NETWORK ENTRIE FOR MANAGING A USER'S PASSWORD
The network entity with a data diode segregates security domains to securely transmit and manage user passwords as hash values, addressing data leak and update challenges in current systems.
Patent Information
- Application Number
- DE102017121497
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2017-09-15
- Publication Date
- 2025-05-08
- Estimated Expiration
- 2037-09-15
AI Technical Summary
Current password management systems face challenges in securely transmitting and updating passwords, particularly in preventing data leaks and dictionary/brute force attacks, due to the lack of standardized cryptographic protection mechanisms and high implementation complexity.
A network entity comprising a front-end server, a data diode, and a back-end server, where the data diode segregates the communication network into two security domains, allowing secure transmission and storage of passwords as hash values, enabling automated updates without requiring plaintext passwords.
This solution effectively prevents data leaks and allows for secure password management and authentication, reducing the risk of attacks and enabling efficient automated updates of cryptographic hash functions.
Smart Images

Figure 00000009_0000 
Figure 00000010_0000 
Figure 00000011_0000
Abstract
Description
[0001] The present invention relates to the field of password management.
[0002] Disclosure US 2007 / 0182983 A1 discloses a concept for the secure transmission of an electronic document between a first security domain, which has low security requirements, and a second security domain, which has high security requirements.
[0003] The publication “SCHNEIER B.: “Applied Cryptography, second edition, Protocols, Algorithms, and Source Code in C”, John Wiley & Sons, 1996, pages: TitlePage, i-xxv, 47-74” reveals the use of a salt for the cryptographic protection of passwords.
[0004] The published patent application DE 10 2015 211 566 A1 discloses a method for determining a derived key from a key and a derivation parameter, in which a puzzle to be solved is first determined using the key and / or the derivation parameter before the derived key is calculated from the solution of the puzzle and the key and / or the derivation parameter.
[0005] User passwords can be stored in a database in a variety of ways, for example, in a cryptographically secured format using hash values and salts. Hash values or salts are often not used in password management because approaches to updating cryptographic protection mechanisms are currently not standardized and therefore involve significant implementation effort.
[0006] In the event of a database data leak, the passwords or hash values are typically exposed to dictionary attacks or brute-force attacks. The chances of success for potential attackers can increase, for example, if new weaknesses are discovered in the cryptographic hash functions used.
[0007] Updating the cryptographic hash function typically requires all user passwords to be made available again in plaintext before the update. The new cryptographic hash function is then applied to each newly available password in plaintext, for example, when a user logs in again. This complete update is time-consuming and not always feasible. In particular, the password database is especially vulnerable during this period.
[0008] It is therefore an object of the present invention to create an efficient concept for managing a user's password.
[0009] These and other tasks are solved by the features of the independent claims. Advantageous further development methods are the subject of the dependent patent claims, the description, and the drawings.
[0010] The invention is based on the finding that the above problem can be solved by a network entity in a communication network comprising a front-end server, a data diode, and a back-end server, with the data diode being located between the front-end and back-end servers. A user's password is received by the front-end server via the communication network and transmitted via the data diode to the back-end server, which stores the password cryptographically in the form of a hash value. The data diode effectively prevents data leaks in the back-end server and ensures that the password hash value is not directly accessible via the communication network. The front-end server can be assigned to a first security domain with low security requirements, and the back-end server can be assigned to a second security domain with high security requirements.
[0011] The backend server can also update the password hash value by applying another cryptographic hash function to the already stored hash value and replacing it. Consequently, there is no need to re-provide the password, and the cryptographic hash functions used can be updated automatically.
[0012] For subsequent user authentication via the communication network, the frontend server can receive a comparison password over the network and transmit it to the backend server via the data diode. The backend server can then determine a comparison hash value of the comparison password and compare it to the stored hash value to authenticate the user. An authentication indicator, which signals successful user authentication, can then be transmitted back to the frontend server via a return channel of the data diode. Therefore, the network entity can be used to authenticate the user over the communication network, with the cryptographic hash functions being applied by the backend server in a secure environment behind the data diode.
[0013] This concept can be used to manage multiple passwords for multiple users. Furthermore, user authentication via the communication network can be efficiently implemented.
[0014] According to a first aspect, the invention relates to a network entity for managing a user's password. The network entity comprises a front-end server configured to receive a communication message containing the password via a communication network, extract the password from the communication message, and transmit the password via a first data connection. The network entity further comprises a data diode configured to forward the password via a forward channel of the data diode, wherein the data diode is configured to receive the password via the first data connection and transmit the password via a second data connection.The network entity further includes a backend server, which is configured to receive the password via the second data connection, apply a cryptographic hash function to the password to obtain a hash value of the password, and store the hash value of the password to manage the user's password.
