Management of Shared Authentication Credentials
By integrating the MAC address as an authentication factor for shared credentials, the system ensures only authorized devices can access shared credentials, addressing accountability and compliance issues in shared authentication systems.
Patent Information
- Application Number
- CN202111268076.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-12-18
- Filing Date
- 2021-10-29
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-10-29
AI Technical Summary
The existing shared authentication credential management system has problems such as poor user accountability, compliance violations, potential misuse, audit risks and complexity, and existing methods are difficult to effectively prevent security vulnerabilities caused by password bypassing and not checking in.
By binding the media access control address (MAC address) to the shared authentication credentials, using the MAC address as an additional authentication factor, and combining existing authentication credentials for verification, ensuring that only authorized devices can use the authentication credentials when checking out and checking in, and update their passwords after checking in to reduce the risk of bypass.
Improve the security and accountability of shared authentication credentials, reduce potential misuse caused by password bypass and unchecked, and enhance the system's compliance and audit capabilities.
Smart Images

Figure CN114647837B_ABST
Abstract
Description
Technical Field
[0001] The present invention generally relates to the field of security, and more particularly to managing shared authentication credentials. Background Art
[0002] Secure Shell (SSH) is an encrypted network protocol used to securely operate network services over an insecure network. Typical applications include remote command line, login, and remote command execution, but any network service can be protected with SSH. SSH provides a secure channel over an insecure network by using a client-server architecture and connecting an SSH client application to an SSH server. SSH is commonly used to log in to remote machines and execute commands, but SSH also supports tunneling, forwarding Transmission Control Protocol (TCP) ports, and X11 connections. Additionally, SSH can use the associated Secure Shell File Transfer (SFTP) or Secure Copy (SCP) protocol to transfer files. SSH is a protocol that can be used by many different types of applications across different platforms (e.g., different operating systems).
[0003] A Media Access Control address (MAC address) is a unique identifier assigned to a network interface controller (NIC) and used as a network address in communications within a network segment. This usage is common in most IEEE 802 networking technologies, including Ethernet, Wi-Fi, and Bluetooth. In the Open Systems Interconnection (OSI) network model, the MAC address is used in the media access control protocol sublayer of the data link layer. As typically represented, a MAC address can be recognized as six groups of two hexadecimal digits, separated by hyphens, colons, or no separator. MAC addresses are primarily assigned by device manufacturers and are therefore often referred to as burned-in addresses or Ethernet hardware addresses, hardware addresses, or physical addresses. Each address can be stored in hardware (e.g., read-only memory of a card) or through a firmware mechanism. Summary of the Invention
[0004] Aspects of the present invention disclose a method, computer program product, and system for managing and using shared authentication credentials. The method includes one or more processors updating usage information associated with an authentication credential with a Media Access Control address (MAC address) corresponding to a computing device associated with use of the authentication credential. The method further includes one or more processors receiving a login request including the authentication credential from a computing device. The method also includes one or more processors obtaining the MAC address of the computing device that sent the login request. The method also includes one or more processors verifying the authentication credential and the MAC address. Brief Description of the Drawings
[0005] Figure 1 is a functional block diagram of a data processing environment in accordance with an embodiment of the present invention.
[0006] Figure 2 is a flowchart depicting the operational steps of a program for managing and tracking the use of shared authentication credentials according to an embodiment of the present invention.
[0007] Figure 3 is a flowchart depicting the operational steps of a program for verifying authentication credentials according to an embodiment of the present invention.
[0008] Figure 4 depicts according to an embodiment of the present invention Figure 1 a block diagram of the components of a computing system of a client device, a shared ID management system, and an authentication system. Detailed Description
[0009] Embodiments of the present invention allow a process for extending the functionality of shared authentication credentials (e.g., shared identification (ID) credentials and passwords), especially in an information technology (IT) infrastructure environment. Thus, embodiments of the present invention operate to extend the functionality of existing tools and systems by creating a technical solution for a shared authentication credential system that more fully realizes the avoidance of password sharing. Embodiments of the present invention operate to incorporate the media access control address (MAC address) of a requesting user's device during the process of checking out and checking in authentication credentials.
[0010] Some embodiments of the present invention recognize that shared authentication credentials are a standard feature of IT infrastructure and are used to provide a common identity for a group of users performing a specific set of tasks. Embodiments of the present invention recognize that current implementations of shared authentication credentials include sine problems such as: the accountability of tracking which user has used a shared authentication credential for a specific operation, compliance violations due to passwords shared for shared IDs, potential misuse of shared authentication credentials (e.g., security vulnerabilities, etc.), audit risks and complexities, and the like.
[0011] In addition, embodiments of the present invention recognize that existing methods for shared authentication credential services utilize check-out and check-in processes to maintain individual accountability and assume that users corresponding to shared authentication credentials strictly follow the check-out and check-in processes to maintain the security and accountability of the usage log of shared authentication credentials. Thus, embodiments of the present invention recognize that existing methods for shared authentication credential tools have many potential leakage areas. For example, at check-out, passwords can be shared from one user to another individual, bypassing the complete check-out and check-in processes.
