same size (e.g., a check vector of size z and a credential subset vector of size z).
[0148] At operation 1560, the authenticator may select the check vector corresponding to the minimum distance. At operation 1570, based on a comparison of the value corresponding to the selected vector with a threshold, the authenticator may cause access to a secure access-controlled resource to be granted. For example, the minimum distance value corresponding to the selected vector and the threshold. In other examples, the ratio of the minimum distance corresponding to the selected vector and the next smallest distance corresponding to the selected vector or a second check vector may be compared with the threshold.
[0149] Figure 16The figure illustrates a flowchart of method 1600 for authentication attempts using a subset according to some examples of the present disclosure. At operation 1610, the client can cause a GUI to be displayed. For example, the GUI as shown in Figure 7 . The GUI can have one or more data input fields for a user to input one or more symbols of one or more credentials. For example, the GUI can include an input field for accepting characters of the requested authentication credentials from an input device. In some examples, the GUI accepts the requested authentication credentials in the form of a set of symbols (e.g., characters). Exemplary input devices can include a keyboard, a screen keyboard, mouse input, touch input, biometric input, etc. In some examples, the GUI may require that the set of symbols (e.g., characters) includes more symbols (e.g., characters) than the stored credentials. For example, by checking the length of the characters entered by the user and checking the length relative to the length of the stored password. In some examples, the GUI may require that the set of characters includes a threshold number of symbols more than the stored credentials. The threshold can be pre-specified or can be determined based on the length of the credentials. For example, if the credential (e.g., password) is short, the system may require more noise symbols than when the credential is long. In other examples, the system can compare the values of the input submitted symbols with the symbol values of the credentials to determine if noise symbols have been added.
[0150] In some examples, the client can perform a check to ensure that noise symbols (e.g., characters) are scattered within the submitted credentials. For example, if the noise symbols are at the beginning, end, or both the beginning and end, but are not scattered within the submitted symbols, the client may display an error. For example, if the scatter measurement of the noise symbols among the entire credential symbols is below a threshold, the client can show an error and prompt the user to fix the submitted symbols such that the scatter measurement is above or equal to the threshold. The scatter measurement is described in more detail below.
[0151] In some examples, the client can verify that the submitted symbols do not exactly match the stored credentials, but include a subset. For example, the client can compare the input symbols with the stored credentials to ensure that the user has entered a subset of a minimum length and / or a maximum length. If the submitted symbols do not include a subset of the credentials, the GUI can display an error and prompt the user to fix the submitted symbols such that the submitted symbols include a subset of the stored credentials.
[0152] If any of the above checks indicates that the user's submitted symbol (e.g., character) does not meet one or more of the above requirements, the client can display an error and request that the user correct the submitted symbol. Once the user submits the symbol by specifying an input completion (e.g., pressing ENTER, clicking, or tapping a button indicating input completion) for the symbol (e.g., character) input, an error can be displayed. In other examples, the system can monitor the symbols being input as the user enters them. For example, after a predetermined number of symbols (e.g., the length of the storage credential), the system can check the symbols for length, noisy symbols, and / or dispersion measurements depending on the implementation. An exemplary warning to the user is shown in FIG. 8.
[0153] At operation 1620, the client can accept symbols (e.g., characters) entered by the user in one or more data input fields of the GUI, where the set of symbols includes more characters than the storage credential and includes a subset of the set of characters that do not exactly match the storage credential. For example, after the user has submitted an input indicating that the set of symbols is complete and the set of characters meets the requirements (e.g., the length is greater than the credential, the submitted symbols include noisy characters, the noise is scattered, and / or the noise is scattered and the dispersion measurement is above a threshold). In an example, the requirement may not require the length of the set of characters to be greater than the credential. For example, when the password is "password", a noisy subset entered by the user can be "p1a2s3s", which has fewer characters than "password", but may still be secure enough.
[0154] At operation 1630, the client can receive or identify an indication of whether access is granted. In some examples, the client can send the submitted symbol to a remote authenticator in a remote computing device, such as shown in Figure 2 The client can then receive an indication from the remote device as to whether access is granted. In other examples, the client itself can include an authenticator and can perform authentication as shown in Figure 1 In these examples, the indication can be an indication of whether access is granted received from the authenticator via a function return, interprocess communication, etc.
[0155] At operation 1632, the system can determine whether the indication grants or denies access. If access is denied, at operation 1645, the GUI can be made to display a message indicating that access is denied. In some examples, the user can retry the authentication. In some examples, a limit on the number of retry attempts can be implemented to prevent the user from retrying the authentication after a determined number of authentication failures within a determined amount of time.
[0156] If access is granted at operation 1632, then at operation 1635, the system may indicate that access has been granted. For example, the system may cause a GUI to display an indication that access has been granted. In other examples, the system may simply remove the login screen and expose access to the access-controlled resource. In other examples, the system may provide the requested access-controlled resource. At operation 1640, in some examples, the client may facilitate access to the requested secure access-controlled resource, such as by redirecting the user's browser to the address for the resource, performing a function that provides the resource, and the like.
[0157] In some examples, the various features described above may be implemented individually or in combination. For example, the system may require noisy characters, enforce a maximum total number of characters, require a subset, require a distribution of noisy characters within a dispersion measurement result, and require non-repetitive submission of symbol 1325. In other examples, only specific features may be implemented, while other features are not implemented. In still other examples, the implemented features and requirements may be configured by an end user, an administrator, and the like. The foregoing disclosure has focused on authenticating user credentials for a user in an authentication technique. However, as noted, the credentials are merely a stored value that can be compared. This technique can generally be used to verify a received value as a stored value. Additionally, in the various flowcharts, the order of operations is exemplary. For example, in Figure 10 operation 1030, 1040, and 1045 may be performed in any order depending on the implementation. This is merely an example, as other flowcharts may be reordered according to the desired implementation.
[0158] Figure 17 FIG. illustrates a block diagram of an exemplary machine 1700 in accordance with some examples of the present disclosure, which may implement one or more of the techniques (e.g., methods) discussed herein. In alternative embodiments, machine 1700 may operate as a stand-alone device or may be connected (e.g., networked) to other machines. In a networked deployment, machine 1700 may operate in a server-client network environment as a server machine, a client machine, or both capabilities. Machine 1700 may implement user device 110, remote device 135, second remote device 255, etc. For example, machine 1700 may be configured to include Figure 3 、 9 any one or more of the components of 12 and 13. Machine 1700 may be configured to execute Figures 4 - 6 、10、11, and 14 - 16 methods. Machine 1700 may be configured to provide Figure 7and the GUI of FIG. 8. In an example, machine 1700 can act as a peer machine in a peer-to-peer (P2P) (or other distributed) network environment. Machine 1700 can be a user device, a remote device, a second remote device, or can take the form of a personal computer (PC), tablet PC, set-top box (STB), personal digital assistant (PDA), mobile phone, smartphone, network device, network router, switch, or bridge, or any machine capable of executing instructions (sequentially or otherwise) that specify actions to be taken by the machine. Further, although only a single machine is illustrated, the term "machine" shall also be taken to include any collection of machines that individually or jointly execute a set of instructions (or multiple sets of instructions) to perform any one or more of the methods discussed herein, such as cloud computing, software as a service (SaaS), other computer cluster configurations.
