Smart random password generation

US10055575B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10055575-B2
Application numberUS-201615135849-A
CountryUS
Kind codeB2
Filing dateApr 22, 2016
Priority dateApr 22, 2016
Publication dateAug 21, 2018
Grant dateAug 21, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for generating a password for accessing a password-protected service is disclosed. A password requirements database and default password generation requirements are stored in a memory of a computing device. The password requirements database includes one or more service profiles, where each service profile includes an identifier for a service and an associated indication of requirements of valid passwords for the service. If the password requirements database includes a service profile associated with the password-protected service, the password is randomly generated to comply with requirements of valid passwords indicated in the service profile associated with the password-protected service; otherwise, the password is randomly generated to comply with the default password generation requirements.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for generating a password, the method comprising: storing information pertaining to one or more password requirements and one or more default password generation requirements, the information pertaining to one or more password requirements including one or more service profiles, each of the one or more service profiles including an identifier for a service and an associated indication of one or more requirements of a valid password for the service; determining an identity of a password-protected first service based on contextual data associated with the first service that is received at a computing device; in response to determining that the one or more password requirements include a service profile associated with the first service: determining whether the one or more password requirements indicated in the service profile associated with the first service are up-to-date; in response to determining that the one or more password requirements are not up-to-date, sending a request to a remote resource associated with the first service to transmit current password requirements for the first service to the computing device; and randomly generating, by a processor of the computing device, a password to comply with the current password requirements for the first service as received from the remote resource. 2. The method of claim 1 , further comprising, if the one or more password requirements does not include a service profile associated with the first service: generating a new service profile for the password-protected service based on the identifying information; and storing the generated new service profile as part of the information pertaining to one or more password requirements. 3. The method of claim 2 , further comprising: polling one or more remote resources to obtain current requirements of valid passwords for services associated with at least one of the service profiles; and updating the information pertaining to one or more password requirements to indicate the current requirements of valid passwords for the services associated with the at least one of the service profiles. 4. The method of claim 3 , wherein the one or more remote resources are polled periodically. 5. The method of claim 3 , further comprising, prior to polling the one or more remote resources, establishing secure connections to the one or more remote resources by verifying digital certificates associated with the one or more remote resources. 6. The method of claim 1 , wherein requirements of valid passwords for a service comprise one or more rules relating to at least one of: password length; presence of specific types of characters in a password; perceived password strength; prohibited elements in a password; or user password history. 7. The method of claim 1 , wherein randomly generating the password comprises generating the password based, at least in part, on user-defined criteria. 8. The method of claim 1 , further comprising transmitting the generated password to the password-protected service to register the generated password. 9. The method of claim 1 , further comprising receiving an input instruction via a user interface to generate the password and wherein generating the password is performed in response to receiving the input instruction. 10. An electronic device, comprising: an input interface; a memory; a processor coupled to the input interface and the memory; and a password manager for generating a password, the password manager including processor-executable instructions that, when executed, cause the processor to: store, information pertaining to one or more password requirements and one or more default password generation requirements, the information pertaining to one or more password requirements including one or more service profiles, each of the one or more service profiles including an identifier for a service and an associated indication of one or more requirements of a valid password for the service; determine an identity of a password-protected service first service based on contextual data associated with the first service that is received at an electronic device; if the one or more password requirements include a service profile associated with the first service: determine whether the one or more password requirements indicated in the service profile associated with the first service are up-to-date; in response to determining that the one or more password requirements are not up-to-date, sending a request to a remote resource associated with the first service to transmit current password requirements for the first service to the electronic device; randomly generate a password that complies with the current password requirements for the first service as received from the remote resource; and if the one or more current password requirements does not include a service profile associated with the first service, randomly generate a password that complies with the default password generation requirements. 11. The electronic device of claim 10 , wherein the instructions, when executed, further cause the processor to, if the one or more password requirements does not include a service profile associated with the first service: generate a new service profile for the password-protected service based on the identifying information; and store the generated new service profile in the memory. 12. The electronic device of claim 11 , wherein the instructions, when executed, further cause the processor to: poll one or more remote resources to obtain current requirements of valid passwords for services associated with at least one of the service profiles; and update the memory to indicate the current requirements of valid passwords for the services associated with the at least one of the service profiles. 13. The electronic device of claim 12 , wherein the one or more remote resources are polled periodically. 14. The electronic device of claim 12 , wherein the instructions, when executed, further cause the processor to, prior to polling the one or more remote resources, establish secure connections to the one or more remote resources by verifying digital certificates associated with the one or more remote resources. 15. The electronic device of claim 10 , wherein requirements of valid passwords for a service comprise one or more rules relating to at least one of: password length; presence of specific types of characters in a password; perceived password strength; prohibited elements in a password; or user password history. 16. The electronic device of claim 10 , wherein randomly generating the password comprises generating the password based, at least in part, on user-defined criteria. 17. The electronic device of claim 10 , wherein the instructions, when executed, further cause the processor to transmit the generated password to the password-protected service to register the generated password. 18. The electronic device of claim 10 , wherein the instructions, when executed, further cause the processor to receive, via the input interface, user instruction to generate the password and wherein the determining step is performed in response to receiving the user instruction. 19. The electronic device of claim 10 , wherein each service profile includes a password expiration policy for a respective service and wherein the instructions, when executed, further cause the processor to, if the one or more password requirements include a service profile associated with the

Assignees

Inventors

Classifications

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • G06F21/46Primary

    by designing passwords or checking the strength of passwords · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10055575B2 cover?
A method for generating a password for accessing a password-protected service is disclosed. A password requirements database and default password generation requirements are stored in a memory of a computing device. The password requirements database includes one or more service profiles, where each service profile includes an identifier for a service and an associated indication of requirement…
Who is the assignee on this patent?
Blackberry Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/46. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 21 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).