Protecting against malicious discovery of account existence

A sign-in system can be protected against enumeration attacks while providing an improved sign-in experience for legitimate users by disclosing whether or not an account exists. An account within a specified domain can be identified by an account identifier such as a username. Before a threshold thr...

Full description

Saved in:
Bibliographic Details
Main Authors Larson, Timothy Colin, Gordon, Ariel
Format Patent
LanguageEnglish
Published 21.04.2020
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:A sign-in system can be protected against enumeration attacks while providing an improved sign-in experience for legitimate users by disclosing whether or not an account exists. An account within a specified domain can be identified by an account identifier such as a username. Before a threshold throttling value is reached, account existence/non-existence information can be provided in response to an access request. In response to reaching or exceeding a specified threshold throttling value, account existence/non-existence information can cease to be provided. Entering a valid account identifier/authenticating credential credentials pair provides access to the computer system regardless of whether or not the threshold was reached or exceeded or not reached.
Bibliography:Application Number: US201715822065