[0159] As described herein, an example can include a logical unit or multiple components, modules, or mechanisms (hereinafter referred to as "modules"), or can operate thereon. A module is a tangible entity (e.g., hardware) capable of performing specified operations and can be configured or arranged in a particular manner. In an example, a circuit can be arranged (e.g., internally or relative to external entities such as other circuits) in a specified manner as a module. In an example, all or part of one or more computer systems (e.g., stand-alone, client, or server computer systems) or one or more hardware processors can be configured by firmware or software (e.g., instructions, an application portion, or an application) to operate as a module for performing specified operations. In an example, the software can reside on a machine-readable medium. In an example, when executed by the underlying hardware of the module, the software causes the hardware to perform the specified operations.
[0160] Accordingly, the term "module" is understood to encompass a tangible entity that is physically constructed, specifically configured (e.g., hardwired) or temporarily (e.g., transiently) configured (e.g., programmed) to operate in a specified manner or to perform any of the operations described herein. Considering examples where modules are configured transiently, not every module within the module needs to be instantiated at any given time. For example, in the case where a module includes a general hardware processor configured by software, the general hardware processor can be configured as respective different modules at different times. The software can accordingly configure the hardware processor, e.g., to constitute a particular module at one time instance and a different module at a different time instance.
[0161] A machine (e.g., a computer system) 1700 can include a hardware processor 1702 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a hardware processor core, or any combination thereof), a main memory 1704, and a static memory 1706, some or all of which can communicate with each other via an interconnect (e.g., a bus) 1708. The machine 1700 can also include a display unit 1710, an alphanumeric input device 1712 (e.g., a keyboard), and a user interface (UI) navigation device 1714 (e.g., a mouse). In an example, the display unit 1710, the input device 1712, and the UI navigation device 1714 can be a touch screen display. The machine 1700 can additionally include a storage device (e.g., a drive unit) 1716, a signal generation device 1718 (e.g., a speaker), a network interface device 1720, and one or more sensors 1721, such as a global positioning system (GPS) sensor, a compass, an accelerometer, or other sensors. The machine 1700 can include an output controller 1728, such as a serial (e.g., universal serial bus (USB)), parallel, or other wired or wireless (e.g., infrared (IR), near field communication (NFC), etc.) connection to communicate with or control one or more peripheral devices (e.g., a printer, a card reader, etc.).
[0162] The storage device 1716 can include a machine-readable medium 1722, on which is stored one or more collections of data structures or instructions 1724 (e.g., software) that embody or are utilized in any one or more of the techniques or functions described herein. The instructions 1724 can also reside, completely or at least partially, within the main memory 1704, within the static memory 1706, or within the hardware processor 1702 during execution by the machine 1700. In an example, one or any combination of the hardware processor 1702, the main memory 1704, the static memory 1706, or the storage device 1716 can constitute a machine-readable medium.
[0163] Although the machine-readable medium 1722 is illustrated as a single medium, the term "machine-readable medium" can include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) configured to store one or more instructions 1724.
[0164] The term "machine-readable medium" can include any medium that can store, encode, or carry instructions executable by machine 1700 and cause machine 1700 to perform any one or more of the techniques in the present disclosure, or any medium that can store, encode, or carry data structures used by or associated with such instructions. Non-limiting examples of machine-readable media can include solid-state memory and optical and magnetic media. Specific examples of machine-readable media can include: non-volatile memory such as semiconductor memory devices (e.g., electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM)) and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; random access memory (RAM); solid-state drives (SSD); and CD-ROM and DVD-ROM disks. In some examples, the machine-readable medium can be a non-transitory machine-readable medium. In some examples, the machine-readable medium can include a machine-readable medium that is not an instantaneous propagated signal.
[0165] Instruction 1724 can also be sent or received via a network interface device 1720 over a communication network 1726 using a transmission medium. Machine 1700 can communicate with one or more other machines using any one of a variety of transmission protocols (e.g., Frame Relay, Internet Protocol (IP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc.). Exemplary communication networks can include: local area networks (LANs), wide area networks (WANs), packet data networks (e.g., the Internet), mobile telephone networks (e.g., cellular networks), plain old telephone (POTS) networks, and wireless data networks (e.g., the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard series, referred to as the IEEE 802.16 standard series, referred to as ), the IEEE 802.15.4 standard series, the Long Term Evolution (LTE) standard series, the Universal Mobile Telecommunications System (UMTS) standard series, peer-to-peer (P2P) networks, etc. In an example, network interface device 1720 can include one or more physical jacks (e.g., Ethernet, coaxial, or telephone jacks) or one or more antennas to connect to communication network 1726. In an example, network interface device 1720 can include multiple antennas to perform wireless communication using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques. In some examples, network interface device 1720 can perform wireless communication using multi-user MIMO techniques.
[0166] Non-limiting examples
[0167] Example 1 is a method for authentication, the method comprising: using one or more hardware processors: identifying a first set of characters corresponding to a stored password; receiving, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; and causing access to a controlled resource to be granted based on determining that the second set of characters includes: a first subset of characters that matches and has the same order as the first set of characters corresponding to the stored password, and a second subset of characters that is not specified for the authentication attempt and is interleaved with the first subset of characters in an order not specified for the authentication attempt.
[0168] In Example 2, the subject matter of Example 1 includes: wherein determining that the second set of characters includes a first subset of characters that matches and has the same order as the first set of characters corresponding to the stored password includes: determining a match between a portion of the second set of characters and the first set of characters based on a distance function and a maximum distance threshold.
[0169] In Example 3, the subject matter of Examples 1-2 includes: wherein the second set of characters is received via a network.
[0170] In Example 4, the subject matter of Examples 1-3 includes: wherein the second set of characters is received from an input device communicatively coupled to the one or more hardware processors.
[0171] In Example 5, the subject matter of Examples 1-4 includes: wherein causing access to the controlled resource to be granted includes: sending an indication that access is granted to a computing device controlling the controlled resource.
[0172] In Example 6, the subject matter of Examples 1-5 includes: wherein determining that the second set of characters includes the first subset of characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
[0173] In Example 7, the subject matter of Example 6 includes: wherein matching the plurality of vectors including permutations of the received second set of characters against the first set of characters includes: comparing a distance derived from a distance function to a threshold.
[0174] In Example 8, the subject matter of Examples 1-7 includes: wherein the first set of characters is retrieved from a hardware storage device.
[0175] In Example 9, the subject matter of Examples 1 - 8 includes storing information about a second set of the characters; receiving a third set of characters entered during a second authentication attempt; and denying access to the access - controlled resource based on determining that the third set of characters is within a threshold similarity of the second set of characters.
[0176] Example 10 is a device for authentication, the device including: one or more hardware processors; a memory storing instructions that, when executed, cause the one or more hardware processors to perform operations including: identifying a first set of characters corresponding to a stored password; receiving, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; and granting access to an access - controlled resource based on determining that the second set of characters includes: a first subset of characters that match and are in the same order as the first set of characters corresponding to the stored password, and a second subset of characters that are not specified for the authentication attempt and are interleaved with the first subset of characters in an order not specified for the authentication attempt.
[0177] In Example 11, the subject matter of Example 10 includes: wherein the operation of determining that the second set of characters includes a first subset of characters that match and are in the same order as the first set of characters corresponding to the stored password includes: determining a match between a portion of the second set of characters and the first set based on a distance function and a maximum distance threshold.
