×

EFFICIENTLY THROTTLING USER AUTHENTICATION

  • US 20130198819A1
  • Filed: 02/01/2012
  • Published: 08/01/2013
  • Est. Priority Date: 02/01/2012
  • Status: Active Grant
First Claim
Patent Images

1. At an authentication server computer system including at least one processor and a memory, in a computer networking environment including a plurality of computing systems, a computer-implemented method for efficiently authenticating users while preventing enumeration attacks, the method comprising:

  • an act of receiving user login credentials from a user, the user login credentials including a user identifier and a password;

    an act of making at least one of the following determinations;

    determining that the user identifier does not match any existing user account;

    determining that the user identifier matches at least one existing user account, but the user'"'"'s account is in a locked state; and

    determining that the user identifier matches at least one existing user account, but the user'"'"'s password does not match the user identifier; and

    an act of returning to the user the same response message regardless of which determination is made, the response message indicating that the user'"'"'s login credentials are invalid, wherein the response message prevents the user from determining which of the credentials was invalid, as the response message is the same for each determination and is sent to the user after a measured response time that is the same for each determination.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×