[0012] In addition, embodiments of the present invention recognize that if a user does not properly check in a credential (e.g., and change the corresponding password) after use, the shared authentication credential may remain available for potential misuse. Further, embodiments of the present invention recognize that current implementations rely on manual processes (e.g., via a compliance team) for compliance to monitor the use of shared authentication credentials in an effort to ensure proper processes are followed.
[0013] Various embodiments of the present invention are directed to extending the functionality provided by existing tools for shared authentication credentials to create a solution for implementing shared authentication credentials while avoiding shared credentials bypassing the shared authentication credential system. Embodiments of the present invention provide a checkout process that includes receiving a new password. The transaction for receiving the new password links (binds) the MAC address of the system providing the request for the authentication credential and updates the corresponding server or database record with an indication of the linked MAC address for the credential. Further, embodiments of the present invention modify the login script or the corresponding Secure Shell (SSH) protocol to include settings for matching the MAC address before authorizing the shared authentication credential as a valid login.
[0014] Accordingly, embodiments of the present invention utilize the MAC address of the corresponding system as another authentication factor in combination with the authentication credential. Thus, when the MAC address of the device performing the login matches the MAC address linked to the authentication credential (i.e., the MAC address of the system / device that checked out the authentication credential), the login will succeed. After use, the user checks in the shared authentication credential, and embodiments of the present invention can be used to update the password of the shared authentication credential, thereby reducing the likelihood of it being used by another individual (without checking out). Additionally, embodiments of the present invention can maintain the MAC address associated with the shared authentication credential until another user (and device) completes a checkout.
[0015] The implementation of embodiments of the present invention can take various forms, and exemplary implementation details are discussed subsequently with reference to the drawings.
[0016] The present invention will now be described in detail with reference to the drawings. Figure 1 is a functional block diagram showing a distributed data processing environment (generally labeled 100) in accordance with one embodiment of the present invention. Figure 1 Only an illustration of one implementation is provided, and no limitation to the environment in which different embodiments may be implemented is implied. Those skilled in the art may make many modifications to the described environment without departing from the scope of the present invention as recited in the claims.
[0017] An embodiment of the data processing environment 100 includes client devices 110, client device 120, a shared ID management system 130, and an authentication system 140, all interconnected via a network 105. In an example embodiment, the shared ID management system 130 represents a computing system (e.g., one or more management servers) that manages shared authentication credentials for a group of users (e.g., a group of users associated with an enterprise), where the group of users is, for example, users associated with client device 110 and client device 120. In another example embodiment, the authentication system 140 represents a computing system (e.g., one or more management servers) that provides authentication services to users (e.g., users associated with client device 110 and client device 120) who utilize the shared authentication credentials from the shared ID management system 130 for protected resources and / or assets. In other embodiments, according to various embodiments of the present invention, the data processing environment 100 may include additional instances of computing devices (not shown) that can interface with the shared ID management system 130 and the authentication system 140.
[0018] The network 105 can be, for example, a local area network (LAN), a telecommunications network, a wide area network (WAN) such as the Internet, or any combination of the three, and includes wired, wireless, or fiber optic connections. Generally, according to embodiments of the present invention, the network 105 can be any combination of connections and protocols that support communication between client device 110, client device 120, the shared ID management system 130, and the authentication system 140. In various embodiments, the network 105 facilitates communication between multiple networked computing devices (e.g., client device 110, client device 120, the shared ID management system 130, the authentication system 140, and other devices not shown), corresponding users (e.g., users of client device 110, users of client device 120, etc.), and corresponding management services (e.g., the shared ID management system 130 and the authentication system 140, etc.).
[0019] In various embodiments of the present invention, according to embodiments of the present invention, client device 110 and client device 120 can be workstations, personal computers, personal digital assistants, mobile phones, or any other device capable of executing computer-readable program instructions. Generally, client device 110 and client device 120 represent any electronic device or combination of electronic devices capable of executing computer-readable program instructions. According to embodiments of the present invention, client device 110 and client device 120 may include components Figure 4 described and depicted in further detail.
[0020] In an example embodiment, client device 110 and client device 120 are, respectively, a personal workstation or a mobile device associated with (e.g., registered with and / or utilized by) the respective users who utilize one or more shared authentication credentials managed by shared ID management system 130. In one example, the user of client device 110 requests to use (i.e., check out) a shared authentication credential from shared ID management system 130. Further, in this example, the user of client device 110 utilizes the checked-out authentication credential to attempt to access a protected asset or resource managed by authentication system 140. Thus, according to an embodiment of the present invention, the user of client device 120 cannot utilize the checked-out authentication credential until the user of client device 110 returns the credential to shared ID management system 130.