[0178] In Example 12, the subject matter of Examples 10 - 11 includes: wherein the second set of characters is received via a network.
[0179] In Example 13, the subject matter of Examples 10 - 12 includes: wherein the second set of characters is received from an input device communicatively coupled to the one or more hardware processors.
[0180] In Example 14, the subject matter of Examples 10 - 13 includes: wherein the operation of granting access to the access - controlled resource includes: sending an indication that access is granted to a computing device controlling the access - controlled resource.
[0181] In Example 15, the subject matter of Examples 10 - 14 includes: wherein the operation of determining that the second set of characters includes the first subset of characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
[0182] In Example 16, the subject matter of Example 15 includes: wherein, the operation of matching the plurality of vectors including the permutation of the second set of received characters to the first set of characters includes: comparing a distance derived from a distance function to a threshold value.
[0183] In Example 17, the subject matter of Examples 10 - 16 includes: wherein, the first set of characters is retrieved from a hardware storage device.
[0184] In Example 18, the subject matter of Examples 10 - 17 includes: wherein, the operation further includes: storing information about the second set of characters; receiving a third set of characters input during a second authentication attempt; and denying access to the access - controlled resource based on determining that the third set of characters is within a threshold similarity of the second set of characters.
[0185] Example 19 is a method for authenticating a password relative to a stored password, the method including: using one or more hardware processors: identifying a first set of characters corresponding to the stored password; receiving, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; granting access to an access - controlled resource based on determining that: the second set of characters includes a first subset of characters that match and are in the same order as the first set of characters corresponding to the stored password, and a second subset of characters that are not specified for the authentication attempt and are interleaved with the first subset of characters in an order not specified for the authentication attempt, and the second set of characters includes a first pre - determined count of characters or the second subset of characters includes a second pre - determined count of characters.
[0186] In Example 20, the subject matter of Example 19 includes: storing information about the second set of characters; receiving a third set of characters to be authenticated during a second authentication attempt; and denying access to the access - controlled resource based on determining that the third set of characters is within a threshold similarity of the second set of characters.
[0187] In Example 21, the subject matter of Examples 19 - 20 includes: receiving a third set of characters to be authenticated during a second authentication attempt; and granting access to the access - controlled resource based on determining that: the third set of characters includes a third subset of characters that matches and has the same order as the first set of characters corresponding to the stored password, and a fourth subset of characters that is not specified for the second authentication attempt and is interleaved with the third subset of characters in an order not specified for the second authentication attempt, and the third set of characters includes a first pre - determined count of characters or the fourth subset of characters includes a second pre - determined count of characters.
[0188] In Example 22, the subject matter of Examples 19 - 21 includes: wherein determining that the second set of characters includes the first subset of characters that matches and has the same order as the first set of characters corresponding to the stored password includes: determining a match between a portion of the second set of characters and the first set of characters based on a distance function and a maximum distance threshold.
[0189] In Example 23, the subject matter of Examples 19 - 22 includes: wherein the second set of characters is received via a network.
[0190] In Example 24, the subject matter of Examples 19 - 23 includes: wherein the second set of characters is received from an input device communicatively coupled to the one or more hardware processors.
[0191] In Example 25, the subject matter of Examples 19 - 24 includes: wherein granting access to the access - controlled resource includes: sending an indication that access is granted to the computing device in which the access - controlled resource is at least partially located.
[0192] In Example 26, the subject matter of Examples 19 - 25 includes: wherein determining that the second set of characters includes the first subset of characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
[0193] In Example 27, the subject matter of Example 26 includes: wherein matching the plurality of vectors including permutations of the received second set of characters against the first set of characters includes: comparing a distance derived from a distance function with a threshold.
[0194] In Example 28, the subject matter of Examples 19 - 27 includes, if the second set of characters does not include the first pre - determined count of characters, denying access.
[0195] Example 29 is a device for authentication, the device comprising: one or more hardware processors; a memory storing instructions which, when executed, cause the one or more hardware processors to perform operations including: identifying a first set of characters corresponding to a stored password; receiving, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; causing access to a controlled resource to be granted based on determining that: the second set of characters includes a first subset of characters that match and are in the same order as the first set of characters corresponding to the stored password, and a second subset of characters that are not specified for the authentication attempt and are interleaved with the first subset of characters in an order not specified for the authentication attempt, and the second set of characters includes a first pre - counted number of characters or the second subset of characters includes a second pre - counted number of characters.
[0196] In Example 30, the subject matter of Example 29 includes: wherein the operations further include: storing information about the second set of characters; receiving, during a second authentication attempt, a third set of characters to be authenticated; and causing access to the controlled resource to be denied based on determining that the third set of characters is within a threshold similarity of the second set of characters.
[0197] In Example 31, the subject matter of Examples 29 - 30 includes: wherein the operations further include: receiving, during a second authentication attempt, a third set of characters to be authenticated; and causing access to the controlled resource to be granted based on the determination that: the third set of characters includes a third subset of characters that match and are in the same order as the first set of characters corresponding to the stored password, and a fourth subset of characters that are not specified for the second authentication attempt and are interleaved with the third subset of characters in an order not specified for the second authentication attempt, and the third set of characters includes a first pre - counted number of characters or the fourth subset of characters includes a second pre - counted number of characters.
[0198] In Example 32, the subject matter of Examples 29 - 31 includes: wherein the operation of determining that the second set of characters includes a first subset of characters that match and are in the same order as the first set of characters corresponding to the stored password includes: determining a match between a portion of the second set of characters and the first set of characters based on a distance function and a maximum distance threshold.
[0199] In Example 33, the subject matter of Examples 29 - 32 includes: wherein the second set of characters is received via a network.
[0200] In Example 34, the subject matter of Examples 29 - 33 includes: wherein the second set of characters is received from an input device communicatively coupled to the one or more hardware processors.
[0201] In Example 35, the subject matter of Examples 29 - 34 includes: wherein the operation that causes access to an access - controlled resource to be granted includes: sending an indication that access is granted to a computing device in which the access - controlled resource is at least partially located.
[0202] In Example 36, the subject matter of Examples 29 - 35 includes: wherein the operation of determining that the second set of characters includes a first subset of the characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
[0203] In Example 37, the subject matter of Example 36 includes: wherein the operation of matching the plurality of vectors including permutations of the received second set of characters against the first set of characters includes: comparing a distance derived from a distance function with a threshold.
[0204] In Example 38, the subject matter of Examples 29 - 37 includes: wherein the operation that causes access to the access - controlled resource to be granted includes: denying access if the second set of characters does not include the first pre - determined number of characters.
[0205] Example 39 is a method for authenticating a received set of symbols relative to a stored value during an authentication attempt, the method comprising: using one or more hardware processors: receiving, during the authentication attempt, the set of symbols to be authenticated, wherein the received set of symbols includes more symbols than a first set of symbols corresponding to the stored value; creating a set of two or more vectors, each vector having a length corresponding to the length of an ordered vector including the first set of symbols corresponding to the stored value, and each vector including a different ordered combination of the received set of symbols, the different ordered combinations of the received set of symbols being ordered in the same order as the symbols were received; determining a set of distances between each respective vector and the ordered vector including the first set of symbols corresponding to the stored value; selecting the vector in the set of vectors corresponding to the minimum distance in the set of distances; and causing access to an access - controlled resource to be granted based on a comparison of a value corresponding to the selected vector with a threshold.