[0015] The data diode is generally designed to allow the transmission of any data in one main direction and to block or restrict the transmission of any data in the opposite direction. In this case, the forward channel serves specifically for the unidirectional transmission of the password in the main direction, whereby the password is received via the first data connection and transmitted via the second data connection. The forward channel of the data diode can be configured to transmit only the password and, optionally, a backup password.
[0016] According to one embodiment, the backend server comprises a database, wherein the database is configured to store the hash value of the password. This ensures that the hash value of the password can be stored and managed efficiently.
[0017] According to one embodiment, the cryptographic hash function is one of the following: Password-Based Key Derivation Function 1 (PBKDF1), Password-Based Key Derivation Function 2 (PBKDF2), Keyed-Hash Message Authentication Code (HMAC), or Argon2. In particular, HMAC-SHA256 can be used as the Keyed-Hash Message Authentication Code (HMAC). This allows the cryptographic hash function to be implemented efficiently.
[0018] According to one embodiment, the backend server is configured to apply another cryptographic hash function to the password hash value to obtain a further hash value of the password and to replace the original hash value with this further hash value. This eliminates the need to re-provide the password when the cryptographic hash function is updated.
[0019] According to one embodiment, the additional cryptographic hash function is one of the following: Password-Based Key Derivation Function 1 (PBKDF1), Password-Based Key Derivation Function 2 (PBKDF2), Keyed-Hash Message Authentication Code (HMAC), or Argon2. In particular, an HMAC-SHA256 can be used as the Keyed-Hash Message Authentication Code (HMAC).
[0020] This ensures that the additional cryptographic hash function used can be implemented efficiently.
[0021] According to one embodiment, the cryptographic hash function and the additional cryptographic hash function are different. This enables efficient automated updating of the hash functions used. In particular, the additional cryptographic hash function can be a newly developed cryptographic hash function that, for example, exhibits improved resistance to cryptographic attacks.
[0022] According to one embodiment, the front-end server is configured to receive a further communication message containing a comparison password via the communication network, to extract the comparison password from the further communication message, and to transmit the comparison password via the first data connection, wherein the data diode is configured to forward the comparison password via the forward channel of the data diode, wherein the data diode is configured to receive the comparison password via the first data connection and to transmit the comparison password via the second data connection, and wherein the back-end server is configured to receive the comparison password via the second data connection, to apply the cryptographic hash function to the comparison password in order to obtain a comparison hash value of the comparison password, and to compare the hash value of the password with the comparison hash value of the comparison password.and to generate an authentication indicator if the hash value matches the comparison hash value. This ensures that efficient user authentication can be implemented in a secure environment behind the data diode by the backend server.
[0023] According to one embodiment, the backend server is configured to apply the additional cryptographic hash function to the comparison hash value of the comparison password in order to obtain another comparison hash value of the comparison password, and to replace the comparison hash value with this additional comparison hash value. This enables user authentication after an update of the hash functions used.
[0024] According to one embodiment, the backend server is configured to transmit the authentication indicator via the second data connection, the data diode is configured to forward the authentication indicator via a return channel of the data diode, the data diode is configured to receive the authentication indicator via the second data connection and transmit the authentication indicator via the first data connection, and the frontend server is configured to receive the authentication indicator via the first data connection. This ensures that user authentication can be signaled efficiently.
[0025] The reverse channel serves, in particular, for the unidirectional forwarding of the authentication indicator in the opposite direction, whereby the authentication indicator is received via the second data connection and transmitted via the first data connection. The reverse channel of the data diode can be configured to forward only the authentication indicator.
[0026] According to one embodiment, the data diode is configured not to transmit the password hash value via its return channel. The return channel is therefore blocked for the password hash value. This ensures that the password hash value is not accessible via the communication network.
[0027] According to one embodiment, the backend server includes a cryptographic coprocessor configured to apply the cryptographic hash function. This ensures that the cryptographic hash function can be applied efficiently.
[0028] According to one embodiment, the cryptographic coprocessor is further configured to apply the additional cryptographic hash function. This ensures that the additional cryptographic hash function can be applied efficiently.
[0029] According to one embodiment, the front-end server is assigned to a first security domain, while the back-end server is assigned to a second security domain. The first security domain may, for example, have lower security requirements than the second security domain. This allows the data diode to efficiently separate the two security domains.
