Protecting against malicious discovery of account existence
A sign-in system can be protected against enumeration attacks while providing an improved sign-in experience for legitimate users by disclosing whether or not an account exists. An account within a specified domain can be identified by an account identifier such as a username. Before a threshold thr...
Saved in:
Main Authors | , |
---|---|
Format | Patent |
Language | English |
Published |
21.04.2020
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Summary: | A sign-in system can be protected against enumeration attacks while providing an improved sign-in experience for legitimate users by disclosing whether or not an account exists. An account within a specified domain can be identified by an account identifier such as a username. Before a threshold throttling value is reached, account existence/non-existence information can be provided in response to an access request. In response to reaching or exceeding a specified threshold throttling value, account existence/non-existence information can cease to be provided. Entering a valid account identifier/authenticating credential credentials pair provides access to the computer system regardless of whether or not the threshold was reached or exceeded or not reached. |
---|---|
Bibliography: | Application Number: US201715822065 |