[0206] In Example 40, the subject matter of Example 39 includes: wherein causing access to the access - controlled resource to be granted based on the comparison of the value corresponding to the selected vector with the threshold includes: determining that the minimum distance is less than the threshold.
[0207] In Example 41, the subject matter of Examples 39 - 40 includes selecting a second vector in the set of vectors corresponding to the second smallest distance in the set of distances, the second vector being different from the selected vector corresponding to the smallest distance; and wherein enabling access to the access - controlled resource based on the comparison of the value corresponding to the selected vector corresponding to the smallest distance with the threshold includes: determining that a value calculated based on the smallest distance and the second smallest distance corresponding to the respective selected vectors corresponding to the smallest distance and the second vector is less than the threshold.
[0208] In Example 42, the subject matter of Example 41 includes: wherein the value is one of the following: the ratio of the smallest distance to the second smallest distance, or the difference between the smallest distance and the second smallest distance.
[0209] In Example 43, the subject matter of Examples 39 - 42 includes: wherein determining the set of distances between each respective vector and the ordered vector including the stored value includes: determining the correlation between the respective vector and the ordered vector.
[0210] In Example 44, the subject matter of Examples 39 - 43 includes: wherein determining the set of distances between each respective vector and the ordered vector including the stored value includes: determining the Hamming distance between each respective vector and the ordered vector.
[0211] In Example 45, the subject matter of Examples 39 - 44 includes receiving a second set of symbols as part of a second authentication attempt; determining the length of the received second set of symbols; determining that the length of the received second set of symbols exceeds a threshold length; and in response to determining that the length of the received second set of symbols exceeds the threshold length, denying access to the access - controlled resource.
[0212] In Example 46, the subject matter of Examples 39 - 45 includes receiving a second set of symbols as part of a second authentication attempt; identifying a distance metric that quantifies the difference between the first set of symbols and the second set of symbols; determining that the distance metric is below a determined threshold; and based on determining that the distance metric is below the determined threshold, denying access to the access - controlled resource.
[0213] Example 47 is a device for authenticating a received set of symbols relative to a stored value during an authentication attempt, the device comprising: one or more hardware processors; a memory including instructions that, when executed by the one or more hardware processors, cause the device to perform operations including: receiving, during the authentication attempt, the set of symbols to be authenticated, wherein the received set of symbols includes more symbols than a first set of symbols corresponding to the stored value; creating a set of two or more vectors, each vector having a length corresponding to the length of an ordered vector including the first set of symbols corresponding to the stored value, each vector including a different ordered combination of the received set of symbols, the different ordered combinations of the received set of symbols being ordered in the same order as the symbols were received; determining a set of distances between each respective vector and the ordered vector including the first set of symbols corresponding to the stored value; selecting the vector in the set of vectors corresponding to the smallest distance in the set of distances; and based on a comparison of a value corresponding to the selected vector with a threshold, causing access to a controlled resource to be granted.
[0214] In example 48, the subject matter of example 47 includes: wherein the operation of causing access to the controlled resource to be granted based on the comparison of the value corresponding to the selected vector with the threshold includes: determining that the smallest distance is less than the threshold.
[0215] In example 49, the subject matter of examples 47-48 includes: wherein the operations further include: selecting a second vector in the set of vectors corresponding to the second smallest distance in the set of distances, the second vector being different from the selected vector corresponding to the smallest distance; and wherein causing access to the controlled resource to be granted based on the comparison of the value corresponding to the selected vector corresponding to the smallest distance with the threshold includes: determining that a value calculated based on the smallest distance and the second smallest distance corresponding to the respective selected vectors corresponding to the smallest distance and the second vector is less than the threshold.
[0216] In example 50, the subject matter of example 49 includes: wherein the value is one of: a ratio of the smallest distance to the second smallest distance, or a difference between the smallest distance and the second smallest distance.
[0217] In example 51, the subject matter of examples 47-50 includes: wherein the operation of determining the set of distances between each respective vector and the ordered vector including the stored value includes: determining a correlation between the respective vector and the ordered vector.
[0218] In Example 52, the subject matter of Examples 47-51 includes: wherein the operation of determining the set of distances between each respective vector and the ordered vector including the stored value includes: determining the Hamming distance between each respective vector and the ordered vector.
[0219] In Example 53, the subject matter of Examples 47-52 includes: wherein the operation further includes: receiving a second set of symbols as part of a second authentication attempt; determining the length of the received second set of symbols; determining that the length of the received second set of symbols exceeds a threshold length; and in response to determining that the length of the received second set of symbols exceeds the threshold length, denying access to the access-controlled resource.
[0220] In Example 54, the subject matter of Examples 47-53 includes: wherein the operation further includes: receiving a second set of symbols as part of a second authentication attempt; identifying a distance metric that quantifies the difference between the first set of symbols and the second set of symbols; determining that the distance metric is below a determined threshold; and based on determining that the distance metric is below the determined threshold, denying access to the access-controlled resource.
[0221] Example 55 is a method for authenticating access to an access-controlled resource, the method comprising: using one or more hardware processors: causing a graphical user interface (GUI) to be displayed to request authentication credentials for an authentication attempt, the GUI including an input field for accepting the required authentication credentials in the form of a set of characters from an input device, the GUI requiring that the set of characters include more characters than the stored credentials; accepting the set of characters from the input field after receiving input for the GUI indicating completion of the set of characters, the set of characters including more characters than the stored credentials; receiving an indication that the accepted set of characters includes a first subset of characters that match and are in the same order as the stored credentials, and a second subset of characters that are not specified for the authentication attempt and are interleaved with the first subset of characters in an order not specified for the authentication attempt; and in response to receiving the indication, allowing access to the access-controlled resource.
[0222] In Example 56, the subject matter of Example 55 includes: wherein the input for the GUI indicating completion of the set of characters includes pressing the enter key or an input pointing to a submit button.
[0223] In Example 57, the subject matter of Examples 55-56 includes: wherein the authentication credentials are a password.
[0224] In Example 58, the subject matter of Examples 55 - 57 includes: wherein, when the character set does not include more characters than the number of characters in the stored credential, the GUI displays a visual indicator.
[0225] In Example 59, the subject matter of Examples 55 - 58 includes: wherein, when the character set does not include a noise character set, the GUI displays a visual indicator.
[0226] In Example 60, the subject matter of Examples 55 - 59 includes: wherein, when the character set does not include a noise character set distributed within the character set corresponding to the stored credential, the GUI displays a visual indicator, and wherein the GUI further requires that the character set include the noise character set distributed within the character set corresponding to the stored credential.
[0227] In Example 61, the subject matter of Example 60 includes: wherein, when the dispersion measure of the noise characters in the character set corresponding to the stored credential does not meet a threshold, the GUI displays the visual indicator, and wherein the GUI further requires that the dispersion measure of the noise character set within the character set meet the threshold.
[0228] In Example 62, the subject matter of Examples 55 - 61 includes determining that the character set includes the first subset and the second subset.
[0229] In Example 63, the subject matter of Examples 55 - 62 includes receiving an indication that the character set includes the first subset and the second subset.