[0030] According to a second aspect, the invention relates to an arrangement for managing a user's password. The arrangement comprises a network entity according to the first aspect of the invention, and another network entity according to the first aspect of the invention, wherein the front-end server of the network entity and the other front-end server of the other network entity are connected to each other via the communication network.
[0031] According to one embodiment, the frontend server of the network entity is configured to forward the communication message containing the password to the other frontend server of the other network entity via the communication network. This ensures that the communication message containing the password can be processed by both the network entity and the other network entity, and consequently, the hash value of the password can be stored redundantly in both network entities.
[0032] According to a third aspect, the invention relates to a method for managing a user's password by means of a network entity, wherein the network entity comprises a frontend server, a data diode and a backend server, and wherein the data diode is configured to forward the password via a forward channel of the data diode.The process involves the frontend server receiving a communication message containing the password via a communication network, the frontend server extracting the password from the communication message, the frontend server sending the password via a first data connection, the data diode receiving the password via the first data connection, the data diode sending the password via a second data connection, the backend server receiving the password via the second data connection, the backend server applying a cryptographic hash function to the password to obtain a hash value of the password, and the backend server storing the hash value of the password to manage the user's password.
[0033] The process can be executed by the network entity. Further features of the process result directly from the features or functionality of the network entity.
[0034] According to a fourth aspect, the invention relates to a computer program with program code for executing the method according to the third aspect of the invention.
[0035] Further embodiments of the invention are explained in more detail with reference to the accompanying drawings. These show: Fig. 1. A schematic diagram of a network entity for managing a user's password; Fig. 2. A schematic diagram of an arrangement for managing a user's password; Fig. 3. A schematic diagram of a procedure for managing a user's password; and Fig. 4 A schematic diagram of a data diode for forwarding a password via a forward channel of the data diode.
[0036] Fig. Figure 1 shows a schematic diagram of a network entity 100 for managing a user's password. The network entity 100 comprises a front-end server 101, which is configured to receive a communication message containing the password via a communication network, extract the password from the communication message, and transmit the password via a first data connection. The network entity 100 further comprises a data diode 103, which is configured to forward the password via a forward channel of the data diode 103, wherein the data diode 103 is configured to receive the password via the first data connection and transmit the password via a second data connection.The network entity 100 further comprises a backend server 105 configured to receive the password via the second data connection, apply a cryptographic hash function to the password to obtain a hash value of the password, and store the hash value of the password to manage the user's password.
[0037] The backend server 105 may include a database 107, wherein the database 107 is configured to store the hash value of the password. The database 107 may be implemented, for example, using a redundant array of independent disks (RAID) to increase the robustness of the database 107.
[0038] The backend server 105 can be configured to apply another cryptographic hash function to the password hash value to obtain a further hash value of the password, and then replace the original hash value with this additional hash value. This allows for the creation of a chain of hash values. Thus, the password hash value, or the password itself, can remain protected should a weakness in the cryptographic hash function be discovered.
[0039] The backend server 105 may further include a cryptographic coprocessor 109, which is configured to apply the cryptographic hash function and / or the additional cryptographic hash function. The backend server 105 may include additional cryptographic coprocessors to accelerate the application of the cryptographic hash function and / or the additional cryptographic hash function.
[0040] Network entity 100 enables automated updates of the hash functions used, whereby the additional cryptographic hash function can be implemented, for example, by means of a secure update function in the backend server 105 or in the cryptographic coprocessor 109. By using the data diode 103 between the frontend server 101 and the backend server 105, the password hash value can be stored in the database 107, effectively preventing data leaks from the database 107.
[0041] Updating the functionality of frontend server 101 can be performed online via the communication network, with the frontend server 101 verifying the signature of the update information beforehand. Updating the functionality of backend server 105 may require physical access to the backend server 105, with the update information being transferred to the backend server 105 using a USB storage device, and the backend server 105 verifying the signature of the update information beforehand. The USB storage device can then be securely erased.
[0042] Communication between a user's client and the Frontend Server 101 via the communication network can, for example, take place using a communication connection protected by Transport Layer Security (TLS). This communication can be achieved using various communication protocols, such as Lightweight Directory Access Protocol (LDAP). The Frontend Server 101 can employ full disk encryption (FDE).