[0021] Client device 110 and client device 120 include respective instances of user interface 112, user interface 122, application 114, and application 124. User interface 112 and user interface 122 are programs that provide an interface between the respective users of client device 110 and client device 120 and multiple applications (e.g., application 114 and application 124) residing on the devices. A user interface (such as user interface 112 or user interface 122) refers to the information (such as graphics, text, and sound) presented to the user by the program and the control sequences by which the user controls the program. There are various types of user interfaces. In one embodiment, user interface 112 and / or user interface 122 is a graphical user interface. A graphical user interface (GUI) is a type of user interface that allows a user to interact with an electronic device (e.g., a computer keyboard and mouse) via graphical icons and visual indicators (such as assistive symbols), as opposed to a text-based interface, typed command labels, or text navigation. In computing, the GUI was introduced in response to the perceived steep learning curve of command-line interfaces that required commands to be typed on a keyboard. Actions in a GUI are typically performed by directly manipulating graphical elements. In another embodiment, user interface 112 and / or user interface 122 is a script or an application programming interface (API).
[0022] Application 114 and application 124 may represent one or more applications (e.g., an application suite) operating on respective instances of client device 110 and client device 120. In various exemplary embodiments, application 114 and application 124 may be applications used by the users of client device 110 or client device 120 to send data and / or receive data from shared ID management system 130 and authentication system 140. For example, application 114 and application 124 may be web browsers that can be accessed and utilized by the users of client device 110 or client device 120.
[0023] In another example, application 114 and application 124 are enterprise-specific applications associated with a shared ID management system 130, an authentication system 140, and / or a corresponding organization. In an additional example, application 114 and application 124 are applications corresponding to accessing specific protected resources or assets protected by the authentication system 140 (specific applications for protected assets). In an additional embodiment, in accordance with various embodiments of the present invention, application 114 and application 124 may send data to and receive data from an administrative program 200 on the shared ID management system 130 (e.g., as a client-side application of the administrative program 200) and an authentication program 300 on the authentication system 140 (e.g., as a client-side application of the authentication program 300).
[0024] In an exemplary embodiment, the shared ID management system 130 may be a desktop computer, a computer server, or any other computer system known in the art. In certain embodiments, the shared ID management system 130 represents a computer system that utilizes clustered computers and components (e.g., database server computers, application server computers, etc.) that act as a single seamless resource pool when accessed by elements of the data processing environment 100 (e.g., client devices 110, client devices 120, authentication system 140, and other devices not shown). Generally, the shared ID management system 130 represents any electronic device or combination of electronic devices capable of executing computer-readable program instructions. In accordance with an embodiment of the present invention, the shared ID management system 130 may include components described in further detail and depicted hereinafter. Figure 4 Components are described in further detail and depicted hereinafter.
[0025] The shared ID management system 130 includes a shared credential vault 132 and an administrative program 200. In various embodiments, in accordance with aspects of the present invention, the shared ID management system 130 operates as a computing system that manages shared authentication credentials for a group of users (e.g., a group of users associated with an enterprise), the group of users being users such as those associated with client devices 110 and client devices 120. In one embodiment, in accordance with an embodiment of the present invention, the shared ID management system 130 provides an improved process for checking out and checking in shared authentication credentials.
[0026] In various embodiments, the shared ID management system 130 stores multiple shared authentication credentials in the shared credential repository 132. In additional embodiments, the shared credential repository 132 also stores usage information corresponding to the shared authentication credentials (e.g., checkout and check-in history, etc.). For example, the shared credential repository 132 stores the history of which users have utilized a particular shared authentication credential, the corresponding MAC address, etc. In additional example embodiments, the hypervisor 200 utilizes the shared credential repository 132 to track the in-progress (and completed) allocation and assignment (i.e., checkout) of the shared authentication credentials.
[0027] The shared credential repository 132 can be implemented using any type of storage device, e.g., a persistent storage device 405 that is capable of storing data that can be accessed and utilized by the shared ID management system 130, such as a database server, a hard disk drive, or a flash memory. In other embodiments, the shared credential repository 132 can represent multiple storage devices and data collections within the shared ID management system 130.
[0028] In an example embodiment, in accordance with an embodiment of the present invention, the hypervisor 200 manages and tracks the usage of the shared authentication credentials. In various embodiments, in accordance with an embodiment of the present invention, the hypervisor 200 manages the checkout and check-in of the shared authentication credentials to users and tracks the MAC address corresponding to the requesting device of the user. Further, the hypervisor 200 communicates with the authentication system 140 to manage the authentication of the shared authentication credentials.
[0029] In an example embodiment, the authentication system 140 can be a desktop computer, a computer server, or any other computer system known in the art. In certain embodiments, the authentication system 140 represents a computer system that utilizes cluster computers and components (e.g., database server computers, application server computers, etc.) that act as a single seamless resource pool when accessed by elements of the data processing environment 100 (e.g., client devices 110, client devices 120, the shared ID management system 130, and other devices not shown). Generally, the authentication system 140 represents any electronic device or combination of electronic devices capable of executing computer-readable program instructions. In accordance with an embodiment of the present invention, the authentication system 140 can include components that are further described and depicted in more detail. Figure 4 Further detailed description and depiction.
[0030] The authentication system 140 includes a tracking database 142 and an authentication program 300. In various embodiments, the authentication system 140 operates as a computing system that provides an authentication service to protected resources and / or assets for users (e.g., users associated with client device 110 and client device 120) that utilize shared authentication credentials from a shared ID management system 130. In additional embodiments, in accordance with embodiments of the present invention, the authentication system 140 is a computing system that facilitates secure communication and access to secure resources and assets using the SSH protocol.