[0230] Example 64 is a device for authenticating access to an access-controlled resource, the device comprising: one or more hardware processors; a memory storing instructions which, when run by the one or more hardware processors, cause the device to perform operations including: causing a graphical user interface (GUI) to be displayed to request authentication credentials for an authentication attempt, the GUI including an input field for accepting the requested authentication credentials in the form of a set of characters from an input device, the GUI requiring that the set of characters include more characters than a stored credential; accepting, after receiving the input for the GUI regarding completion of the set of characters, the set of characters from the input field, the set of characters including more characters than the stored credential; receiving an indication that the accepted set of characters includes a first subset of characters that match and are in the same order as the stored credential, and a second subset of characters that are not specified for the authentication attempt and are interleaved with the first subset of characters in an order not specified for the authentication attempt; and in response to receiving the indication, allowing access to the access-controlled resource.
[0231] In example 65, the subject matter of example 64 includes: wherein the input for the GUI regarding completion of the set of characters includes a press of an enter key or an input pointing to a submit button.
[0232] In example 66, the subject matter of examples 64 - 65 includes: wherein the authentication credential is a password.
[0233] In example 67, the subject matter of examples 64 - 66 includes: wherein when the set of characters does not include more characters than the number of characters in the stored credential, the GUI displays a visual indicator.
[0234] In example 68, the subject matter of examples 64 - 67 includes: wherein when the set of characters does not include a set of noise characters, the GUI displays a visual indicator.
[0235] In example 69, the subject matter of examples 64 - 68 includes: wherein when the set of characters does not include a set of noise characters distributed within the set of characters corresponding to the stored credential, the GUI displays a visual indicator, and wherein the GUI further requires that the set of characters include the set of noise characters distributed within the set of characters corresponding to the stored credential.
[0236] In Example 70, the subject matter of Example 69 includes: wherein, when the dispersion measure of the noise characters in the character set corresponding to the stored credential does not meet a threshold, the GUI displays the visual indicator, and wherein the GUI also requires the dispersion measure of the noise character set within the character set to meet the threshold.
[0237] In Example 71, the subject matter of Examples 64-70 includes: wherein the operation further includes: determining that the character set includes the first subset and the second subset.
[0238] In Example 72, the subject matter of Examples 64-71 includes: wherein the operation further includes: receiving an indication that the character set includes the first subset and the second subset.
[0239] Example 73 is a method for authenticating a password relative to a stored password, the method comprising: using one or more hardware processors: identifying a first set of characters corresponding to the stored password; receiving, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; and enabling access to a controlled resource based on determining that the second set of characters includes: a first subset of characters that match and are in the same order as the first set of characters corresponding to the stored password, and a second subset of characters that are not specified for the authentication attempt and are distributed with the first subset of characters in an order not specified for the authentication attempt, wherein the dispersion measure of the characters at the corresponding positions of the first subset or the second subset within the second set of characters is within a threshold range.
[0240] In Example 74, the subject matter of Example 73 includes: wherein the dispersion measure of the corresponding positions of the first subset or the second subset includes the maximum distance between the corresponding positions of the subsequent characters of the second subset of characters within the second set of characters.
[0241] In Example 75, the subject matter of Examples 73-74 includes: wherein the dispersion measure of the corresponding positions of the first subset or the second subset includes the average distance between the corresponding positions of the subsequent characters of the second subset of characters within the second set of characters.
[0242] In Example 76, the subject matter of Examples 73-75 includes: wherein the dispersion measure of the corresponding positions of the first subset or the second subset includes the variance of the corresponding positions of the characters of the second subset of characters within the second set of characters.
[0243] In Example 77, the subject matter of Examples 73-76 includes: wherein, the second set of the characters is received via a network.
[0244] In Example 78, the subject matter of Examples 73-77 includes: wherein, the second set of the characters is received from an input device communicatively coupled to the one or more hardware processors.
[0245] In Example 79, the subject matter of Examples 73-78 includes: wherein, determining the second set of the characters includes the first subset of the characters includes: matching a plurality of vectors including permutations of the received second set of the characters against the first set of the characters.
[0246] In Example 80, the subject matter of Example 79 includes: wherein, matching the plurality of vectors including permutations of the received second set of the characters against the first set of the characters includes: comparing a distance derived from a distance function with a threshold.
[0247] In Example 81, the subject matter of Examples 73-80 includes: storing information about the second set of the characters; receiving a third set of the characters input during a second authentication attempt; and denying access to the access-controlled resource based on determining that the third set of the characters is within a threshold similarity of the second set of the characters.
[0248] Example 82 is a device for authentication, the device including: one or more hardware processors; a memory storing instructions that when executed cause the one or more hardware processors to perform operations including: identifying a first set of characters corresponding to a stored password; receiving, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; and granting access to an access-controlled resource based on determining that the second set of the characters includes: a first subset of characters that match and are in the same order as the first set of characters corresponding to the stored password, and a second subset of characters that are not specified for the authentication attempt and are distributed with the first subset of characters in an order not specified for the authentication attempt, wherein a spread metric of the corresponding positions of the characters of the first subset or the second subset within the second set of the characters is within a threshold range.
[0249] In Example 83, the subject matter of Example 82 includes: wherein, the spread metric of the corresponding positions of the first subset or the second subset includes a maximum distance between the corresponding positions of subsequent characters of the second subset of the characters within the second set of the characters.
[0250] In Example 84, the subject matter of Examples 82 - 83 includes: wherein the spread measure of the respective positions of the first subset or the second subset includes the average distance between the respective positions of subsequent characters of the second subset of characters within the second set of characters.
[0251] In Example 85, the subject matter of Examples 82 - 84 includes: wherein the spread measure of the respective positions of the first subset or the second subset includes the variance of the respective positions of the second subset of characters within the second set of characters.
[0252] In Example 86, the subject matter of Examples 82 - 85 includes: wherein the second set of characters is received via a network.
[0253] In Example 87, the subject matter of Examples 82 - 86 includes: wherein the second set of characters is received from an input device communicatively coupled to the one or more hardware processors.
[0254] In Example 88, the subject matter of Examples 82 - 87 includes: wherein the operation of determining the second set of characters including the first subset of characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
[0255] In Example 89, the subject matter of Example 88 includes: wherein the operation of matching the plurality of vectors including permutations of the received second set of characters against the first set of characters includes: comparing a distance derived from a distance function with a threshold.
[0256] In Example 90, the subject matter of Examples 82 - 89 includes: wherein the operation further includes: storing information about the second set of characters; receiving a third set of characters input during a second authentication attempt; and denying access to the access - controlled resource based on determining that the third set of characters is within a threshold similarity of the second set of characters.
[0257] Example 91 is a method for authenticating access to an access-controlled resource, the method comprising: using one or more hardware processors: causing a graphical user interface (GUI) to be displayed to request authentication credentials for accessing the access-controlled resource, the GUI including an input field for receiving the requested authentication credentials in the form of a set of characters from an input device, the GUI requiring that the set of characters include at least one character other than the characters in a stored credential; receiving, after receiving input for the GUI that is complete with respect to the set of characters, the set of characters from the input field, the set of characters including more characters than the stored credential and not including a subset of the set of characters that exactly matches the stored credential in its entirety; receiving an indication that the set of characters includes a first subset of characters that match a portion of the stored credential, the matching portion of the stored credential having fewer characters than the stored credential and in the same order; and in response to receiving the indication, displaying on the GUI that access to the access-controlled resource has been granted.
[0258] In example 92, the subject matter of example 91 includes: wherein the set of characters of the input for the GUI is required to have a predetermined number of characters of a length.
