IP Library Granted Patent US 10,057,247
Granted Patent B2
US 10,057,247 · App. 14/983,364 · Granted Aug 21, 2018

Systems and methods for determining a strength of a created credential

Inventor: Bjorn Markus Jakobsson (Mountain View, CA)
Assignee: PayPal, Inc.
H04L63/083G06F21/46
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,057,247
App. No.
14/983,364
Granted
Aug 21, 2018
Kind
B2
Abstract

Devices, systems, and methods for determining a strength of a created credential are provided. The device includes one or more processors configured to decompose a created credential into credential components, parse the credential components using a limited dictionary, determine a probability of the credential components using a limited ruleset, and calculate a score of the created credential based on the determined probability. The device also includes a memory, the memory storing the limited dictionary and the limited ruleset, and a network interface component coupled to a network, the network interface component configured to transmit the created credential to a remote server over the network for a secondary credential strength determination if the calculated score is above a threshold.

Claims (42)

1. A client device, comprising:

a non-transitory memory storing a first word dictionary that is a subset of a second word dictionary on a remote server; and

one or more hardware processors coupled to the non-transitory memory and configured to read instructions to cause the client device to perform operations comprising:

decomposing a password into components including one or more words;

applying a concatenation ruleset, an insertion ruleset, and a replacement ruleset to the components, the applying including comparing the one or more words in the password with words in the first word dictionary;

determining a probability value for each of the one or more words based on a usage probability of each of the one or more words;

determining, by a first application on the client device, a first strength indication of the password based at least on the determined probability values for the one or more words;

in response to the first strength indication being above a threshold, requesting a second strength indication of the password based on the second word dictionary from the remote server; and

receiving a communication from the remote server regarding whether to accept or reject the password based on the second strength indication, wherein the second strength indication was determined by a second application of the remote server.

2. The client device of claim 1 , wherein the operations further comprise determining that the first strength indication indicates a rejection, and in response, requesting a second password.

3. The client device of claim 2 , wherein the operations further comprise displaying a strength indicator in response to determining the first strength indication.

4. The client device of claim 1 , wherein the decomposing comprises parsing the one or more words from the password.

5. The client device of claim 4 , wherein the one or more words are parsed from the password for maximum coverage.

6. The client device of claim 1 , wherein the usage probability of each of the one or more words is based on a number of occurrences of the one or more words in a plurality of passwords.

7. The client device of claim 1 , wherein the operations further comprise requesting a second password in response to the first strength indication being below the threshold.

8. A computer implemented method comprising:

receiving a password entered on a client device;

decomposing the password into components including one or more words;

applying at least one of a concatenation ruleset, an insertion ruleset, or a replacement ruleset to the components, the applying including accessing a first word dictionary stored on the client device and comparing the one or more words in the password with words in the first word dictionary;

determining, by a first application on the client device, a first strength indication for the password based at least on comparing the one or more words in the password;

in response to the first strength indication being above a threshold, requesting a second strength indication of the password based on a second word dictionary from a server device, wherein the first word dictionary is a subset of the second word dictionary; and

receiving, from the server device, content associated with the second strength indication, wherein the second strength indication was determined by a second application of the server device.

9. The computer implemented method of claim 8 , wherein the method further comprises providing feedback and requesting a second credential in response to the first strength indication being below the threshold.

10. The computer implemented method of claim 9 , wherein providing feedback comprises displaying a visual indication of a relative strength of the password.

11. The computer implemented method of claim 8 , wherein the decomposing comprises parsing the one or more words from the password.

12. The computer implemented method of claim 11 , wherein the method further comprises parsing the one or more words from the password for maximum coverage.

13. The computer implemented method of claim 11 , wherein the determining of the first strength indication comprises:

determining a frequency for each of the one or more words; and

averaging the frequency of the one or more words.

14. The computer implemented method of claim 13 , wherein the frequency is determined based on a number of occurrences of the one or more words in a plurality of passwords.

15. A non-transitory computer-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising:

decomposing a password into components including one or more words;

applying at least one of a concatenation ruleset, an insertion ruleset, or a replacement ruleset to the components, the applying including comparing the one or more words in the password with words in a first word dictionary;

determining a probability value for each of the one or more words based on a usage probability of each of the one or more words;

determining, by a first application on a client device, a first strength indication of the password based at least on the determined probability values for the one or more words;

in response to the first strength indication being above a threshold strength, requesting a second strength indication of the password based on a second word dictionary from a remote server; and

receiving a communication from the remote server regarding whether to accept or reject the password based on the second strength indication, wherein the second strength indication was determined by a second application of the remote server.

16. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise determining that the first strength indication indicates a rejection, and in response, requesting a second password.

17. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise displaying a strength indicator in response to determining the first strength indication.

18. The non-transitory computer-readable medium of claim 15 , wherein the decomposing comprises parsing the one or more words from the password.

19. The non-transitory computer-readable medium of claim 18 , wherein the one or more words are parsed from the password for maximum coverage.

20. The non-transitory computer-readable medium of claim 15 , wherein the usage probability of each of the one or more words is based on a number of occurrences of the one or more words in a plurality of passwords.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2017
From: JAKOBSSON, BJORN MARKUS
To: EBAY INC.
Reel/Frame 040871/0129 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2017
From: EBAY INC.
To: PAYPAL, INC.
Reel/Frame 040871/0242 →
Continuity (2)
Continuation 13724409 · Dec 21, 2012
Related Publication 20160112401A1 · Apr 21, 2016
Cited By (1)
US 12,231,421