[0031] In various embodiments of the present invention, a user of client device 110 (or client device 120) registers with the shared ID management system 130 and the authentication system 140 (e.g., via a corresponding application). For example, the user completes a registration process, provides information, and authorizes the collection and analysis of relevant data provided at least by client device 110 (i.e., opt-in) (e.g., MAC address, user profile information, user contact information, authentication information, user preferences, or types of information, for use by the shared ID management system 130 with the management program 200 and for use by the authentication system 140 with the authentication program 300).
[0032] In various embodiments, the tracking database 142 stores information associated with the use of shared authentication credentials, such as the MAC address of a device (e.g., a user who has checked out a credential) to which a shared credential has been assigned. In an additional aspect, the authentication system 140 encrypts the information stored in the tracking database 142. In an example embodiment, the tracking database 142 can be an organized collection of data hosted on the authentication system 140.
[0033] The tracking database 142 can be implemented using any type of storage device, e.g., a permanent storage device 405 capable of storing data accessible and utilizable by the authentication system 140, such as a database server, a hard disk drive, or a flash memory. In other embodiments, the tracking database 142 can represent multiple storage devices and collections of data within the authentication system 140.
[0034] In an example embodiment, in accordance with embodiments of the present invention, the authentication program 300 verifies authentication credentials that include a MAC address. In various embodiments, the authentication program 300 receives a login request from a user and obtains the MAC address of the user's requesting device. In accordance with embodiments of the present invention, the authentication program 300 is then operable to verify the authentication credentials of the login request and the obtained MAC address to determine whether to authorize or restrict access to a protected resource.
[0035] In various embodiments, the authentication system 140 may host protected / secure assets or operate as a gateway (i.e., an intermediary) to authenticate users before accessing and / or utilizing the protected / secure assets. In another embodiment, the shared ID management system 130 and the authentication system 140 may be included in a single system that interfaces with the users of the client device 110 and the client device 120, and this single system combines the various functions previously discussed in accordance with the various embodiments of the present invention.
[0036] Figure 2 FIG. 4 is a flowchart showing the operating steps of a hypervisor 200 according to an embodiment of the present invention, and the hypervisor 200 is a program for managing and tracking the use of shared authentication credentials. In various embodiments, the hypervisor 200 operates on the shared ID management system 130 to manage the checkout and check-in processes of the shared authentication credentials in the shared credential repository 132. In an exemplary embodiment, the hypervisor 200 operates as a background process, waiting to receive requests from users. In additional embodiments, the hypervisor 200 determines whether the user requesting the authentication credentials is an authorized user (i.e., a user who has registered and been approved to use the shared authentication credentials) before processing the request for the credentials.
[0037] In step 202, the hypervisor 200 receives a request to checkout authentication credentials. In one embodiment, the hypervisor 200 receives a request to checkout authentication credentials from a user of the client device 110. In some embodiments, the user of the client device 110 may request a specific set of authentication credentials from the shared credential repository 132. In additional embodiments, the user of the client device 110 may request access to a specific protected resource / asset (e.g., using the SSH protocol), and the hypervisor 200 may identify the corresponding authentication credentials from the shared credential repository 132. In various embodiments, the authentication credentials may be a username and password combination, or any other form of shared authentication credentials that can operate in accordance with the various embodiments of the present invention.
[0038] In step 204, the hypervisor 200 obtains the MAC address. In one embodiment, the hypervisor 200 obtains or retrieves the MAC address of the requesting computing device (i.e., the client device 110) via the network 105. The Media Access Control address (MAC address) is a unique identifier assigned to a network interface controller (NIC) and is used as a network address in communications within a network segment. In an exemplary embodiment, the hypervisor 200 (using SSH transmission) obtains the MAC address of the client device 110 to be used as an identification factor / credential for the user of the specific device.
[0039] In various embodiments, the shared ID management system 130 (and the hypervisor 200) may send one or more commands (or utilities) over the network 105 to a requesting computing device to obtain (or request) a corresponding MAC address (e.g., based on the operating system of the requesting device). In an example scenario, the hypervisor 200 may utilize utilities and commands such as "getmac" and "ifconfig" or other commands corresponding to the characteristics of a particular requesting device. In another embodiment, the hypervisor 200 may request that the requesting user provide the MAC address. The hypervisor 200 may then verify that the MAC address provided by the user is the correct MAC address of the requesting computing device.
[0040] In step 206, the hypervisor 200 sends the MAC address to the authentication system. In one embodiment, the hypervisor 200 sends the obtained MAC address (from step 204) to the authentication system 140. In various embodiments, the hypervisor 200 sends the MAC address to the authentication system 140 to update the necessary tracking information for an instance of the shared credential in the tracking database 142. On the other hand, the hypervisor 200 may encrypt the MAC address and then send the encrypted MAC address to the authentication system 140. In an alternative embodiment, the hypervisor 200 may send the unencrypted MAC address to the authentication system 140 for encryption before storage.
[0041] In various embodiments, the process of obtaining and storing the MAC address of the requesting device binds the shared authentication credential for use by the requesting device (i.e., the client device 110) until the requesting device checks in the authentication credential. Thus, embodiments of the present invention implement an additional security factor in the process of utilizing the shared authentication credential.