[0259] In example 93, the subject matter of examples 91-92 includes: wherein access to the access-controlled resource is denied based on determining that the matching portion of the set of characters is equal in its entirety to the first set of characters.
[0260] In example 94, the subject matter of examples 91-93 includes: receiving a second set of characters from the input field during a subsequent authentication attempt; and displaying in the GUI an indication that access to the access-controlled resource has been granted based on determining that: the second set of characters includes: a third subset of characters that match a second portion of the stored credential, the third subset of characters having fewer characters than the stored credential and in the same order; and a minimum number of additional characters that are interspersed with the third subset of characters; and the first subset of characters is different from the third subset of characters.
[0261] In Example 95, the subject matter of Examples 91-94 includes: receiving a second set of characters from the input field during a subsequent authentication attempt; and displaying an indication in the GUI that access to the access-controlled resource has been granted based on determining that: the second set of characters includes: a third subset of characters that match a second part of the stored credential, the third subset of characters having fewer characters and in the same order as the stored credential; and a minimum number of additional characters interspersed with the third subset of characters; and the additional characters are different from a second subset of characters interleaved with the first subset.
[0262] In Example 96, the subject matter of Examples 91-95 includes: wherein, displaying the indication that access to the access-controlled resource has been granted includes: determining that the first subset of characters includes a minimum number of characters corresponding to the stored credential.
[0263] In Example 97, the subject matter of Examples 91-96 includes: wherein, the first subset of characters is determined to match a part of the stored credential based on a distance function and a maximum distance threshold.
[0264] In Example 98, the subject matter of Example 97 includes: wherein, displaying the indication that access to the access-controlled resource has been granted includes: determining that the distance of the first subset of characters from the part of the stored credential is less than the maximum distance threshold and greater than the zero distance threshold.
[0265] In Example 99, the subject matter of Examples 97-98 includes: wherein, displaying the indication that access to the access-controlled resource has been granted includes: determining that the ratio of the distance of the first subset of characters from the part of the stored credential to the distance of a third subset of characters from the part of the stored credential exceeds a minimum ratio threshold.
[0266] In Example 100, the subject matter of Examples 91-99 includes: monitoring the input of the second set of characters when the second set of characters is being input; determining that the second set of characters does not include a second subset of characters interleaved with the first subset; and displaying an indication of the input of the second subset before completion of the input of the second set of characters.
[0267] In Example 101, the subject matter of Examples 91-100 includes: monitoring the input of the second set of characters when the second set of characters is being input; determining that the second set of characters completely includes the stored credential; and displaying an indication to remove at least one character from the second set of characters corresponding to the stored credential before completion of the input of the second set of characters.
[0268] In Example 102, the subject matter of Examples 91 - 101 includes: wherein, the GUI requires that the character set does not completely include the stored credentials.
[0269] In Example 103, the subject matter of Examples 91 - 102 includes: wherein, the character set is indicated as including a second subset of characters that are not specified for the access - controlled resource and are interleaved with a first subset of the characters in a non - specified order.
[0270] Example 104 is a device for authenticating access to an access - controlled resource, the device including: one or more hardware processors; a memory that stores instructions that, when executed, cause the one or more hardware processors to perform operations including: causing a graphical user interface (GUI) to be displayed to request authentication credentials for accessing the access - controlled resource, the GUI including an input field for accepting, from an input device, the requested authentication credentials in the form of a character set, the GUI requiring that the character set include at least one character other than the characters in the stored credentials; accepting, after receiving input regarding completion of the character set for the GUI, the character set from the input field, the character set including more characters than the stored credentials and not including a subset that exactly matches the stored credentials as a whole; receiving an indication that the character set includes a first subset of characters that match a portion of the stored credentials, the matching portion of the stored credentials having fewer characters than the stored credentials and having the same order; and in response to receiving the indication, displaying on the GUI that access to the access - controlled resource has been granted.
[0271] In Example 105, the subject matter of Example 104 includes: wherein, the character set of the input for the GUI is required to have a predetermined number of characters of a length.
[0272] In Example 106, the subject matter of Examples 104 - 105 includes: wherein, access to the access - controlled resource is denied based on determining that the matching portion of the character set is equal to the first set of characters as a whole.
[0273] In Example 107, the subject matter of Examples 104 - 106 includes the following operations: receiving a second set of characters from the input field during a subsequent authentication attempt; and displaying an indication in the GUI that access to the access-controlled resource has been granted based on determining that: the second set of characters includes: a third subset of characters that match a second part of the stored credential, the third subset of characters having fewer characters and in the same order as the stored credential; and a minimum number of additional characters interspersed with the third subset of characters; and the first subset of characters is different from the third subset of characters.
[0274] In Example 108, the subject matter of Examples 104 - 107 includes the following operations: receiving a second set of characters from the input field during a subsequent authentication attempt; and displaying the indication in the GUI that access to the access-controlled resource has been granted based on determining that: the second set of characters includes: a third subset of characters that match a second part of the stored credential, the third subset of characters having fewer characters and in the same order as the stored credential; and a minimum number of additional characters interspersed with the third subset of characters; and the additional characters are different from a second subset of characters interlaced with the first subset.
[0275] In Example 109, the subject matter of Examples 104 - 108 includes: wherein the operation of displaying the indication that access to the access-controlled resource has been granted includes: determining that the first subset of characters includes a minimum number of characters corresponding to the stored credential.
[0276] In Example 110, the subject matter of Examples 104 - 109 includes: wherein the first subset of characters is determined to match a part of the stored credential based on a distance function and a maximum distance threshold.
[0277] In Example 111, the subject matter of Example 110 includes: wherein the operation of displaying the indication that access to the access-controlled resource has been granted includes: determining that the distance of the first subset of characters from the part of the stored credential is less than the maximum distance threshold and greater than zero distance threshold.
[0278] In Example 112, the subject matter of Examples 110 - 111 includes: wherein the operation of displaying the indication that access to the access-controlled resource has been granted includes: determining that the ratio of the distance of the first subset of characters from the part of the stored credential to the distance of a third subset of characters from the part of the stored credential exceeds a minimum ratio threshold.
[0279] In Example 113, the subject matter of Examples 104 - 112 includes the following operations: monitoring the input of the second set of characters when the second set of characters is input; determining that the second set of characters does not include a second subset of characters that interleave with the first subset; and displaying an indication of inputting the second subset before completion of the input of the second set of characters.
[0280] In Example 114, the subject matter of Examples 104 - 113 includes the following operations: monitoring the input of the second set of characters when the second set of characters is input; determining that the second set of characters completely includes the stored credential; and displaying an indication of removing at least one character from the second set of characters corresponding to the stored credential before completion of the input of the second set of characters.
[0281] In Example 115, the subject matter of Examples 104 - 114 includes: wherein the GUI requires that the set of characters does not completely include the stored credential.
[0282] In Example 116, the subject matter of Examples 104 - 115 includes: wherein the set of characters is indicated as including a second subset of characters that are not specified for the access - controlled resource and that interleave with the first subset of characters in a non - specified order.
