Invention Grant
- Patent Title: Access control by testing for shared knowledge
- Patent Title (中): 通过测试获取共享知识的访问控制
-
Application No.: US12466242Application Date: 2009-05-14
-
Publication No.: US08387122B2Publication Date: 2013-02-26
- Inventor: Michael Toomim , James Fogarty , James Landay , Nathan Morris , Xianhang Zhang , Tadayoshi Kohno
- Applicant: Michael Toomim , James Fogarty , James Landay , Nathan Morris , Xianhang Zhang , Tadayoshi Kohno
- Applicant Address: US WA Seattle
- Assignee: University of Washington
- Current Assignee: University of Washington
- Current Assignee Address: US WA Seattle
- Agency: Kilpatrick Townsend and Stockton LLP
- Main IPC: H04L9/00
- IPC: H04L9/00 ; G06F21/00

Abstract:
Access to resource(s) intended to be shared with specific groups of individuals is controlled using concise tests of shared knowledge instead of (or in addition) to accounts and access control lists. Users can readily learn the concept and choose questions that will control the access by the desired group with little effort. Such questions can be relatively secure to guesses by those not intended to have access, particularly if the number of allowed guesses is relatively limited. Users can generally predict the security of their questions, but sometimes underestimate the ability of attackers to use Web searching or enumeration to discover answers. In such cases, the system can automatically discover weak questions and then suggest alternatives. By lowering the threshold to access control, shared knowledge tests can enable more types of information to acquire collaborative value on the Internet and on other types of networks.
Public/Granted literature
- US20090288150A1 ACCESS CONTROL BY TESTING FOR SHARED KNOWLEDGE Public/Granted day:2009-11-19
Information query