[0042] In an example embodiment, in accordance with various aspects of the present invention, the shared ID management system 130 and the authentication system 140 may utilize the iptables utility to manage the utilization of the obtained MAC address. IPTables is a front-end user space tool for managing Netfilter in the Linux kernel. IPTables is mainly used in the transport layer (layer 4) and the network layer (layer 3), and IPTables can also work in the DataLink (data link) layer. Embodiments of the present invention may utilize the iptables utility to allow or deny login requests based on the MAC address of the user's device (regarding Figure 3For further details). In an example scenario, the hypervisor 200 sends the command "iptables -A INPUT -p tcp --dport #port No.# -m mac - source #MAC Add.# -j ACCEPT" to run on the authentication system 140 (i.e., the terminal server) to modify iptables to block the use of shared authentication credentials, except for computing devices with a specific MAC address (i.e., the MAC address obtained in step 204).
[0043] In step 208, the hypervisor 200 sends the authentication credentials to the requesting user. In one embodiment, the hypervisor 200 sends the authentication credentials (requested in step 202) to the user on the client device 110 (i.e., the requesting computing device, which corresponds to the obtained MAC address). In an additional embodiment, the hypervisor 200 may send the authentication credentials to the requesting user (step 208) in parallel with sending the MAC address to the authentication system (step 206). In another embodiment, the hypervisor 200 may send the authentication credentials to the requesting user after receiving confirmation that the MAC address has been received and correctly recorded (i.e., has been used to update the record corresponding to a specific instance of the shared authentication credentials in the tracking database 142).
[0044] In step 210, the hypervisor 200 receives the returned authentication credentials. In one embodiment, the hypervisor 200 receives the return (check - in) of the authentication credentials from the user of the client device 110. In various embodiments, the hypervisor 200 waits until it receives the sent authentication credentials (from step 208). On the other hand, the hypervisor 200 may verify (via MAC address comparison) that the authentication credentials are received from the same device that requested the credentials. In a further embodiment, the hypervisor 200 may maintain the binding of the authentication credentials to the MAC address of the client device 110 until another device (e.g., the client device 120) checks out the authentication credentials.
[0045] In another embodiment, the hypervisor 200 changes at least one authentication credential in response to receiving the check - in of the credential. For example, the hypervisor 200 changes the password of the authentication credential and then stores the updated authentication credential in the shared credential repository 132. In another example, the user of the client device 110 may change the password as part of the check - in process of the authentication credential. In an additional embodiment, the hypervisor 200 may send the updated authentication credential to the authentication system 140 to update the record during the authentication process.
[0046] Figure 3FIG. 0 is a flowchart showing the operating steps of an authentication program 300 according to an embodiment of the present invention, which is a program for verifying authentication credentials. In various embodiments, the authentication program 300 operates as a process for authenticating a user who attempts to access a protected asset or resource (e.g., for an enterprise, using SSH). In an exemplary embodiment, according to various embodiments of the present invention, the authentication program 300 operates as a background process, waiting to receive MAC address information (e.g., from the shared ID management system 130) and / or a login request (e.g., from a user using the client device 110).
[0047] In step 302, the authentication program 300 receives a MAC address corresponding to a set of authentication credentials. In one embodiment, the authentication program 300 receives the MAC address of the client device 110 from the shared ID management system 130 (in step 206 of the hypervisor 200). In an exemplary embodiment, the authentication program 300 receives an indication of the MAC address and the corresponding set of authentication credentials (which are bound to the MAC address) from the shared ID management system 130. In an additional embodiment, the authentication program 300 may receive an indication of a protected resource or asset. In various embodiments, the authentication program 300 receives an encrypted MAC address. In another embodiment, the authentication program 300 may encrypt the received MAC address before storing it.
[0048] In some embodiments, according to various aspects of the present invention, the authentication program 300 (and the authentication system 140) may utilize the iptables utility to manage the utilization of the obtained MAC address (previously discussed with respect to step 206 of the hypervisor 200). In an exemplary embodiment, the authentication program 300 receives the MAC address (of the client device 110) and updates the tracking database 142 with information indicating that the MAC address is bound to the corresponding set of authentication credentials. For example, the authentication program 300 updates the tracking database 142 to track the binding of the MAC address of the client device 110 to a specific set of authentication credentials. Thus, according to other embodiments of the present invention, the authentication program 300 utilizes the MAC address as an additional authentication factor when verifying a specific set of authentication credentials.
[0049] In step 304, the authentication program 300 receives a login request. In one embodiment, the authentication program 300 receives a request from a user of the client device 110 to access a protected / secure resource. In various embodiments, the authentication program 300 waits until a login request or other form of request is received to access a protected resource or asset using authentication credentials. In additional embodiments, the authentication program 300 may be initiated at step 204 to initiate authentication for the login process. In an example scenario, the authentication program 300 receives a login request and corresponding authentication credentials (e.g., a request to securely log in to a remote machine from the client device 110) using the SSH protocol.