[0283] Example 117 is a method for authenticating a password to be authenticated relative to a stored password including a first set of characters, the method including: using one or more hardware processors: receiving a second set of characters to be authenticated during an authentication attempt; and enabling access to an access - controlled resource based on: determining that no subset of the second set of characters matches the first set of characters corresponding to the stored password; and determining that the second set of characters includes: a first subset of the second set of characters that matches a portion of the first set of characters corresponding to the stored password, the portion of the first set of characters having fewer characters than the first set of characters and having the same order; and a minimum number of additional characters that are interspersed with the first subset of characters.
[0284] In Example 118, the subject matter of Example 117 includes: receiving a third set of characters to be authenticated during a second authentication attempt; and denying access to the access - controlled resource based on determining that a portion of the third set of characters is equal to the first set of characters.
[0285] In Example 119, the subject matter of Examples 117 - 118 includes: receiving a third set of characters during a second authentication attempt; and granting access to the access - controlled resource based on determining that the third set of characters includes: a second subset of characters that matches a portion of the first set of characters corresponding to the stored password, the portion of the first set of characters having fewer characters than the first set of characters and having the same order; and a minimum number of second additional characters interspersed with the first subset of characters, and wherein the first subset of characters is different from the second subset of characters.
[0286] In Example 120, the subject matter of Examples 117 - 119 includes: receiving a third set of characters during a second authentication attempt; and granting access to the access - controlled resource based on determining that the third set of characters includes: a second subset of characters that matches a portion of the first set of characters corresponding to the stored password, the portion of the first set of characters having fewer characters than the first set of characters and having the same order; and a minimum number of second additional characters interspersed with the first subset of characters, and wherein the second additional characters are different from the additional characters.
[0287] In Example 121, the subject matter of Examples 117 - 120 includes: wherein granting access to the access - controlled resource includes: determining that the portion of the first set of characters includes a minimum number of characters corresponding to the stored password.
[0288] In Example 122, the subject matter of Examples 117 - 121 includes: wherein determining that the second set of characters includes the first subset of characters includes: determining a match between a portion of the second set of characters and the first subset of characters based on a distance function and a maximum distance threshold.
[0289] In Example 123, the subject matter of Example 122 includes: wherein granting access to the access - controlled resource includes: determining that the distance of the first subset of characters from the characters in the second set is less than the maximum distance threshold and greater than the zero - distance threshold.
[0290] In Example 124, the subject matter of Examples 122 - 123 includes: wherein granting access to the access - controlled resource includes: determining that the ratio of the distance of the first subset of characters from the characters in the second set to the distance of the second subset of characters from the characters in the second set exceeds a minimum ratio threshold.
[0291] In Example 125, the subject matter of Examples 117 - 124 includes: wherein determining that the second set of characters includes a first subset of the characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
[0292] Example 126 is an apparatus for authenticating a password to be authenticated relative to a stored password including a first set of characters, the apparatus including: one or more hardware processors; a memory storing instructions that when executed cause the one or more hardware processors to perform operations including: receiving, during an authentication attempt, a second set of characters to be authenticated; and causing access to a controlled resource to be granted based on: determining that no subset of the second set of characters matches the first set of characters corresponding to the stored password; and determining that the second set of characters includes: a first subset of the second set of characters that matches a portion of the first set of characters corresponding to the stored password, the portion of the first set of characters having fewer and in the same order characters than the first set of characters; and a minimum number of additional characters interspersed with the first subset of characters.
[0293] In Example 127, the subject matter of Example 126 includes: wherein the operations further include: receiving, during a second authentication attempt, a third set of characters to be authenticated; and denying access to the controlled resource based on determining that a portion of the third set of characters is equal to the first set of characters.
[0294] In Example 128, the subject matter of Examples 126 - 127 includes the operations of: receiving, during a second authentication attempt, a third set of characters; and causing access to the controlled resource to be granted based on determining that the third set of characters includes: a second subset of characters that matches a portion of the first set of characters corresponding to the stored password, the portion of the first set of characters having fewer and in the same order characters than the first set of characters; and a minimum number of second additional characters interspersed with the first subset of characters, and wherein the first subset of characters is different from the second subset of characters.
[0295] In Example 129, the subject matter of Examples 126 - 128 includes the following operations: receiving a third set of characters during a second authentication attempt; and granting access to the access-controlled resource based on determining that the third set of characters includes: a second subset of characters that matches a portion of the first set of characters corresponding to the stored password, the portion of the first set of characters having fewer characters than the first set of characters and in the same order; and a minimum number of second additional characters interspersed with the first subset of characters, and wherein the second additional characters are different from the additional characters.
[0296] In Example 130, the subject matter of Examples 126 - 129 includes: wherein the operation of granting access to the access-controlled resource includes: determining that the portion of the first set of characters includes a minimum number of characters corresponding to the stored password.
[0297] In Example 131, the subject matter of Examples 126 - 130 includes: wherein the operation of determining that the second set of characters includes the first subset of characters includes: determining a match between a portion of the second set of characters and the first subset of characters based on a distance function and a maximum distance threshold.
[0298] In Example 132, the subject matter of Example 131 includes: wherein the operation of granting access to the access-controlled resource includes: determining that the second set of distances of the first subset of characters from the characters is less than the maximum distance threshold and greater than the zero distance threshold.
[0299] In Example 133, the subject matter of Examples 131 - 132 includes: wherein the operation of granting access to the access-controlled resource includes: determining that the ratio of the second set of distances of the first subset of characters from the characters to the second set of distances of the second subset of characters from the characters exceeds a minimum ratio threshold.
[0300] In Example 134, the subject matter of Examples 126 - 133 includes: wherein the operation of determining that the second set of characters includes the first subset of characters includes: matching a plurality of vectors including permutations of the second set of received characters against the first set of characters.
[0301] Example 135 is a method for verifying a password, the method comprising: receiving a set of characters as part of an access request process to access an access-controlled resource; determining that no subset of the set of characters exactly matches a stored password; accessing a plurality of ordered vectors comprising ordered subsets of the stored password, each of the plurality of ordered vectors having a length less than the length of the stored password; creating a plurality of check vectors based on the received set of characters, each of the plurality of check vectors having a length corresponding to the length of an ordered vector in the plurality of ordered vectors, wherein each of the plurality of check vectors comprises a different ordered combination of the received set of characters having the same order; determining a set of distances between each corresponding vector in the plurality of check vectors and each ordered vector in the plurality of ordered vectors; selecting the vector in the set of check vectors corresponding to the minimum distance in the set of distances; and based on a comparison of a value corresponding to the selected vector with a threshold, granting access to the access-controlled resource.
[0302] In example 136, the subject matter of example 135 includes: wherein determining the set of distances between each corresponding vector in the plurality of check vectors and each ordered vector in the plurality of ordered vectors includes: determining a Hamming distance between the corresponding vector and each ordered vector of the plurality of ordered vectors.
[0303] In example 137, the subject matter of examples 135-136 includes: wherein granting access to the access-controlled resource includes: determining that the minimum distance is greater than a zero distance threshold.
[0304] In example 138, the subject matter of examples 135-137 includes: selecting a second vector in the plurality of check vectors corresponding to the second smallest distance in the set of distances; and wherein granting access to the access-controlled resource includes: determining that the ratio of the minimum distance to the second smallest distance is less than the threshold.
[0305] In example 139, the subject matter of examples 135-138 includes: receiving a second set of characters as part of a second access request process to access the access-controlled resource; determining that a subset of the second set of characters exactly matches the stored password; and denying access based on determining that the subset of the second set of characters exactly matches the stored password.