[0043] Fig. Figure 2 shows a schematic diagram of an arrangement 200 for managing a user's password. The arrangement 200 comprises a network entity 100 and another network entity 100a, where the network entity 100 and the other network entity 100a are each defined according to Fig. 1 are trained. Network entity 100 comprises a frontend server 101, a data diode 103, and a backend server 105 with a database 107 and a cryptographic coprocessor 109. Further network entity 100a comprises another frontend server 101a, another data diode 103a, and another backend server 105a with another database 107a and another cryptographic coprocessor 109a.
[0044] Frontend server 101 of network entity 100 and the other frontend server 101a of network entity 100a are connected via a communication network. Frontend server 101 of network entity 100 is configured to forward the communication message containing the password to the other frontend server 101a of network entity 100a via the communication network.
[0045] The configuration 200 enables high availability (HA) of the password management. Network entity 100 and network entity 100a can each exchange Transport Layer Security (TLS) certificates beforehand to authenticate each other using cryptographic key or fingerprint verification.
[0046] Fig. Figure 3 shows a schematic diagram of a method 300 for managing a user's password by means of a network entity, wherein the network entity comprises a frontend server, a data diode and a backend server, and wherein the data diode is configured to forward the password via a forward channel of the data diode.
[0047] The procedure 300 comprises receiving 301 a communication message containing the password via a communication network by the frontend server, extracting 303 the password from the communication message by the frontend server, transmitting 305 the password via a first data connection by the frontend server, receiving 307 the password via the first data connection by the data diode, transmitting 309 the password via a second data connection by the data diode, receiving 311 the password via the second data connection by the backend server, applying 313 a cryptographic hash function to the password by the backend server to obtain a hash value of the password, and storing 315 the hash value of the password by the backend server to manage the user's password.
[0048] Fig.Figure 4 shows a schematic diagram of a data diode 103 for forwarding a password via a forward channel of the data diode 103. The data diode 103 comprises a memory 401 with a first memory area 401a and a second memory area 401b. The data diode 103 further comprises a first data interface 403, which is configured to receive a password via a first data connection and to store the password in the first memory area 401a. The data diode 103 further comprises a filter element 405, which is configured to read the password from the first memory area 401a and to store the password in the second memory area 401b. The data diode 103 further comprises a second data interface 407, which is configured to read the password from the second memory area 401b and to transmit the password via a second data connection.The data diode 103 can be configured to transmit only the password via the forward channel.
[0049] Accordingly, data diode 103 can be configured to forward a comparison password via its forward channel. The first data interface 403 can be configured to receive the comparison password via the first data connection and store it in the first memory area 401a. Filter element 405 can be configured to read the comparison password from the first memory area 401a and store it in the second memory area 401b. The second data interface 407 can be configured to read the comparison password from the second memory area 401b and transmit it via the second data connection. Data diode 103 can also be configured to forward only the password and the comparison password via its forward channel.
[0050] In order to implement a return channel of the data diode 103 for forwarding an authentication indicator, the memory 401 can further comprise a third memory area (not shown) and a fourth memory area (not shown). The second data interface 407 can be configured to receive the authentication indicator via the second data connection and to store the authentication indicator in the third memory area. The filter element 405 can be configured to read the authentication indicator from the third memory area and store it in the fourth memory area. The first data interface 403 can be configured to read the authentication indicator from the fourth memory area and transmit it via the first data connection. The data diode 103 can be configured to forward exclusively the authentication indicator via the return channel.
[0051] Filter element 405 is therefore designed to control the forwarding of the password and / or the authentication indicator via data diode 103. In particular, filter element 405 can be designed to effectively prevent the forwarding of a password hash value via the return channel of data diode 103.