[0050] In step 306, the MAC address is obtained. In one embodiment, the authentication program 300 obtains or retrieves the MAC address of the requesting computing device (i.e., the client device 110) via the network 105. In an example embodiment, the authentication program 300 (using SSH transport) obtains the MAC address of the client device 110 to be used as an identification factor / credential for the user of the particular device. In various embodiments, the authentication system 140 (and the authentication program 300) may send one or more commands (or utilities) to the requesting computing device via the network 105 to obtain (or request) the corresponding MAC address (e.g., based on the operating system of the requesting device).
[0051] In an example scenario, the authentication program 300 may utilize utilities and commands such as "getmac" and "ifconfig" or other commands corresponding to the characteristics of the particular requesting device. In another embodiment, the authentication program 300 may request that the requesting user provide the MAC address. Then, the authentication program 300 may verify that the MAC address provided by the user is the correct MAC address of the requesting computing device. In additional embodiments, the authentication program 300 may receive the MAC address of the requesting device (client device 110) as part of the login request (e.g., included in the SSH login request) at (step 304).
[0052] In step 308, the authentication program 300 verifies the authentication credentials and the MAC address. In one embodiment, the authentication program 300 verifies the received authentication credentials (for the login request of step 304) and verifies the MAC address of the requesting device (obtained in step 306). In an example embodiment, the authentication program 300 compares the received authentication credentials with a database of valid authentication credentials to determine whether the received authentication credentials match an entry in the database. Additionally, the authentication program 300 compares the obtained MAC address (of client device 110) with the stored (and encrypted) MAC address associated with the received authentication credentials (stored in the tracking database 142) to verify the requesting client device using the MAC address. In various embodiments, the authentication program 300 verifies the username and password combination and also verifies the MAC address of the device sending the username and password.
[0053] In decision step 310, the authentication program 300 determines whether the verification has passed. In one embodiment, the authentication program 300 determines whether the received authentication credentials (for the login request of step 304) and the MAC address of the requesting device (obtained in step 306) match the corresponding stored valid data. In response to determining that the user (using client device 110) has provided the correct authentication credentials, the authentication program 300 determines that the verification has passed (decision step 310, "yes" branch). In response to determining that the user (using client device 110) has provided incorrect authentication credentials, the authentication program 300 determines that the verification has not passed (decision step 310, "no" branch).
[0054] In step 312, the authentication program 300 authorizes access. More specifically, in response to determining that the verification has passed (decision step 310, "yes" branch), the authentication program 300 authorizes access to the requested asset / resource (step 312). In some embodiments, the authentication program 300 may track the authorized users and devices in the tracking database 142. In additional embodiments, the authentication program 300 may periodically obtain the MAC address of the connected client device to verify the identity of the accessing user and device. In another embodiment, the authentication program 300 may terminate in response to a user logout.
[0055] In step 314, the authentication program 300 restricts access. More specifically, in response to determining that the verification has not passed (decision step 314, "no" branch), the authentication program 300 restricts the access of the user attempting to access the asset / resource. In one embodiment, the authentication program 300 may block the user (and device) for which the MAC address authentication has failed and then end.
[0056] In another embodiment, in response to determining that the authentication has failed (decision step 314, "no" branch), the authentication program 300 may return to step 304 to allow subsequent authentication attempts. For example, the system may allow a limited number of failed login attempts (e.g., three times) for the username and password sharing authentication credentials (or potentially, also for MAC address verification) before performing access restriction actions on the user and / or device. In various embodiments, the authentication program 300 may take actions on the users and / or devices that fail authentication according to client preferences (e.g., the guidelines of the enterprise associated with the user and / or the protected resource / asset).
[0057] Figure 4 FIG. 400 depicts a computer system 400 according to an illustrative embodiment of the present invention, which represents client device 110, client device 120, shared ID management system 130, and authentication system 140. It should be understood that Figure 4 only an illustration of one implementation is provided, without implying any limitation on the environment in which different embodiments may be implemented. Many modifications may be made to the described environment. The computer system 400 includes one or more processors 401, cache 403, memory 402, permanent storage device 405, communication unit 407, one or more input / output (I / O) interfaces 406, and communication fabric 404. The communication fabric 404 provides communication between cache 403, memory 402, permanent storage device 405, communication unit 407, and one or more input / output (I / O) interfaces 406. The communication fabric 404 may be implemented with any architecture designed to transfer data and / or control information between processors (such as microprocessors, communication and network processors, etc.), system memory, peripherals, and any other hardware components within the system. For example, the communication fabric 404 may be implemented with one or more buses or crossbars.
[0058] Memory 402 and permanent storage device 405 are computer-readable storage media. In this embodiment, memory 402 includes random access memory (RAM). Generally, memory 402 may include any suitable volatile or non-volatile computer-readable storage media. Cache 403 is a fast memory that enhances the performance of processor 401 by storing recently accessed data and data near the recently accessed data.
[0059] Program instructions and data (e.g., software and data 410) for practicing embodiments of the present invention may be stored in the permanent storage device 405 and the memory 402 for execution by one or more corresponding processors 401 via the cache 403. In an embodiment, the permanent storage device 405 includes a magnetic hard disk drive. As an alternative or addition to the magnetic hard disk drive, the permanent storage device 405 may further include a solid state drive, a semiconductor storage device, a read only memory (ROM), an erasable programmable read only memory (EPROM), a flash memory, or any other computer-readable storage medium capable of storing program instructions or digital information.
