최소 단어 이상 선택하여야 합니다.
최대 10 단어까지만 선택 가능합니다.
다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
NTIS 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
DataON 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
Edison 바로가기다음과 같은 기능을 한번의 로그인으로 사용 할 수 있습니다.
Kafe 바로가기국가/구분 | United States(US) Patent 등록 |
---|---|
국제특허분류(IPC7판) |
|
출원번호 | US-0360100 (2009-01-26) |
등록번호 | US-8321682 (2012-11-27) |
발명자 / 주소 |
|
출원인 / 주소 |
|
대리인 / 주소 |
|
인용정보 | 피인용 횟수 : 5 인용 특허 : 549 |
A password management system and method for securing networked client terminals and mobile devices is provided. More specifically, the present invention provides a system and method for encrypting randomly generated administrator-level passwords and providing a means for decrypting the randomly gene
A password management system and method for securing networked client terminals and mobile devices is provided. More specifically, the present invention provides a system and method for encrypting randomly generated administrator-level passwords and providing a means for decrypting the randomly generated passwords for single-use unrestricted access to a designated terminal or mobile device. When unrestricted access to the terminal or mobile device is required, the encrypted administrator-level password is decrypted using a shared symmetric key, which is generated during encryption of the administrator password, to reveal the administrator-level password for the terminal or mobile device. The administrator-level password is a single-use password, wherein upon use of the administrator-level password a new administrator-level password may be automatically generated for the corresponding terminal or mobile device.
1. A computer-implemented method for securing access to a networked user computer, said method comprising: generating a random string of characters representative of a first administrator-level password, wherein said first administrator-level password is unique to said networked user computer;encryp
1. A computer-implemented method for securing access to a networked user computer, said method comprising: generating a random string of characters representative of a first administrator-level password, wherein said first administrator-level password is unique to said networked user computer;encrypting said first administrator-level password using a symmetric key, wherein said encrypted first administrator-level password generates a first breakglass string;storing said first breakglass string in association with said networked user computer for which said encrypted first administrator-level password was created; andupon decryption of said first breakglass string, generating a second administrator-level password for encryption into a second breakglass string of characters. 2. The computer-implemented method of claim 1, wherein said networked user computer is a hardware workstation terminal or mobile device. 3. The computer-implemented method of claim 1, wherein encrypting said first administrator-level password using said symmetric key further comprises: identifying said networked user computer for which said first administrator-level password was created;generating a public key and a private key associated with said networked user computer;retrieving a server public key associated with said networked user computer; andgenerating said symmetric key using said private key and said retrieved server public key. 4. A computer-implemented method for obtaining access to a secured network user computer, said method comprising: retrieving an encrypted first administrator-level password, wherein said encrypted administrator-level password is represented by a first breakglass string unique to said secured network user computer;decrypting said first breakglass string using a symmetric key; andrevealing said first administrator-level password for obtaining unrestricted access to said secured network user computer, wherein upon decryption of said first administrator-level password, a second administrator-level password for encryption into a second breakglass string is generated. 5. The computer-implemented method of claim 4, wherein retrieving said encrypted administrator-level password further comprises the steps of: accessing a secure network database, said secure network database configured to store an encrypted administrator-level password for a plurality of secured network user computers; andquerying said secure network database for said encrypted first administrator-level password corresponding to said unique system identifier for said secured network user computer to which unrestricted access is desired. 6. The computer-implemented method of claim 4, wherein decrypting said first breakglass string using said symmetric key further comprises the steps of: retrieving a unique system identifier for said secured network user computer;deriving a public key, wherein said public key is derived from said first breakglass string;retrieving a server private key associated with said networked user computer; andgenerating said symmetric key using said derived public key and said retrieved server private key. 7. The computer-implemented method of claim 4, wherein upon use of said first administrator-level password for obtaining unrestricted access to said secured network user computer, said first administrator-level password is rendered obsolete for future use. 8. The computer-implemented method of claim 4, wherein activities corresponding to said encrypted first administrator-level password are logged to maintain an audit trail. 9. A computer-implemented method for securing access to a networked workstation, said method comprising the steps of: providing at least one client terminal employing a random password management agent, said random password management agent being configured to generate a random string of characters representative of a first administrator-level password, and further being configured to encrypt said first administrator-level password using a shared symmetric key to generate a first breakglass string of characters;providing at least one database server configured to store said first breakglass string of characters in association with a client terminal for which the first administrator-level password was encrypted; andproviding at least one controller terminal employing a random password recovery system application, said random password recovery system application retrieving said first breakglass string of characters and deriving said symmetric key to decrypt said first breakglass string of characters and reveal said first administrator-level password;wherein upon decryption of said first administrator-level password, said random password management agent employed by said client terminal is configured to generate a second administrator-level password for encryption into a second breakglass string of characters and render said first administrator-level password obsolete.
Copyright KISTI. All Rights Reserved.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.