[0052] All features shown or described in connection with individual embodiments of the invention can be provided in any combination in the object according to the invention in order to simultaneously realize their advantageous effects. LIST OF REFERENCE SYMBOLS 100 network entity 101 Frontend Servers 103 Data diode 105 backend servers 107 Database 109 Cryptographic Coprocessor 100a Another network entity 101a Additional Frontend Server 103a Additional data diode 105a Additional backend server 107a Further database 109a Additional cryptographic coprocessor 200 arrangement 300 methods for managing a user's password 301 Received 303 Extract 305 Send 307 Received 309 Send 311 Received 313 Apply 315 Save 401 storage 401a First memory area 401b Second memory area 403 First data interface 405 Filter element 407 Second data interface
Claims
[1] Network entity (100) for managing a user’s password, comprising: a front-end server (101) which is designed to receive a communication message with the password via a communication network, to extract the password from the communication message, and to send the password via a first data connection; a data diode (103) configured to forward the password via a forward channel of the data diode (103), wherein the data diode (103) is configured to receive the password via the first data connection and to transmit the password via a second data connection; and a backend server (105) configured to receive the password via the second data connection, apply a cryptographic hash function to the password to obtain a hash value of the password, and store the hash value of the password to manage the user's password. [2] Network entity (100) according to claim 1, wherein the backend server (105) comprises a database (107), wherein the database (107) is configured to store the hash value of the password. [3] Network entity (100) according to one of the preceding claims, wherein the cryptographic hash function is one of the following cryptographic hash functions: Password-Based Key Derivation Function 1 (PBKDF1), Password-Based Key Derivation Function 2 (PBKDF2), Keyed-Hash Message Authentication Code (HMAC), or Argon2. [4] Network entity (100) according to one of the preceding claims, wherein the backend server (105) is configured to apply a further cryptographic hash function to the hash value of the password in order to obtain a further hash value of the password, and to replace the hash value with the further hash value. [5] The network entity (100) of claim 4, wherein the further cryptographic hash function is one of the following further cryptographic hash functions: Password-Based Key Derivation Function 1 (PBKDF1), Password-Based Key Derivation Function 2 (PBKDF2), Keyed-Hash Message Authentication Code (HMAC), or Argon2. [6] Network entity (100) according to one of claims 4 or 5, wherein the cryptographic hash function and the further cryptographic hash function are different. [7] Network entity (100) according to one of the preceding claims, wherein the front-end server (101) is configured to receive a further communication message with a comparison password via the communication network, to extract the comparison password from the further communication message, and to transmit the comparison password via the first data connection, wherein the data diode (103) is configured to forward the comparison password via the forward channel of the data diode (103), wherein the data diode (103) is configured to receive the comparison password via the first data connection and to transmit the comparison password via the second data connection, and wherein the back-end server (105) is configured to receive the comparison password via the second data connection, to apply the cryptographic hash function to the comparison password to obtain a comparison hash value of the comparison password,to compare the hash value of the password with the comparison hash value of the comparison password, and to generate an authentication indicator if the hash value matches the comparison hash value. [8] Network entity (100) according to claim 7, wherein the backend server (105) is configured to transmit the authentication indicator via the second data connection, wherein the data diode (103) is configured to forward the authentication indicator via a return channel of the data diode (103), wherein the data diode (103) is configured to receive the authentication indicator via the second data connection and to transmit the authentication indicator via the first data connection, and wherein the frontend server (101) is configured to receive the authentication indicator via the first data connection. [9] Network entity (100) according to claim 8, wherein the data diode (103) is configured not to forward the hash value of the password via the return channel of the data diode (103). [10] Network entity (100) according to one of the preceding claims, wherein the backend server (105) comprises a cryptographic coprocessor (109) which is configured to apply the cryptographic hash function. [11] Network entity (100) according to one of the preceding claims, wherein the frontend server (101) is associated with a first security domain, and wherein the backend server (105) is associated with a second security domain. [12] Arrangement (200) for managing a user’s password, comprising: a network entity (100) according to one of claims 1 to 11; and a further network entity (100a) according to one of claims 1 to 11; wherein the frontend server (101) of the network entity (100) and the further frontend server (101a) of the further network entity (100a) are connected to one another via the communication network. [13] Arrangement (200) according to claim 12, wherein the front-end server (101) of the network entity (100) is designed to forward the communication message with the password to the further front-end server (101a) of the further network entity (100a) via the communication network. [14] Method (300) for managing a user's password by means of a network entity (100), wherein the network entity (100) comprises a front-end server (101), a data diode (103) and a back-end server (105), wherein the data diode (103) is designed to forward the password via a forward channel of the data diode (103), comprising: Receiving (301) a communication message with the password via a communication network by the frontend server (101); Extracting (303) the password from the communication message by the frontend server (101); Sending (305) the password via a first data connection by the frontend server (101); Receiving (307) the password via the first data connection by the data diode (103); Sending (309) the password via a second data connection through the data diode (103); Receiving (311) the password via the second data connection by the backend server (105); applying (313) a cryptographic hash function to the password by the backend server (105) to obtain a hash value of the password; and Storing (315) the hash value of the password by the backend server (105) in order to manage the user's password. [15] Computer program with a program code for carrying out the method (300) according to claim 14.
Citation Information
Patent Citations
Method, component, and computer program product for determining a derived key
DE102015211566A1
Threat mitigation in computer networks
US20070182983A1