[0306] In example 140, the subject matter of examples 135 - 139 includes: receiving a second set of characters during a second access request process, wherein the set of characters is different from the second set of characters; selecting a second vector from a second plurality of check vectors corresponding to a new minimum distance in a second set of distances; and based on a comparison of a second value corresponding to the selected vector with a second threshold, causing access to the access - controlled resource to be granted.
[0307] In example 141, the subject matter of examples 135 - 140 includes: wherein causing access to the access - controlled resource to be granted includes: determining that the selected vector includes a minimum number of characters corresponding to the stored password.
[0308] Example 142 is a device for verifying an input password, the device including: one or more hardware processors; a memory storing instructions that, when executed, cause the one or more hardware processors to perform operations including: receiving a set of characters as part of an access request process to access an access - controlled resource; determining that no subset of the set of characters exactly matches a stored password; accessing a plurality of ordered vectors including ordered subsets of the stored password, each of the plurality of ordered vectors having a length less than the length of the stored password; creating a plurality of check vectors based on the received set of characters, each of the plurality of check vectors having a length corresponding to the length of an ordered vector in the plurality of ordered vectors, wherein each vector in the plurality of check vectors includes a different ordered combination of the received set of characters having the same order; determining a set of distances between each corresponding vector in the plurality of check vectors and each ordered vector in the plurality of ordered vectors; selecting a vector from the set of check vectors corresponding to the minimum distance in the set of distances; and based on a comparison of a value corresponding to the selected vector with a threshold, causing access to the access - controlled resource to be granted.
[0309] In example 143, the subject matter of example 142 includes: wherein the operation of determining the set of distances between each corresponding vector in the plurality of check vectors and each ordered vector in the plurality of ordered vectors includes: determining a Hamming distance between the corresponding vector and each ordered vector in the plurality of ordered vectors.
[0310] In example 144, the subject matter of examples 142 - 143 includes: wherein the operation of causing access to the access - controlled resource to be granted includes: determining that the minimum distance is greater than a zero - distance threshold.
[0311] In Example 145, the subject matter of Examples 142 - 144 includes the following operations: selecting a second vector corresponding to the second smallest distance in the set of distances among the plurality of check vectors; and wherein enabling access to the access-controlled resource includes determining that the ratio of the smallest distance to the second smallest distance is less than the threshold.
[0312] In Example 146, the subject matter of Examples 142 - 145 includes: wherein the operations further include: receiving a second set of characters as part of a second access request process to access the access-controlled resource; determining that a subset of the second set of characters exactly matches the stored password; and denying access based on determining that the subset of the second set of characters exactly matches the stored password.
[0313] In Example 147, the subject matter of Examples 142 - 146 includes the following operations: receiving a second set of characters during a second access request process, wherein the set of characters is different from the second set of characters; selecting a second vector corresponding to the new smallest distance in the second set of distances among the second plurality of check vectors; and enabling access to the access-controlled resource based on a comparison of a second value corresponding to the selected vector with a second threshold.
[0314] In Example 148, the subject matter of Examples 142 - 147 includes: wherein the operation of enabling access to the access-controlled resource includes determining that the selected vector includes the minimum number of characters corresponding to the stored password.
[0315] Example 149 is at least one machine-readable medium including instructions that, when run by a processing circuit, cause the processing circuit to perform operations to implement any of Examples 1 - 148.
[0316] Example 150 is an apparatus including units for implementing any of Examples 1 - 148.
[0317] Example 151 is a system for implementing any of Examples 1 - 148.
[0318] Example 152 is a method for implementing any of Examples 1 - 148.
Claims
1. A method for authenticating a password relative to a stored password, the method comprising: using one or more hardware processors: determining a first set of characters corresponding to the stored password; receiving, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; and granting access to a controlled resource based on determining that the second set of characters includes: a first subset of password characters that matches and has the same order as the first set of characters corresponding to the stored password; and a second subset of noise characters that are not specified for the authentication attempt and are distributed with the first subset of password characters in an order not specified for the authentication attempt, wherein a measure of the spread of the characters in the respective positions within the second set of characters for the first subset or the second subset is within a threshold range.
2. The method according to claim 1, wherein, the measure of the spread of the respective positions for the first subset or the second subset includes: the maximum distance between the respective positions within the second set of characters for subsequent characters in the second subset of noise characters.
3. The method according to claim 1, wherein, the measure of the spread of the respective positions for the first subset or the second subset includes: the average distance between the respective positions within the second set of characters for subsequent characters in the second subset of noise characters.
4. The method according to claim 1, wherein, the measure of the spread of the respective positions for the first subset or the second subset includes: the variance of the respective positions within the second set of characters for the second subset of noise characters.
5. The method according to claim 1, wherein, the second set of characters is received from an input device communicatively coupled to the one or more hardware processors.
6. The method according to claim 1, wherein, determining that the second set of characters includes the first subset of password characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
7. The method according to claim 6, wherein, matching the plurality of vectors including permutations of the received second set of characters against the first set of characters includes: comparing a distance derived from a distance function with a threshold.
8. The method according to claim 1, further comprising: storing information about the second set of characters; receiving a third set of characters input during a second authentication attempt; and denying access to the controlled resource based on determining that the third set of characters is within a threshold similarity of the second set of characters.
9. A device for authentication, the device comprising: one or more hardware processors; a memory storing instructions that, when executed, cause the one or more hardware processors to perform operations including the following: Determine a first set of characters corresponding to a stored password; Receive, during an authentication attempt, a second set of characters to be authenticated, wherein the received second set of characters to be authenticated includes more characters than the first set of characters corresponding to the stored password; and Grant access to the access-controlled resource based on determining that the second set of characters includes: A first subset of password characters that matches and is in the same order as the first set of characters corresponding to the stored password; and A second subset of noise characters that are not specified for the authentication attempt and are distributed with the first subset of password characters in an order not specified for the authentication attempt, wherein a measure of the spread of the characters in the respective positions within the second set of characters of the first subset or the second subset is within a threshold range.
10. The apparatus according to claim 9, wherein, The measure of the spread of the respective positions of the first subset or the second subset includes: the maximum distance between the respective positions within the second set of characters of subsequent characters in the second subset of noise characters.
11. The apparatus according to claim 9, wherein, The measure of the spread of the respective positions of the first subset or the second subset includes: the average distance between the respective positions within the second set of characters of subsequent characters in the second subset of noise characters.
12. The apparatus according to claim 9, wherein, The measure of the spread of the respective positions of the first subset or the second subset includes: the variance of the respective positions within the second set of characters of the second subset of noise characters.
13. The apparatus according to claim 9, wherein, The operation of determining that the second set of characters includes the first subset of password characters includes: matching a plurality of vectors including permutations of the received second set of characters against the first set of characters.
14. The apparatus according to claim 13, wherein, The operation of matching the plurality of vectors including permutations of the received second set of characters against the first set of characters includes: comparing a distance derived from a distance function with a threshold.
15. The apparatus according to claim 9, wherein, The operation further includes: Storing information about the second set of characters; Receiving a third set of characters input during a second authentication attempt; and Denying access to the access-controlled resource based on determining that the third set of characters is within a threshold similarity of the second set of characters.
Citation Information
Patent Citations
Cryptographic primitive for user authentication
EP3261287A1
Method and system for protecting a user's password
US20050273625A1