Methods, systems, and computer program products for recovering a password using user-selected third party authorization

US9323918B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9323918-B2
Application numberUS-201414531417-A
CountryUS
Kind codeB2
Filing dateNov 3, 2014
Priority dateOct 29, 2009
Publication dateApr 26, 2016
Grant dateApr 26, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A password recovery technique for access to a system includes receiving a request from a first party to recover the first party's password to access the system, receiving a selection of a second party from the first party, sending a message to the second party requesting that the second party authorize the request to recover the first party's password, receiving authorization from the second party for the request to recover the first party's password, and resetting the first party's password responsive to receiving authorization from the second party.

First claim

Opening claim text (preview).

That which is claimed: 1. A method, comprising: receiving, by a server associated with a second party, an electronic request sent from a network address associated with a device, the electronic request requesting recovery of a password associated with a first party; sending, by the server, a webpage to the network address associated with the device, the webpage for generating an interface for selecting a third party to authorize the recovery of the password, the interface comprising one of a field for entering an identity of the third party and a list that contains the identity of the third party; receiving, by the server, a selection of the third party sent from the network address associated with the device, the selection input via the interface; retrieving, by the server, a contact address associated with the third party; sending, by the server, an electronic message to the contact address associated with the third party, the electronic message requesting that the third party authorize the recovery of the password associated with the first party; receiving, by the server, authorization from the third party for the recovery of the password associated with the first party; and resetting, by the server, the password associated with the first party responsive to the authorization authorized by the third party. 2. The method of claim 1 , further comprising: presenting the first party with a security question responsive to receiving the electronic request to recover the password; and receiving a correct response to the security question from the first party. 3. The method of claim 1 , further comprising generating the electronic message. 4. The method of claim 1 , wherein sending the electronic message to the contact address associated with the third party comprises: receiving content for the electronic message sent from the network address associated with the device; and sending the content to the contact address associated with the third party requesting that the third party authorize the recovery of the password. 5. The method of claim 4 , further comprising receiving information that validates an identity of the first party to the third party. 6. The method of claim 5 , further comprising receiving a pre-arranged code established between the first party and the third party that validates the identity of the first party. 7. The method of claim 1 , further comprising: retrieving an account associated with the third party; and sending a prompt to the contact address associated with the third party after a log in. 8. The method of claim 1 , wherein sending the electronic message to the contact address associated with the third party comprises sending one of e-mail message and a text message. 9. The method of claim 1 , further comprising retrieving multiple contact addresses, each one of the multiple contact addresses associated with a different third party authorized to recover the password associated with the first party. 10. The method of claim 9 , further comprising: selecting a different contact address from the multiple contact addresses, the different contact address associated with an additional third party authorizer; and sending the electronic message to the different contact address associated with the additional third party authorizer, the electronic message requesting that the additional third party authorizer approve the recovery of the password associated with the first party. 11. The method of claim 10 , wherein resetting the password associated with the first party comprises resetting the password responsive to receiving the authorization from both the third party and the additional third party authorizer. 12. The method of claim 9 , wherein retrieving the multiple contact addresses comprises retrieving an email contact list. 13. The method of claim 1 , further comprising: determining a time between sending the electronic message to the second party and receiving the authorization for the recovery of the password; comparing the time to a threshold value; and resetting the password responsive to the time being less than the threshold value. 14. A system, comprising: a processor; and a memory coupled to the processor, the memory storing code that when executed causes the processor to perform operations, the operations comprising: receiving an electronic request sent from a network address associated with a device, the electronic request requesting recovery of a password associated with a first party; sending a webpage to the network address associated with the device, the webpage for generating an interface for selecting a third party to authorize the recovery of the password, the interface comprising one of a field for entering an identity of the third party and a list that contains the identity of the third party; receiving a selection of the third party sent from the network address associated with the device, the selection input via the interface; retrieving a contact address associated with the third party; sending an electronic message to the contact address associated with the third party, the electronic message requesting that the third party authorize the recovery of the password associated with the first party; receiving an electronic authorization sent from the contact address associated with the third party, the electronic authorization authorizing the recovery of the password associated with the first party; and resetting the password associated with the first party responsive to the electronic authorization authorized by the third party. 15. The system of claim 14 , wherein the operations further comprise: sending a prompt to the network address associated with the device, the prompt presenting the first party with a security question to recover the password; and receiving a correct response to the security question sent from the network address. 16. The system of claim 14 , wherein the operations further comprise generating the electronic message. 17. The system of claim 14 , wherein the operations further comprise receiving a pre-arranged code established between the first party and the third party. 18. A computer program product memory device storing code that when executed causes a processor to perform operations, the operations comprising: receiving an electronic request sent from a network address associated with a device, the electronic request requesting recovery of a password associated with a first party; sending a webpage to the network address associated with the device, the webpage for generating an interface for selecting a third party to authorize the recovery of the password, the interface comprising one of a field for entering an identity of the third party and a list that contains the identity of the third party; receiving a selection of the third party sent from the network address associated with the device, the selection input via the interface; retrieving a contact address associated with the third party; sending an electronic message to the contact address associated with the third party, the electronic message requesting that the third party authorize the recovery of the password associated with the first party; receiving an electronic authorization sent from the contact address associated with the third party, the electronic authorization authorizing the recovery of the password associated with the first party; and resetting the password associated with the first party responsive to the electronic authorization authorized by the third party.

Assignees

Inventors

Classifications

  • G06F21/45Primary

    Structures or tools for the administration of authentication · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • Lost password, e.g. recovery of lost or forgotten passwords · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • User authentication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9323918B2 cover?
A password recovery technique for access to a system includes receiving a request from a first party to recover the first party's password to access the system, receiving a selection of a second party from the first party, sending a message to the second party requesting that the second party authorize the request to recover the first party's password, receiving authorization from the second pa…
Who is the assignee on this patent?
At & T Ip I Lp
What technology area does this patent fall under?
Primary CPC classification G06F21/45. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 26 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).