[0060] The medium used by the permanent storage device 405 may also be removable. For example, a removable hard disk drive may be used for the permanent storage device 405. Other examples include optical discs and disks, thumb drives, and smart cards that are inserted into a drive for transfer onto another computer-readable storage medium that is also part of the permanent storage device 405. The software and data 410 may be stored in the permanent storage device 405 for access and / or execution by one or more corresponding processors 401 via the cache 403. For the client device 110, the software and data 410 includes the user interface 112 and the application 114. For the client device 120, the software and data 410 includes the user interface 122 and the application 124. For the shared ID management system 130, the software and data 410 includes the shared credential repository 132 and the management program 200. For the authentication system 140, the software and data 410 includes the tracking database 142 and the authentication program 300.
[0061] In these examples, the communication unit 407 provides communication with other data processing systems or devices. In these examples, the communication unit 407 includes one or more network interface cards. The communication unit 407 may provide communication by using physical and / or wireless communication links. Program instructions and data (e.g., software and data 410) for practicing embodiments of the present invention may be downloaded to the permanent storage device 405 via the communication unit 407.
[0062] (One or more) I / O interfaces 406 allow for the input and output of data with other devices that may be connected to each computer system. For example, (one or more) I / O interfaces 406 may provide a connection to (one or more) external devices 408 (such as a keyboard, keypad, touch screen, and / or some other suitable input device). (One or more) external devices 408 may also include portable computer-readable storage media, such as, for example, a thumb drive, a portable optical or magnetic disk, and a memory card. Program instructions and data (e.g., software and data 410) for practicing embodiments of the present invention may be stored on such portable computer-readable storage media and may be loaded onto the permanent storage device 405 via (one or more) I / O interfaces 406. (One or more) I / O interfaces 406 are also connected to a display 409.
[0063] The display 409 provides a mechanism for displaying data to a user and may be, for example, a computer monitor.
[0064] The programs described herein are identified based on the applications in which they are implemented in particular embodiments of the present invention. However, it should be understood that any specific program terms herein are used for convenience only, and thus the present invention should not be limited to use in any particular application identified and / or implied by such terms.
[0065] The present invention may be a system, method, and / or computer program product at any possible level of integration of technical details. The computer program product may include (one or more) computer-readable storage media having computer-readable program instructions thereon for causing a processor to perform aspects of the present invention.
[0066] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable storage medium can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing storage devices. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanical encoding device such as a punched card or raised structures in a groove having instructions recorded thereon, and any appropriate combination of the foregoing devices. As used herein, a computer-readable storage medium should not be construed as being a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0067] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or downloaded to an external computer or an external storage device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). The network can include a copper transmission cable, an optical transmission fiber, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the corresponding computing / processing device.
[0068] The computer-readable program instructions for performing the operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider via the Internet). In some embodiments, an electronic circuit, including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit so as to perform aspects of the present invention.
[0069] Aspects of the present invention are described herein with reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0070] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create a means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium, which may direct a computer, a programmable data processing apparatus, and / or other devices to operate in a particular manner, so that the computer-readable storage medium in which the instructions are stored comprises an article of manufacture, the article of manufacture including instructions for implementing aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0071] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices, causing a series of operational steps to be performed on the computer, other programmable apparatus, or other devices to produce a computer-implemented process, such that the instructions executed on the computer, other programmable apparatus, or other devices implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0072] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may not occur in the order noted in the figures. For example, two blocks shown in succession may in fact be executed substantially concurrently, or these blocks may sometimes be executed in the reverse order, depending on the functions involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or a combination of dedicated hardware and computer instructions.
[0073] The description of the various embodiments has been presented herein for purposes of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein were chosen to best explain the principles of the embodiments, the practical application, or the technical improvement over technologies found in the marketplace, or to enable other ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A method for managing authentication credentials, comprising: In response to a corresponding computing device checking out an authentication credential, updating usage information associated with the authentication credential with a media access control (MAC) address corresponding to the corresponding computing device by one or more processors; Receiving, by one or more processors, a login request including the authentication credential from a computing device; Obtaining, by one or more processors, the MAC address of the computing device that sent the login request; Verifying, by one or more processors, the authentication credential and the MAC address; After the corresponding computing device checks in the authentication credential, maintaining, by one or more processors, the MAC address corresponding to the corresponding computing device associated with the authentication credential until a second computing device checks out the authentication credential; And In response to the second computing device checking out the authentication credential, updating the usage information associated with the authentication credential with a second MAC address corresponding to the second computing device by one or more processors.
2. The method according to claim 1, further comprising: Authorizing, by one or more processors, access to the computing device in response to determining that verification of the authentication credential and the MAC address has passed.
3. The method according to claim 1, further comprising: Restricting, by one or more processors, access to the computing device in response to determining that verification of the authentication credential and the MAC address has failed.
4. The method according to claim 1, wherein, Updating the usage information associated with the authentication credential with the MAC address corresponding to the corresponding computing device further comprises: Encrypting, by one or more processors, the MAC address; and Storing, by one or more processors, the encrypted MAC address in the usage information, indicating that the use of the authentication credential is bound to the MAC address.
5. The method according to claim 1, wherein, The authentication credential is a shared authentication credential associated with multiple potential users.
6. The method according to claim 1, wherein Verifying the authentication credential and the MAC address further comprises: Determining, by one or more processors, whether the authentication credential matches information in a valid authentication credential database; and Determining, by one or more processors, whether the MAC address of the computing device that sent the login request obtained matches the MAC address in the usage information associated with the authentication credential.
7. The method according to claim 1, wherein Obtaining the MAC address of the computing device that sent the login request further comprises: Receiving, by one or more processors, information indicating the MAC address of the computing device that sent the login request through Secure Shell (SSH) protocol communication.
8. The method according to claim 3, wherein Restricting access to the computing device further comprises: Blocking, by one or more processors, the computing device in response to determining that the MAC address of the computing device that sent the login request obtained does not match the MAC address in the usage information associated with the authentication credential.
9. A computer program product, comprising: One or more computer-readable storage media and program instructions stored on the one or more computer-readable storage media, the program instructions comprising: Program instructions to update usage information associated with the authentication credential with the media access control (MAC) address corresponding to the corresponding computing device in response to the corresponding computing device checking out the authentication credential; Program instructions to receive a login request including the authentication credential from a computing device; Program instructions to obtain the MAC address of the computing device that sent the login request; Program instructions to verify the authentication credential and the MAC address; Program instructions to maintain the association between the MAC address corresponding to the corresponding computing device and the authentication credential until a second computing device checks out the authentication credential after the corresponding computing device checks in the authentication credential; and Program instructions to update the usage information associated with the authentication credential with a second MAC address corresponding to the second computing device in response to the second computing device checking out the authentication credential.
10. The computer program product according to claim 9 further comprises: Program instructions stored on the one or more computer-readable storage media to: Authorize access to the computing device in response to determining that verification of the authentication credential and the MAC address has passed.
11. The computer program product according to claim 9, further comprising: Program instructions stored on the one or more computer-readable storage media to: Restrict access to the computing device in response to determining that verification of the authentication credential and the MAC address has failed.
12. The computer program product according to claim 9, wherein, The program instructions to update the usage information associated with the authentication credential with the MAC address corresponding to the corresponding computing device further include program instructions for: Encrypting the MAC address; and Storing the encrypted MAC address in the usage information, indicating that the use of the authentication credential is bound to the MAC address.
13. The computer program product according to claim 9, wherein, The authentication credential is a shared authentication credential associated with multiple potential users.
14. The computer program product according to claim 9, wherein, The program instructions to verify the authentication credential and the MAC address further include program instructions for: Determining whether the authentication credential matches information in a valid authentication credential database; and Determining whether the MAC address of the computing device that sent the login request obtained matches the MAC address in the usage information associated with the authentication credential.
15. A computer system, comprising: One or more computer processors; One or more computer-readable storage media; And Program instructions stored on the computer-readable storage media for execution by at least one of the one or more processors, the program instructions including: Program instructions to update usage information associated with the authentication credential with the media access control (MAC) address corresponding to the corresponding computing device in response to the corresponding computing device checking out the authentication credential; Program instructions to receive a login request including the authentication credential from a computing device; Program instructions to obtain the MAC address of the computing device that sent the login request; Program instructions to verify the authentication credential and the MAC address; Program instructions to maintain the association between the MAC address corresponding to the corresponding computing device and the authentication credential until a second computing device checks out the authentication credential after the corresponding computing device checks in the authentication credential; and Program instructions for updating the usage information associated with the authentication credential with a second MAC address corresponding to the second computing device in response to the second computing device checking out the authentication credential.
16. The computer system according to claim 15, further comprising: Program instructions stored on the computer-readable storage medium for execution by at least one of the one or more processors to: Authorize access by the computing device in response to determining that verification of the authentication credential and the MAC address has passed.
17. The computer system according to claim 15, further comprising: Program instructions stored on the computer-readable storage medium for execution by at least one of the one or more processors to: Restrict access by the computing device in response to determining that verification of the authentication credential and the MAC address has failed.
18. The computer system according to claim 15, wherein, The program instructions for updating the usage information associated with the authentication credential with the MAC address corresponding to the respective computing device further include program instructions for: Encrypting the MAC address; and Storing the encrypted MAC address in the usage information, indicating that the use of the authentication credential is bound to the MAC address.
19. The computer system according to claim 15, wherein, The authentication credential is a shared authentication credential associated with multiple potential users.
20. The computer system according to claim 15, wherein, The program instructions for verifying the authentication credential and the MAC address further include program instructions for: Determining whether the authentication credential matches information in a valid authentication credential database; and Determining whether the MAC address of the computing device that sent the login request matches the MAC address in the usage information associated with the authentication credential.
Citation Information
Patent Citations
System and method for providing access credentials
CN103503408A
Device credentials management
CN110463164A